Management body responsibility for ICT risk
The management body is ultimately accountable for the organization's ICT risk management framework and its implementation. They must actively approve strategies, allocate necessary resources, and maintain sufficient knowledge to make informed decisions regarding digital operational resilience.
What it means
Article 5 shifts ICT risk from a purely technical concern to a core governance requirement. It mandates that the board or executive leadership cannot simply delegate "IT security" to a CISO or IT department; while tasks can be delegated, ultimate legal and operational accountability remains with the management body.
In practice, this means the management body must ensure that ICT risk is integrated into the overall business risk appetite. They are responsible for ensuring there is enough funding, staffing, and tooling to meet DORA requirements, and they must oversee the effectiveness of the controls put in place.
Furthermore, there is a requirement for "competence." Management cannot claim ignorance of technical risks; they must proactively acquire the knowledge necessary to challenge reports and oversee ICT risk management effectively.
How to meet it
- Establish a formal ICT Risk Management Framework that is explicitly reviewed and signed off by the board.
- Implement a recurring reporting cycle (e.g., quarterly) where the CISO or CIO presents the current ICT risk profile and resilience status to the management body.
- Define and approve a specific budget for ICT operational resilience, ensuring it covers both preventative measures and recovery capabilities.
- Create a tailored training program for board members focused on digital resilience, emerging cyber threats, and DORA compliance.
- Formally document the roles and responsibilities of the management body regarding ICT risk within the corporate governance charter.
- Integrate ICT risk KPIs into the organization's overarching business continuity and risk management strategies.
Evidence an auditor asks for
- Board meeting minutes documenting discussions, challenges, and formal approvals of ICT risk policies and strategies.
- Signed approval records for the annual ICT budget specifically highlighting investments in digital resilience.
- Training logs or certificates proving that members of the management body have completed ICT risk education.
- Copies of board-level reports (dashboards) showing how ICT risks are communicated to leadership.
- An organizational chart and governance charter clearly mapping accountability for ICT risk to the management body.
Common pitfalls
- "Rubber stamping": Providing signatures on policies without evidence in meeting minutes that the board actually reviewed or questioned them.
- Over-delegation: Treating ICT risk as a siloed IT function rather than a business risk, leading to a lack of active oversight by executives.
- Knowledge gaps: Relying on overly technical reports that the management body cannot interpret, resulting in an inability to make "informed decisions."