The Danish Financial Supervisory Authority has found that insurance and pension companies are progressing with implementation of the Digital Operational Resilience Act (DORA), but must strengthen their management of information and communication technology risk. Its review of 14 selected companies identified weaknesses in board oversight, allocation of responsibilities, documentation and alignment of risk management frameworks, staff capabilities, operational preparedness and learning from incidents and testing. Companies should give boards sufficient information to oversee ICT risk and critical third party dependencies, clearly separate operational and control functions, and complete the mapping of relevant assets, services and data. They should also systematically test business continuity and disaster recovery plans, establish effective crisis communications and use internal and external incidents to improve risk management. The authority has required companies with identified deficiencies to submit remediation plans and is following up through status meetings and ICT inspections. Targeted, risk based inspections covering all five DORA areas will be conducted in the coming years, and deficiencies or insufficient remediation progress may lead to supervisory action.
2026-09-23Danish Finanstilsynet
Danish Financial Supervisory Authority identifies DORA weaknesses at insurers and pension companies
The Danish Financial Supervisory Authority found that insurers and pension companies are advancing their DORA implementation but still have weaknesses in governance, risk management documentation, skills, operational testing and incident learning. Companies with deficiencies must submit remediation plans, while targeted inspections and inadequate progress may result in supervisory action.