DORA compliance gap leaves US FinTechs exposed

DORA

Risk managers across New York, Chicago and San Francisco are discovering that Europe’s operational resilience regime has quietly become their problem too.

According to Risk Publishing in June 2026, US banks, broker-dealers and insurance groups have been fielding urgent calls from European counterparts demanding evidence of resilience controls that most American firms had never previously been asked to produce, said AscentAI.

AscentAI recently discussed DORA for US financial firms, and who’s impacted and what’s at stake.

The Digital Operational Resilience Act (DORA), adopted by the EU in 2022 and enforceable since 17 January 2025, obliges financial institutions to withstand, respond to and recover from disruptions to information and communication technology.

Crucially, its scope goes well beyond cybersecurity, capturing IT system failures, power outages and third-party provider incidents – anything that interrupts a firm’s digital operations.

DORA was conceived to replace a patchwork of inconsistent, often non-binding EU guidelines that varied by member state and sector.

In their place sits a single framework spanning all EU states and financial sectors, with a reach that extends across the Atlantic. US banks with EU subsidiaries, American cloud providers serving EU banks, US FinTechs with EU clients, insurers with EU reinsurance arrangements and asset managers running EU funds all fall within its remit.

Affected organisations must comply with DORA’s five pillars: ICT risk management, incident reporting to competent authorities within prescribed timelines, resilience testing (including threat-led penetration testing at least every three years for significant entities), third-party risk management via a Register of Information, and voluntary cyber threat intelligence sharing.

Recent survey data suggests US firms’ readiness is lacking, particularly around resilience testing and third-party risk. Firms already operating under ISO 27001, NIST CSF or SOC 2 have a head start, with roughly 70-80% of Pillar 1 requirements typically already addressed by such frameworks.

FinTechs with less mature GRC capabilities, however, face a steeper climb. Recommended steps include determining which provisions apply (smaller organisations may qualify for a simplified framework under Article 16), performing a gap assessment, documenting an ICT risk management framework with board-level governance, building a third-party register, testing regularly, establishing incident reporting processes and training staff.

The penalties sharpen the incentive. Financial entities face fines of up to 2% of total annual worldwide turnover for ICT risk management or incident reporting failures, alongside public disclosure of breaches and suspension of ICT service agreements.

Critical third-party providers risk penalties of up to EUR 5m at entity level and EUR 500,000 for individuals, plus daily periodic payments of 1% of average daily worldwide turnover for up to six months. Senior managers can be held personally liable for up to EUR 1m each.

The message for US institutions is clear, in that DORA belongs in the compliance framework alongside FINRA and SEC obligations. Finance operates across borders, and so does this regulation.

Read the full AscentAI post here.

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.