GERMANY Law and Practice Contributed by: Josefine Spengler and Svetlana Ulrici, Annerton
Concentration Risk Management Managing concentration risk is a key supervisory focus, particularly in relation to cloud and large-scale ICT providers. Regulated entities are expected to identify, assess and mitigate risks arising from reliance on a limited number of providers. Mitigation measures may include diversification, multi-vendor strategies, enhanced monitoring and contractual safeguards. Authorities increasingly expect concentration risk to be addressed at strategic level, not merely as a techni - cal procurement issue. 3.3 Key Operational Resilience Obligations DORA requires senior management of financial enti - ties to take ownership of ICT risk and resilience, including approving the ICT risk strategy, ensuring adequate resources, and embedding operational resilience in the broader risk management and inter - nal control system. In practice, institutions must be able to demonstrate clear roles, escalation paths and decision-making procedures that function under crisis conditions. ICT Risk Management (Core Control Expectations) DORA requires a comprehensive ICT risk manage - ment framework covering identification, protection, detection, response and recovery. Practical baseline elements include an up-to-date asset and depend - ency view, access controls, logging and monitoring, secure configuration, and disciplined vulnerability and patch management. The framework must also address resilience in cloud environments, including operational dependencies and realistic continuity planning. Third-party risk is a central pillar. Financial entities must maintain a structured process for assessing and monitoring ICT outsourcing, including concentration risk and the ability to maintain control over outsourced functions. This includes contractual safeguards and operational readiness to manage incidents involving key providers. Digital Operational Resilience Testing Financial entities must conduct regular testing of their ICT resilience and security posture. Testing is expected to be risk-based and proportionate but suf - ficiently robust to validate whether critical functions can withstand and recover from disruptions. For more
complex or higher-impact entities, advanced testing expectations apply, and supervisors increasingly look for evidence that tests drive measurable improve - ments rather than being treated as a formal exercise. Testing obligations also influence third-party rela - tionships. Providers supporting critical functions are expected to co-operate with testing and provide infor - mation necessary for the institution’s assurance and validation processes. Incident Management and Reporting DORA requires financial entities to maintain structured incident detection, classification and response pro - cedures, including internal escalation, containment and recovery. Reporting obligations are triggered for major ICT-related incidents, assessed using criteria such as impact on critical services, number of affected clients or transactions, duration, geographical spread and material financial or data-related impact. Major incidents are reported to the competent author - ity (BaFin) via a staged approach consisting of initial notification, intermediate updates and a final report after resolution. ICT third-party providers are gener - ally not required to report directly under DORA, but must enable timely reporting through contractual co- operation, rapid information sharing and support dur - ing incident response. Interplay With Other Frameworks (Practical Co-Ordination) In practice, operational resilience programmes are designed to satisfy DORA as the sector “deep regime”, while ensuring consistency, where personal data is affected, with GDPR security and breach han - dling. The central operational challenge is therefore co-ordination: aligning internal processes, maintaining consistent incident narratives across different report - ing channels, and ensuring that third-party contracts and procedures support multi-regime compliance. 3.4 Operational Resilience Enforcement DORA creates an EU oversight framework in which a Lead Overseer (within the European Supervisory Authorities’ (ESAs) Joint Committee set-up) conducts supervision of designated critical ICT third-party pro - viders. The ESAs published the first list of designated
150 CHAMBERS.COM
Powered by FlippingBook