# Does DORA Require a Dedicated ICT Risk Officer?

Source: https://www.cyadviso.com/dora-ict-risk-officer-requirement
Last reviewed: 2026-07-21
Tags: DORA, ICT Risk, Governance, Compliance

DORA Articles 5–16 require a documented ICT risk function, not a specific officer title. What EU fintechs must assign and resource before supervisory review.

---

**Last reviewed: 21 July 2026**

**Key takeaways**

- DORA Articles 5–16 require an ICT risk management function assigned to a named owner, resourced, and operated continuously — not a specific job title.
- Article 5 governs the function at management body level; it says nothing about hiring a CISO, Chief Risk Officer, or "ICT Risk Officer".
- DORA accommodates three structures — an internal ICT risk function, a shared role with genuine operational capacity, or an external vCISO — provided the function actually operates.
- In supervisory reviews NCAs ask three structural questions (who owns the function, is it operational, does the management body receive dedicated ICT risk reporting); function, not title, generates or prevents findings.

---

No. DORA does not require a job title called "ICT Risk Officer". DORA Articles 5 through 16 mandate a *function*: an ICT risk management framework that is assigned to a named owner, resourced, documented, and operated continuously. Whether the person filling that function is called an ICT Risk Officer, a vCISO, a Head of Information Security, or something else does not determine compliance. Whether the function actually operates does.

The question itself arrives in two forms. Sometimes from a CEO who has just read a DORA compliance brief: "Do we need to hire someone with ICT Risk Officer in their title?" Sometimes from a compliance team defending its existing structure: "We already have someone doing this, so do we need a new role?" The regulatory answer is the same in both cases — the title is not the test; the operating function is.

This article walks through what Articles 5 through 16 require of the ICT risk function, the three structural questions regulators ask in supervisory reviews, and how EU-licensed fintechs can staff the function in ways that satisfy DORA without necessarily creating a new headcount line.

For the anatomy of ownership — why a compliance officer cannot typically absorb this function without dedicated capacity, and who is accountable — see the hub article [DORA ICT risk ownership →](/dora-ict-risk-ownership). This article answers the narrower question fintechs actually ask: do you need a dedicated, titled role, and how can the function be staffed without necessarily creating a new headcount line?

---

## What Article 5 actually requires

Article 5 of DORA establishes management body accountability for the ICT risk management framework. The management body must approve the framework, define risk appetite, and ensure adequate resourcing. Article 5(4) goes further: the management body must maintain updated knowledge of ICT risks, which in practice means regular engagement with whoever runs the ICT risk function.

Article 5 says nothing about job titles. It says nothing about hiring a dedicated CISO, Chief Risk Officer, or ICT Risk Officer. What it requires is that the ICT risk management framework is governed at management body level, with a named function owner reporting into that body.

The implication is that the management body needs a named function owner to report to it. Who holds that function and under what title is left to the entity. DORA's formulation is intentionally flexible: a proportionate approach applies, and a small EMI does not face the same resourcing expectations as a major institution. The framework should be "appropriate to the size, business and risk profile" of the financial entity (Article 4 proportionality principle).

---

## The function requirement: Articles 6 through 16

The function requirement becomes more detailed as you move through Articles 6 to 16. Article 6(1) requires the framework to be "sound, comprehensive and well-documented." Article 6(5) requires regular review: at least yearly, after major ICT-related incidents, following supervisory instructions, and following testing or audit conclusions. Article 8 requires ongoing identification and classification of ICT assets. Articles 9 through 13 add security controls, detection mechanisms, response plans, and recovery procedures.

None of these are once-a-year tasks. They require someone with ongoing operational involvement in the entity's ICT environment: knowledge of what systems exist, which vendors are critical, where vulnerabilities were found and what was done about them. The EBA ICT Risk Guidelines clarify that "sound" means the framework operates continuously, not just that it is described in a policy document.

The practical test a National Competent Authority applies is this: if the NCA requests the ICT risk register, the incident log, and records of management body oversight, can the named function owner produce current versions? Not versions from the last advisory engagement. Current versions, reflecting the actual state of the ICT environment at the time of the request.

---

## Three structural approaches DORA accommodates

EU-licensed fintechs typically staff the ICT risk function in one of three ways, and DORA accommodates all three provided the function genuinely operates.

**Internal ICT risk function.** A dedicated internal resource, whether an ICT Risk Manager, CISO, or Head of Information Security, owns the framework on a full-time basis. This is the clearest structural answer and also the most resource-intensive. For larger entities or those with complex ICT environments, it is often the appropriate baseline.

**Shared function alongside other roles.** An existing role, such as a CTO, IT Director, or compliance officer, absorbs ICT risk management alongside other responsibilities. DORA does not prohibit this. What DORA requires is that the person has operational capacity to execute Articles 8 through 16: not just time to review a policy document once a year, but ongoing engagement with the entity's ICT assets, incidents, and third-party dependencies. Where a role is separately resourced and technically qualified, this can work. Where ICT risk is a nominal additional task added to an already-loaded function, it generates findings.

**External or outsourced function (vCISO model).** DORA permits the operational ICT risk function to be performed externally; under Article 5 the management body's accountability stays in-house and cannot be outsourced. A vCISO who acts as the named ICT risk function owner can satisfy DORA if the management body retains accountability and the function operates continuously. This is the structural answer for fintechs in CISO-vacancy periods, for smaller entities where a full-time internal hire is disproportionate to the ICT risk profile, and for those who have completed a gap assessment but have not yet embedded a permanent ICT risk governance structure.

---

## What regulators examine: function versus title

In supervisory reviews, National Competent Authorities do not ask whether the entity has an ICT Risk Officer. They ask three structural questions.

First: who is the named owner of the ICT risk management framework? What is their reporting line to the management body? The name and the reporting structure must appear in governance documentation, not just be informally understood within the organisation.

Second: is the framework operational? The NCA will request the ICT risk register and ask when it was last updated. If the register reflects the state at the time of the last advisory engagement and has not been maintained since, that generates a finding. The answer to "when was this last updated?" must point to recent activity by the named function owner, not to an external consultant's engagement.

Third: does the management body receive dedicated ICT risk reporting, separate from compliance reporting? Article 5(4) requires the management body to maintain updated knowledge of ICT risks. A single annual compliance report that mentions ICT risks in a summary section does not satisfy this. Regulators look for a standing reporting cadence, quarterly or more frequent, with documented management body decisions on material ICT risks.

Function, not title, is what generates or prevents findings.

---

## Practical implications for EMIs, PIs, and CASPs

For EU-licensed EMIs, Payment Institutions, and CASPs, the proportionality question is relevant. DORA Article 4 allows for proportionate application based on size, risk profile, and nature of operations. A small PI processing lower transaction volumes and running a straightforward ICT environment is not expected to staff its ICT risk function identically to a large institution.

What proportionality does not permit is a nominal designation with no operational reality. The supervisory expectation scales with size, but the requirement for an operational, assigned, and continuously maintained ICT risk function does not disappear at any entity size within DORA's scope.

For fintechs in a CISO-vacancy period, this matters directly. The gap between the departure of a CISO and the hire of their replacement can run six to twelve months. During that period, the ICT risk function must continue to operate. An interim vCISO arrangement, or a clearly documented extension of the function to an existing qualified role with operational capacity, satisfies DORA. An unassigned function during a vacancy does not.

{/* [HUMAN-FILL: anonymized vignette — category (EMI/PI/CASP) + regulator-as-subject + outcome, C-1 name-scan before publish. Natural slot: one anonymized case where a shared/unassigned function during a vacancy produced a finding, or where a vCISO arrangement satisfied the NCA. No client name, no fabricated numbers ([live-check]). */}

[Latvijas Banka, the Latvian National Competent Authority](/dora-bank-of-latvia), and [Lietuvos bankas, the Lithuanian National Competent Authority](/dora-bank-of-lithuania) have both issued supervisory guidance consistent with DORA Title II, emphasising clearly assigned ICT risk accountability at management body level as a core supervisory expectation.

---

## Terminology and board-level documentation

For precise definitions of the terms used in DORA Articles 5 through 16, the [DORA glossary →](/dora-glossary) defines the ICT Risk Management Framework, Management Body, and related roles. For the board-level governance documentation requirement under Article 5(2), the [DORA board responsibilities checklist →](/dora-board-responsibilities-2025-eu-financial-checklist) sets out what the management body needs to document to evidence its oversight of the ICT risk function.

---

## Frequently asked questions

### Does DORA require a dedicated ICT risk officer?

DORA Articles 5 through 16 require a documented ICT risk management function assigned to a named owner, overseen by the management body. DORA does not mandate a specific job title, nor does it require a full-time internal hire. The function must be clearly assigned, adequately resourced, and operationally active. An external vCISO can fulfil the ICT risk function if the management body retains accountability and the function operates on an ongoing basis.

### Can a compliance officer serve as the ICT risk function owner under DORA?

A compliance officer can own the ICT risk management function if they have the operational capacity to execute Articles 8 through 16: ongoing asset identification, incident classification, third-party oversight, and regular ICT risk reporting to the management body. A compliance officer who is separately resourced and technically qualified for these tasks can fulfil both roles. A compliance team absorbing ICT risk as an additional task without that capacity cannot: the framework may exist on paper, but it will not operate in the way Articles 8 through 13 require.

### Can an external vCISO satisfy the DORA ICT risk function requirement?

Yes. DORA permits the operational ICT risk function to be outsourced, while Article 5 keeps the management body accountable for the framework. An external vCISO acting as the named ICT risk function owner satisfies the regulation if the management body formally approves the arrangement and retains accountability for the framework, the vCISO provides regular ICT risk reporting to the management body, and the function operates continuously. A retainer-based arrangement with a defined governance cadence is the typical structure. The vCISO must not engage only on request: DORA requires ongoing operation, not periodic project work.

### What happens if the ICT risk function is unassigned during a CISO hire period?

The ICT risk function must remain operational during any vacancy. A CISO departure does not suspend DORA obligations. Options include: designating an existing qualified resource as interim function owner with documented capacity, engaging a vCISO for the interim period, or formally reassigning the function with appropriate resourcing documented at management body level. An unassigned or informally covered function during a vacancy is a compliance gap that NCAs identify in supervisory reviews.

---

## How CyAdviso structures the ICT risk function

CyAdviso works with EU-licensed fintechs, including EMIs, Payment Institutions, and CASPs, to design and operate the ICT risk management function under DORA. Engagements under EU financial-sector supervision typically involve: assessing whether the current assignment of the ICT risk function meets the Articles 5 through 16 operational requirements; designing the governance structure, reporting cadence, and evidence package; and where needed, acting as the named ICT risk function owner for a defined engagement period.

The outcome is a function that operates under supervisory scrutiny, not a policy document that generates findings when the NCA arrives.

To discuss whether your current ICT risk function structure satisfies DORA supervisory expectations, [schedule a consultation with CyAdviso](https://cal.com/andrey-gubarev/15min) or contact us at info@cyadviso.com.

---

Authored by Andrey Gubarev — CISO for EU fintechs (CISM, CDPSE, SABSA).
CyAdviso · DORA / ICT risk / vCISO programmes for EU-licensed fintechs.
Canonical HTML: https://www.cyadviso.com/dora-ict-risk-officer-requirement
