Skip to content

Site navigation

AML & DORA

Where DORA fits in a licensing application, and where it does not

ICT evidence belongs in the application. Whether DORA itself binds you at that point depends on what you already are.

In short

DORA applies to the financial entities listed in Article 2(1), which is a closed list, with entities excluded in Article 2(3) and a simplified framework in Article 16.12 Applying for an authorisation does not by itself bring a firm inside DORA, so what an authority examines at application is the ICT and security evidence the sectoral framework requires. An applicant that already holds another authorisation may already be a listed financial entity, and DORA already binds it in that capacity.14

What the law requires

Who DORA actually binds

DORA applies to the financial entities listed in Article 2(1) and to ICT third-party service providers. The list is closed. Article 2(3) excludes certain entities from it entirely, and Article 16 applies a simplified ICT risk management framework to others.123

The practical effect is that the depth of what DORA requires is not uniform, and whether it applies is a conclusion to check against the entity types you already hold rather than one to assume either way.1

What the law requires

What is assessed at application, and what already binds

A payment institution applicant must submit a security policy document containing a risk assessment and a description of the security control and mitigation measures. Other frameworks set their own application content requirements.4

That is what an authority looks at where the applicant is not otherwise a listed financial entity. Where it is one already, for example an authorised institution applying for a further authorisation, DORA binds it in that existing capacity and the application does not change that.14

What the law requires

Third-party risk

For entities within scope, DORA requires ICT third-party risk to be managed and a register of information on contractual arrangements to be maintained, and it establishes an oversight framework for critical ICT third-party service providers.3

RenIQ practitioner observation

A practical approach

Build the ICT evidence the application asks for, and build it in a shape that carries over into the framework you will be subject to once authorised. Sequencing it that way avoids doing the work twice without claiming an obligation that has not yet attached.

Related regime guide: AML & DORA

This is a supporting note behind the decision guide A weak or stalled application: repair it, reset the scope, or stop.

Last updated 2026-08-21. 2 min read, calculated from 333 words.

Turn this into your authorisation plan

Book an intro call to apply this analysis to your specific product, jurisdiction and timeline.