Skip to content

Site navigation

Regulatory regime guide

AML and DORA: two separate frameworks, not one regime

Anti-money-laundering obligations and the Digital Operational Resilience Act. They are cited together often, but they have different scopes, different sources and different supervisors.

Scope
European Union, with national implementation for anti-money-laundering. Verify against current national requirements.

Direct answer

Anti-money-laundering rules and DORA are two frameworks, not one. Neither is an authorisation regime in its own right.14 Anti-money-laundering obligations reach a firm through the Union directive as transposed into national law, so the detail differs by Member State; the 2024 package replaces much of that with a directly applicable regulation, but from a later date set in the instruments themselves.456 DORA applies to the closed list of financial entities in Article 2(1), excludes some entities entirely and applies a simplified framework to others.12 A firm does not become subject to DORA by applying for an authorisation, so what an authority examines at application is the ICT and security evidence the sectoral framework itself requires. An applicant that already holds another authorisation may already be a listed financial entity in that other capacity, and DORA already binds it there.18

Who this applies to

  • Firms that are obliged entities under national anti-money-laundering law4
  • The financial entities listed in Article 2(1) of DORA, which is a closed list1
  • ICT third-party service providers to those financial entities3

Regulated activities

  • Customer due diligence, monitoring and sanctions screening under national anti-money-laundering law4
  • Business-wide risk assessment and governance
  • ICT risk management, incident reporting and resilience testing under DORA, for entities within its scope1
  • ICT third-party risk management and the register of information3

Routes to market

Evidence built into the authorisation file

Build the financial-crime framework and the ICT and security evidence the sectoral application actually asks for, rather than a generic programme that may not yet bind you.18

Remediation programme

Close gaps identified in a readiness review before submission or supervision.

Capital and substance

  • Anti-money-laundering: a compliance function with local substance and independence, sized to the national obligations that apply.4
  • DORA, for entities within its scope: ICT governance, a register of information on ICT third-party arrangements, incident reporting and resilience testing.3
  • Some entities are outside DORA entirely, and others are subject to a simplified ICT risk management framework, so the depth required is not uniform.12
  • At application stage, the security and ICT evidence required by the sectoral framework, such as the security policy document a payment institution applicant must submit.18

Authorisation stages

  1. 1

    Establish which framework binds you

    Confirm your national anti-money-laundering obligations, and whether you are a listed financial entity under DORA already, in full or in simplified form.14

  2. 2

    Risk assessment

    Complete the business-wide financial-crime risk assessment and, where DORA applies, the ICT risk assessment.1

  3. 3

    Framework build

    Implement controls, policies and monitoring.

  4. 4

    Evidence and ongoing supervision

    Prepare documentation and testing results, and maintain reporting over time.

Where applications commonly fail

  • Treating anti-money-laundering and DORA as one combined regime with one uniform standard14
  • Planning against the 2024 anti-money-laundering package as though it already applied56
  • Assuming an application by itself brings a firm inside DORA, or that holding another authorisation keeps it outside18
  • Weak sanctions screening and transaction monitoring
  • Incomplete register of information and third-party oversight3

Frequently asked questions

It depends on entity type. DORA applies to the financial entities listed in Article 2(1), which is a closed list, and to ICT third-party service providers. Article 2(3) excludes certain entities entirely, and Article 16 applies a simplified ICT risk management framework to others. It is not a general obligation on every regulated firm.

Primary sources for this page

8 citations, each to the article or section the statement rests on. The numbers beside a statement point to the citation behind it. Always confirm against the current official text.

  1. 1Article 2(1), the list of financial entities to which DORA applies, and Article 2(3), the entities excluded from itRegulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sectorEuropean Parliament and Council of the European Union
  2. 2Article 16, simplified ICT risk management framework for the entities it listsRegulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sectorEuropean Parliament and Council of the European Union
  3. 3Chapter V, management of ICT third-party risk, including the register of information and the oversight framework for critical ICT third-party service providersRegulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sectorEuropean Parliament and Council of the European Union
  4. 4Article 1 and Article 2, subject matter and the obliged entities covered, as transposed into national lawDirective (EU) 2015/849 of the European Parliament and of the Council of 20 May 2015 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financingEuropean Parliament and Council of the European Union
  5. 5Article 3, obliged entities, and Article 90, entry into force and date of applicationRegulation (EU) 2024/1624 of the European Parliament and of the Council of 31 May 2024 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financingEuropean Parliament and Council of the European Union
  6. 6Article 78, transposition, including the dates from which Member States must apply the national measuresDirective (EU) 2024/1640 of the European Parliament and of the Council of 31 May 2024 on the mechanisms to be put in place by Member States for the prevention of the use of the financial system for the purposes of money laundering or terrorist financingEuropean Parliament and Council of the European Union
  7. 7Article 1, establishment and subject matter, and Article 13(4), the date from which direct supervision of selected obliged entities beginsRegulation (EU) 2024/1620 of the European Parliament and of the Council of 31 May 2024 establishing the Authority for Anti-Money Laundering and Countering the Financing of TerrorismEuropean Parliament and Council of the European Union
  8. 8Article 5(1), the contents of an application for authorisation as a payment institution, including point (j), the security policy documentDirective (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal marketEuropean Parliament and Council of the European Union

Last updated 2026-08-21. 3 min read, calculated from 656 words.

Planning a AML & DORA application?

Book an intro call to pressure-test your route, timeline and evidence plan with a senior practitioner.