The programme took two years. It involved the systematic analysis of more than 1,600 individual requirements drawn from the DORA Level 1 text, the Implementing Technical Standards, the Regulatory Technical Standards, and the guidelines published by the European Supervisory Authorities. Each requirement was assessed against the current state of the institution's ICT risk management, incident management, resilience testing and third-party risk frameworks. Gaps were identified, documented and prioritised. Remediation actions were agreed, resourced and tracked to completion. The programme was independently reviewed by the institution's internal audit function — whose mandate is to assess the adequacy and effectiveness of controls — and by a dedicated programme quality control team. At the point of formal programme closure, the compliance position was documented, evidenced and signed off.
Then the external auditors arrived.
Their findings were significant. Not minor process observations, not documentation gaps — significant findings, requiring formal management responses, remediation plans and follow-up assessment. In some cases, the findings covered areas that the internal programme had explicitly addressed, with evidence that had been reviewed and accepted by the internal audit team.
This experience is not unique. It is being replicated, with variations, across financial institutions that have invested heavily in DORA compliance programmes and are discovering that the standard against which external auditors assess their work is not the same standard their internal programmes were designed to meet. The gap between those two standards is the subject of this article — examined, as honestly as possible, from both sides of the table.
The Institution's Position: Proportionality is Not a Loophole
DORA's proportionality principle is explicit, not implicit. Article 4(2) of Regulation (EU) 2022/2554 is direct: "Financial entities shall implement the rules laid down in this Chapter in accordance with the principle of proportionality, taking into account their size and overall risk profile, and the nature, scale and complexity of their services, activities and operations." The Regulatory Technical Standards reinforce this position throughout — the ICT risk management framework RTS (Regulatory Technical Standard — a binding Level 2 measure published by the European Supervisory Authorities that specifies how a regulation must be implemented), the ICT third-party risk RTS, the incident classification RTS all contain proportionality language that explicitly contemplates different implementations for entities of different sizes and risk profiles.
The institution that has analysed 1,600+ requirements, documented its gap assessment, implemented remediation actions and had those actions independently verified has done exactly what the regulatory framework anticipated. The proportionality principle was not invented to give institutions an excuse to avoid compliance — it was included because the ESAs (European Supervisory Authorities — the EBA, ESMA and EIOPA, which together publish binding technical standards and guidelines under DORA) recognised that a single, uniformly prescriptive standard would be either inadequate for systemic institutions or disproportionate for smaller entities. The institution's implementation reflects its risk profile, its operational complexity, and its capacity for remediation — all of which are legitimate inputs to the proportionality assessment that DORA explicitly requires.
The institution's position on the specific findings is more nuanced than simple disagreement. In the majority of cases, the institution does not dispute the external auditor's observation — it disputes the conclusion drawn from it. The external auditor observes that the ICT risk management framework does not include a specific element that the auditor considers standard practice. The institution's response is that the absence of that element reflects a documented proportionality judgement: the element is not required given the institution's size, risk profile and the compensating controls that are in place. The disagreement is not about what was built — it is about whether what was built is sufficient.
"We did not implement DORA against the standard that would apply to a G-SIB (Global Systemically Important Bank — one of the world's largest and most systemically critical financial institutions, subject to the highest tier of regulatory capital and supervisory requirements). We implemented it against the standard that applies to an institution of our size, complexity and risk profile — which is precisely what Article 4(2) requires. The finding is not that we failed to comply. The finding is that we complied differently from how the auditor expected."
There is a further dimension to the institution's position that deserves honest examination. In many cases, the external auditors' benchmark was developed through their experience auditing other financial institutions — typically, larger institutions with more complex risk profiles and greater compliance resources. The practice that the auditor considers standard was observed at institutions for whom it was proportionate — but that does not make it proportionate for every institution. The auditor's cross-sector experience is valuable. It is also, without careful application, a source of systematic over-prescription for smaller institutions.
Finally, the institution notes that the programme was not conducted in isolation. External advisors — including, in some cases, subsidiaries or affiliates of the same firms now conducting the external audit — were engaged during the programme to provide guidance on implementation. The interpretations that the external audit now characterises as insufficient were, in many cases, developed in dialogue with external expertise. The consistency of interpretation between advisory and audit arms of the same organisations is a question that the industry has not yet adequately addressed.
The External Auditor's Position: Proportionality Has a Floor
The external auditor's starting point is not the institution's proportionality assessment — it is the regulatory minimum, as understood through the Level 1 text, the Level 2 measures, and the supervisory guidance that has accumulated through the Joint Committee Q&A process, the ESA guidelines and the supervisory dialogue that has followed DORA's January 2025 application date. That minimum is not unlimited by proportionality, but it is more demanding than many institutions' internal assessments acknowledge.
The proportionality principle, correctly applied, adjusts how DORA's requirements are implemented — it does not adjust whether they are implemented. An institution that uses proportionality to reduce the frequency of resilience testing, or to limit the scope of its third-party risk assessment, or to simplify its incident classification criteria, is applying the principle within its intended scope. An institution that uses proportionality to avoid implementing a core element of the ICT risk management framework — or to classify ICT third-party providers at a lower criticality level than their actual operational importance warrants — has misapplied it.
The external auditor's findings, in the majority of cases, are not assertions that the institution should have implemented DORA to G-SIB standards. They are assertions that specific requirements were not met at any standard of proportionality — that the gap identified is not a calibration gap but a substantive compliance gap. The institution may disagree with that assessment. But the external auditor's accountability is to the regulator, not to the institution, and the regulator's expectations — as communicated through supervisory statements, onsite inspections and the emerging body of DORA supervisory practice — are materially more demanding than many institutions anticipated when designing their compliance programmes.
The ECB's and national competent authorities' approach to DORA supervision is still being shaped. The 2025–2026 supervisory cycle is the first in which DORA findings will be incorporated into SREP (Supervisory Review and Evaluation Process — the annual supervisory assessment through which competent authorities evaluate each institution's risks, governance and capital adequacy) assessments and — for critical third-party providers — will drive the new ESA oversight programme. External auditors are operating in an environment where the regulatory expectations are actively being defined through supervisory practice, and where the cost of under-reporting a significant finding — to the auditor's professional standing and to the institution's regulatory relationship — is materially higher than the cost of over-reporting one. That asymmetry influences how findings are characterised.
The cross-sector experience that the institution identifies as a source of over-prescription is, from the auditor's perspective, a source of genuine insight that the institution cannot have. No single institution can observe how its incident classification approach compares to the industry, whether its resilience testing scope is genuinely representative, or how its third-party risk governance looks relative to the population of similar institutions. The external auditor can make those comparisons — and the comparisons reveal patterns of systemic underperformance in specific areas that cannot be attributed to proportionate calibration across the whole industry.
The internal audit finding — that the programme was compliant — is also, from the external auditor's perspective, subject to a limitation that the institution should acknowledge. Internal audit assesses the programme against the framework the institution designed. If the framework was calibrated below the regulatory minimum, internal audit will confirm compliance with a non-compliant framework. The independence of internal audit, in this context, is formal rather than substantive — the auditors are independent of management, but they are not independent of the institution's own interpretive framework. External audit provides the independence from the interpretive framework that internal audit cannot.
Where the Lines of Conflict Are Drawn
The specific areas where internal compliance assessments and external audit findings most frequently diverge are consistent enough across institutions to identify as structural, not incidental.
ICT third-party risk classification. The kowF (the German regulatory shorthand for the DORA supplier criticality classification methodology, formally the Kritikalitätsbewertung von IT-Drittdienstleistern, required under Article 6(6) and Delegated Regulation 2024/1774) methodology — the criticality assessment for ICT third-party service providers required by Article 6(6) and the Delegated Regulation 2024/1774 — gives institutions discretion in how they assess the criticality of their suppliers. Internal programmes consistently classify a smaller proportion of suppliers as critical or important than external auditors consider appropriate. The auditor's cross-sector view reveals that institutions systematically understate the operational dependency on specific providers — particularly cloud infrastructure providers and core banking system vendors — whose failure would have material impact on the institution's operations. The institution's assessment reflects its own analysis; the auditor's assessment reflects what has happened at other institutions when those providers experienced disruptions.
Incident classification thresholds. Article 18 and the RTS on major incident classification (Delegated Regulation 2024/1772) set thresholds for classifying ICT-related incidents as major. The thresholds are defined in terms of impact on clients, financial loss, reputational damage and service availability. Institutions calibrate these thresholds to their risk profile — which, applied consistently with the proportionality principle, is legitimate. External auditors frequently find that the calibration has been set at levels that would exclude events that the auditor, drawing on supervisory guidance and cross-sector experience, considers should be classified as major. The consequence is not merely a documentation finding — it is a finding that the institution would not have reported incidents to its competent authority that it should have reported.
Resilience testing scope and frequency. DORA's basic digital operational resilience testing requirements (Articles 24–25) specify the categories of testing that must be conducted but give institutions discretion over scope, frequency and methodology, subject to proportionality. Internal programmes design testing programmes that they consider adequate for the institution's risk profile. External auditors frequently find that the testing does not cover the full range of disruption scenarios that Articles 24(2)(a)–(f) contemplate — particularly scenario-based testing of ICT business continuity plans, and the source code analysis and security scanning requirements that many institutions have interpreted narrowly.
The documentation of proportionality judgements. Perhaps the most straightforward finding — and one that creates significant unnecessary friction — is the documentation of the proportionality assessments themselves. Institutions that have made genuine, defensible proportionality judgements frequently have not documented those judgements in a form that an external auditor can evaluate. The judgment exists; the rationale exists; but the connection between the institution's risk profile characteristics and the specific implementation choices that reflect those characteristics is not explicitly documented. The external auditor cannot distinguish between a well-reasoned proportionality judgement and an undocumented assumption, and in the absence of documentation, they treat both the same way.
The Path Through the Conflict
The conflict between internal compliance assessments and external audit findings is not, at its core, a conflict about DORA. It is a conflict about interpretation — and interpretation conflicts in regulatory compliance have a resolution pathway that is well established, even if it is not always followed.
Document proportionality judgements explicitly and in advance. The most tractable external audit findings are those that challenge undocumented assumptions. The least tractable are those that challenge documented, reasoned proportionality decisions. Institutions that document their proportionality judgements — recording the specific risk profile characteristics that inform each calibration decision, the compensating controls that support it, and the supervisory guidance or ESA Q&A that they consider relevant — are in a substantially stronger position when those judgements are challenged. This documentation should be prepared as part of the compliance programme, not produced retrospectively in response to audit findings.
Engage supervisors in advance on significant interpretive questions. The proportionality principle creates genuine interpretive questions that reasonable professionals can answer differently. For the interpretive questions that have the largest compliance implications — the third-party criticality classifications, the incident reporting thresholds, the resilience testing scope — institutions that engage with their competent authority in advance, either through supervisory dialogue or through the formal Q&A process, acquire a supervisory view that carries significantly more weight in an external audit than the institution's own assessment. BaFin's approach to such dialogue has become more structured as DORA has bedded in, and the investment in that dialogue is consistently well spent.
Acknowledge the auditor's cross-sector perspective. The external auditor's findings, even where the institution disputes their characterisation, contain useful information. The comparison with other institutions' implementations — even if the comparators are not directly equivalent — identifies areas where the institution's approach diverges from emerging practice in ways that the institution may want to reconsider, independent of the compliance question. Treating every external audit finding as an attack to be defended, rather than as information to be evaluated, consistently produces worse outcomes than engaging with the substance of the finding on its merits.
Establish a structured escalation process for interpretation conflicts. Where genuine interpretation conflicts cannot be resolved between the institution and the external auditor, the correct escalation is to the competent authority — not as an appeal against the finding, but as a supervisory question seeking clarity on the expected interpretation. The ESAs' Q&A process exists precisely for this purpose. Institutions and auditors that use it for significant interpretation questions — rather than treating unresolved conflicts as permanent stalemates — contribute to the supervisory convergence that will eventually reduce the frequency of these conflicts.
The institution's concern about consistency between advisory and audit interpretations within the same firm is legitimate and deserves to be addressed directly by the firms involved. It is not appropriate for an advisory team to help an institution develop a DORA implementation framework and for an audit team from the same firm to subsequently find that framework significantly deficient — without at minimum examining what changed between the advisory engagement and the audit, and whether the advisory team's guidance was accurate. The major advisory and audit firms have internal governance mechanisms for managing these conflicts. Whether those mechanisms are functioning adequately in the DORA context is a question that the firms, and the supervisors who oversee them, should be asking.
What Both Sides Can Agree On
Behind the conflict, there is substantial common ground between institutions and external auditors on DORA implementation — common ground that tends to get lost in the adversarial dynamic of an audit process.
Both sides agree that DORA's flexibility is a feature, not a drafting failure. The Level 1 text was deliberately written to accommodate the diversity of the European financial services sector — from small payment institutions to global systemically important banks — and the proportionality principle is essential to that accommodation. Neither institutions nor external auditors benefit from a regulatory framework that collapses into a single implementation standard regardless of institution size and complexity.
Both sides agree that proportionality has limits, and that those limits are not always clearly defined. The ESA guidelines, the supervisory Q&A process, and the accumulating body of supervisory practice are progressively narrowing the zone of legitimate interpretive discretion — but that process takes time, and in the meantime institutions and auditors are operating in a space where the boundaries are not yet settled.
Both sides agree, ultimately, that the purpose of DORA is operational resilience — not documentation of compliance with operational resilience requirements. Institutions that focus their DORA programmes on building genuine operational resilience capability, rather than on demonstrating compliance with a defined set of requirements, will find that external audit findings — where they occur — are less significant and more easily addressed, because the underlying capability is there even where the documentation of it falls short.
The external auditor who arrives at an institution that has done serious, genuine work on DORA implementation and finds significant findings is not, in most cases, making a bad-faith finding. They are applying a standard that has evolved since the institution's programme was designed, drawing on cross-sector experience that the institution does not have, and exercising the professional scepticism that their role requires. The institution that challenges those findings is not, in most cases, defending inadequate compliance work. It is defending reasonable judgements made in good faith under a framework that was, and remains, genuinely ambiguous in important respects.
Both of those things can be true at the same time. The productive response to that recognition is structured dialogue — between the institution, the auditor and the supervisor — aimed at reaching interpretations that are supervisory consistent, proportionate in practice, and grounded in the operational resilience outcomes that DORA was designed to achieve. That dialogue is happening, slowly and imperfectly, across the European financial services sector. It will take several more supervisory cycles before it produces the convergence that both sides need.