TL;DR: Financial firms preparing for DORA must treat identity governance as part of operational resilience, because access visibility, third-party oversight, and continuous monitoring sit at the centre of incident reporting and risk management, according to Veza’s analysis. The practical shift is from periodic review to continuously governed access paths across internal and external identities.
Editorial analysis by NHI Mgmt Group, based on content published by Veza: “Achieving DORA Compliance: A Practical Guide for Financial Organizations”.
Key questions
Q: What breaks when access governance is still based on periodic reviews under DORA?
A: Periodic reviews miss access that changes between certification cycles, especially in organisations with suppliers, delegated administration, and machine identities.
Q: Why does third-party access raise operational resilience risk in financial services?
A: Third-party access raises resilience risk because external identities often sit outside the organisation’s direct day-to-day control, yet they can still reach critical data and services.
Q: What signs show that identity governance is too weak for DORA compliance?
A: Common signs include stale vendor entitlements, unclear ownership of integration accounts, inconsistent review evidence, and no live view of who can reach critical systems.
Practitioner guidance
- Implement continuous access discovery Maintain a live inventory of who and what can reach critical financial systems, including delegated and inherited permissions.
- Map and govern third-party access lifecycles Assign an owner, purpose, review cadence, and offboarding trigger to every external access path.
- Extend governance to machine identities Include service accounts, tokens, and API keys in identity governance workflows so supplier integrations and automated jobs are visible, reviewable, and revocable when risk changes.
Bottom line: DORA pushes identity governance into the resilience stack, where access visibility and revocation speed affect continuity and reporting.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
DORA turns access governance into a resilience control, not an audit afterthought. Financial firms cannot rely on periodic certification when access is dynamic, federated, and often inherited through suppliers or integrations. The control question is whether the organisation can show current access state fast enough to support incident response and continuity decisions. Practitioners should treat access governance as part of operational resilience architecture, not a separate IAM project.
A few things that frame the scale:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Which controls matter most when DORA testing includes third parties and identities?
A: Access controls, privileged account governance, and recovery validation matter most because they determine whether compromise stays contained or propagates across internal and external dependencies. Identity paths are often the weakest link in resilience testing, especially where service accounts or delegated access are not explicitly scoped and verified.
👉 Read our full editorial: DORA exposes identity governance gaps in financial resilience controls