Auditen
Home / Frameworks / DORA / Management body responsibility for ICT risk
DORA · Art. 5

Management body responsibility for ICT risk

The management body is ultimately accountable for the organization's ICT risk management framework and its implementation. They must actively approve strategies, allocate necessary resources, and maintain sufficient knowledge to make informed decisions regarding digital operational resilience.

What it means

Article 5 shifts ICT risk from a purely technical concern to a core governance requirement. It mandates that the board or executive leadership cannot simply delegate "IT security" to a CISO or IT department; while tasks can be delegated, ultimate legal and operational accountability remains with the management body.

In practice, this means the management body must ensure that ICT risk is integrated into the overall business risk appetite. They are responsible for ensuring there is enough funding, staffing, and tooling to meet DORA requirements, and they must oversee the effectiveness of the controls put in place.

Furthermore, there is a requirement for "competence." Management cannot claim ignorance of technical risks; they must proactively acquire the knowledge necessary to challenge reports and oversee ICT risk management effectively.

How to meet it

Evidence an auditor asks for

  • Board meeting minutes documenting discussions, challenges, and formal approvals of ICT risk policies and strategies.
  • Signed approval records for the annual ICT budget specifically highlighting investments in digital resilience.
  • Training logs or certificates proving that members of the management body have completed ICT risk education.
  • Copies of board-level reports (dashboards) showing how ICT risks are communicated to leadership.
  • An organizational chart and governance charter clearly mapping accountability for ICT risk to the management body.

Common pitfalls

  • "Rubber stamping": Providing signatures on policies without evidence in meeting minutes that the board actually reviewed or questioned them.
  • Over-delegation: Treating ICT risk as a siloed IT function rather than a business risk, leading to a lack of active oversight by executives.
  • Knowledge gaps: Relying on overly technical reports that the management body cannot interpret, resulting in an inability to make "informed decisions."