Priority sector
Banks, payment and e-money institutions, insurers and investment firms operate under the densest compliance framework in the European Union.
Key obligations
DORA has applied to financial entities since 17 January 2025, covering ICT risk, incident reporting, resilience testing and third-party risk.
Regulation (EU) 2024/1624 applies from 10 July 2027, and AMLA will directly supervise selected high-risk cross-border institutions.
Entities subject to EU financial services rules must establish internal reporting channels regardless of their number of workers.
Credit scoring, profiling and transaction monitoring require sound legal bases, impact assessments and, in many cases, a DPO.
Prudential, conduct, anti-money laundering and digital resilience rules converge on the management body, which bears ultimate responsibility for ICT risk under DORA and for the anti-money laundering framework under the AMLR. Supervisors expect evidence, not intentions, and the same incident may trigger reporting duties under several regimes.
DORA: gap analysis, ICT risk framework, incident process and the register of information on ICT third parties;
anti-money laundering: business-wide risk assessment, customer due diligence procedures and support for the compliance officer;
Data Protection Officer: for institutions that process data on a large scale;
whistleblowing: internal channels that meet the requirements applicable to the financial sector.
A free Compliance Assessment maps the overlapping obligations and the gaps that matter most.
Related domains: Digital Operational Resilience · Anti-Money Laundering · Data Protection · Third-Party & Supply Chain · Whistleblower Protection
Regulated functions: Compliance Officer · Information Security Officer · Data Protection Officer · All sectors
General information as at October 2026; it does not constitute legal advice.
Request a free assessment designed for financial institutions.