ICT Risk Management for AI Services under DORA

DORA requires documented ICT risk management for AI services in the financial sector under Art. 5 and 6 of DORA – plus AI Act duties from 2026.

AI services are ICT assets – even if they’re „just“ a chatbot

Anyone working in the financial sector who deploys AI systems – whether as a credit-scoring module, an anti-fraud engine, an internal assistant or a customer-facing chatbot – must treat those systems for what they are under DORA: ICT assets or ICT services. Art. 6(2) DORA requires a risk management framework that adequately protects „all information and ICT assets, including computer software“. A self-trained model, a GPAI solution connected via API, or a SaaS tool with an AI feature all fall within scope – regardless of whether it was developed in-house or procured from a third party.

The typical gap: AI projects often start life as „innovation initiatives“ outside established ICT governance. Business units test a model, and a contract with an AI provider gets signed without the ICT risk function ever being involved. That runs directly against the underlying logic of DORA, which treats risk management as a continuous, firm-wide process.

Governance: the management body bears responsibility

Art. 5 DORA places responsibility explicitly with the management body. Under Art. 5(2)(a), it bears „the ultimate responsibility for managing the financial entity’s ICT risk“ – including AI-related risk. In practice, this means the decision to put an AI system into production cannot rest with the business unit alone. Under Art. 5(2)(c), the management body must set clear responsibilities for ICT-related functions, and under (h) it must approve and periodically review the policy on arrangements with ICT third-party service providers.

Where an AI model is sourced from an external provider (cloud AI, GPAI API, managed service), Art. 5(2)(i) also applies: reporting channels must be in place so the management body is informed of arrangements with ICT third-party providers, of any planned material changes, and of their impact on critical functions. An AI provider that updates its model without prior notice is precisely the scenario this provision is meant to address.

The risk management framework: documentation is not optional

Art. 6(1) DORA requires a „sound, comprehensive and well-documented“ ICT risk management framework. For AI services, this means in practice:

  • Documenting safeguards (Art. 6(2)): How is the model protected against unauthorised access, manipulation or misuse? What data feeds into it, and which ICT infrastructure does it rely on?
  • Independent control function (Art. 6(4)): Non-microenterprises must assign oversight of ICT risk – including for AI systems – to a function independent from development and operations.
  • Annual review (Art. 6(5)): The framework must be reviewed at least once a year, plus after major incidents. An AI system that keeps changing through retraining or provider-side model updates realistically needs a tighter review cycle than this minimum.
  • Internal audit (Art. 6(6)): Auditors with sufficient knowledge of ICT risk must be able to review the framework – which presupposes that someone in-house actually understands how the deployed AI system works and where its risks lie.

The digital operational resilience strategy under Art. 6(8) must also explain how incidents are detected and prevented (lit. e) and how they are communicated (lit. h). An AI system that produces faulty decisions or fails counts as such an incident for the purposes of the framework.

The interface with the AI Act: don’t forget Art. 50

DORA governs the „how“ of risk management, but it does not replace the AI Act obligations that apply to the deployed system itself. From 2 August 2026, the transparency obligations under Art. 50 AI Act apply – including labelling and information duties for chatbots or AI-generated content. Systems already placed on the market before that date benefit from a grace period until 2 December 2026. Anyone running an AI-powered customer service or advisory tool needs to think about both layers together: DORA governance for the „whether and how“ of ICT risk management, and AI Act transparency duties for the specific system in use.

In practice, this link is often missing: the DORA risk management framework is maintained without the responsible teams knowing which additional AI Act duties apply to a given system, or from when – or the other way round.

Where to start

Before adjusting individual forms or clauses, it’s worth getting an overview first: which AI systems do you use, who is the provider, and which DORA and AI Act deadlines actually apply to you? The free assessment at /einstufung gives you an initial orientation within minutes on which obligations are relevant to your AI services.

Factual orientation, not legal advice. Citations refer to the named legal acts and were checked against the official EUR-Lex texts.