The clearest warning signs are repeated evidence hunts before audits, slow incident reporting, inconsistent control records, and teams spending more time assembling proof than improving resilience. Another signal is fragmented visibility across risk, security, and supplier data. When stakeholders cannot get a current view of compliance posture without manual effort, the operating model is already under strain.
When manual DORA compliance stops scaling
Manual compliance tends to break first where DORA asks for repeatable evidence, timely reporting, and coordination across functions. If teams are still chasing attestations, reconciling spreadsheets, and re-building the same audit pack for every request, the issue is no longer administrative inconvenience. It is a sign that resilience, incident, and supplier information are being managed in ways that are too slow and too fragmented for an operational resilience regime. The EU’s own Digital Operational Resilience Act guidance is useful because it keeps the discussion anchored in ongoing governance rather than one-off compliance events.
For practitioners, the key concern is not whether the organisation can pass a single review. It is whether the control model can keep pace with change in assets, suppliers, incidents, and testing without creating backlog and rework. In practice, many teams discover that the first real failure is not a control breach but a delay in proving controls are working, and that delay then spreads into reporting, escalation, and board oversight.
How the breakdown shows up in day-to-day operations
Unsustainable manual compliance is usually visible in the operating rhythm long before it becomes visible in a formal assessment. Evidence requests start to consume more time than actual control improvement. Risk, security, and supplier owners maintain separate records that disagree with one another. Incident timelines are assembled after the fact rather than captured as part of a live process. Each of these conditions creates a different kind of strain, but together they point to the same problem: the organisation is using human effort as the system of record.
That approach can work for a small number of controls, but it becomes brittle when the scope expands across third parties, ICT dependencies, testing, and incident governance. Manual handling also increases the chance that compliance posture reflects the last person who updated a spreadsheet rather than the current state of the environment. DORA is especially unforgiving here because it depends on traceability, consistency, and timeliness across multiple operational domains.
A practical way to judge the situation is to ask whether the business can answer core assurance questions without a coordinated evidence hunt. If the answer requires multiple teams to pause normal work, the model is already inefficient. If the answer cannot be produced quickly during change, incident response, or supplier review, it is not merely inefficient but unreliable. Teams that stay manual for too long often find that exceptions become normal and normal controls become exceptions.
- Evidence collection is recurring rather than event-driven.
- Different teams hold different versions of the same control state.
- Incident and supplier data are updated after deadlines, not during operations.
- Senior stakeholders need manual consolidation to see current compliance posture.
External frameworks help here because they formalise the difference between managed controls and improvised assurance. The NIST Cybersecurity Framework 2.0 is useful for understanding how governance, identification, protection, detection, and recovery depend on sustained operating discipline, not periodic reporting. This guidance breaks down when the organisation cannot maintain trustworthy records across changes in systems, suppliers, and incidents.
Exceptions, trade-offs, and the point where manual is no longer credible
Tighter compliance handling often increases coordination overhead, so organisations have to balance assurance depth against the cost of repetitive manual work. That trade-off is acceptable for narrow, low-change processes, but it becomes problematic when the control environment is dynamic and the evidence set is large. The practical question is not whether manual work is possible, but whether it still preserves accuracy, timeliness, and accountability at the same time.
There is also a genuine distinction between temporary manual effort and a permanently manual operating model. Temporary manual handling during a remediation programme or control redesign can be reasonable. A persistent dependence on email chains, local spreadsheets, and copied evidence is different, because it hides drift until a deadline forces visibility. Guidance versus consensus is worth stating clearly here: there is broad agreement that manual controls can support early-stage compliance, but there is no serious consensus that they remain sustainable once reporting and assurance become continuous obligations.
The clearest edge case is a mature team with low change volume and a small, stable supplier footprint. Even then, the model becomes fragile if incident volume rises, outsourcing expands, or management wants more frequent assurance. If control ownership, reporting cadence, or supplier complexity increases faster than the process can absorb, manual methods stop being a control choice and become an operational liability.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while DORA define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| DORA | Art. 11 — ICT Risk Management Framework | Manual compliance strain reflects weak, unsustained ICT governance. |
| Art. 17 — Advanced ICT Systems, Protocols and Tools | The question is about when manual processes no longer support ongoing compliance. | |
| Art. 19 — Digital Operational Resilience Testing | Manual handling often fails when testing evidence and follow-up become recurring. | |
| Recommendation — Use Art. 11 to formalise repeatable control ownership and evidence capture. Adopt advanced tooling where manual coordination no longer delivers timely assurance. Standardise testing records so results and remediation can be tracked continuously. | ||
| NIST CSF 2.0 | GV.OC-03 — Roles, Responsibilities, and Authorities | The strain often comes from unclear ownership across risk, security, and supplier data. |
| ID.IM-01 — Improvements Are Identified and Managed | Repeated evidence hunts indicate controls are not being improved as the environment changes. | |
| RC.RP-1 — Recovery Plan Executed During or After an Incident | Slow incident reporting weakens the organisation's ability to execute response and recovery. | |
| Recommendation — Clarify control ownership so compliance evidence is maintained by accountable teams. Track recurring manual work as a signal to improve the control operating model. Ensure incident records and reporting steps are executable without manual reconstruction. | ||
| CIS Controls v8 | 4.1 — Establish and Maintain an Inventory of Enterprise Assets | Fragmented visibility often starts with inconsistent records across systems and owners. |
| 17.2 — Establish and Maintain a Risk Management Process | Manual DORA compliance becomes strained when risk evidence is too scattered to govern. | |
| Recommendation — Maintain a current asset inventory so compliance evidence is not rebuilt from scratch. Integrate compliance evidence into the risk process instead of handling it separately. | ||
Practitioner Guidance
What to prioritise: Treat repeat evidence hunting, slow reporting, and conflicting control records as operating-model symptoms, not isolated process defects. The first decision should be whether the organisation is trying to govern too much through ad hoc coordination rather than controlled workflows and shared records.
What to verify: Check whether the same compliance question can be answered from a current source of truth without re-collecting evidence from multiple owners. If the answer depends on who is asked, when they are asked, or which spreadsheet is current, the process is already too fragile for sustained assurance.
What good looks like: Current control status, incident status, and supplier status should be visible without a dedicated evidence project. Teams should spend most of their time fixing weaknesses and only a small, bounded amount of time assembling proof.
Practitioner takeaway: Manual compliance becomes unsustainable when the organisation can still work, but cannot prove its current state quickly enough to support operational resilience, escalation, and governance.
Related resources from NHI Mgmt Group
- Why do manual compliance processes fail under Solvency II scrutiny?
- Why do manual segregation of duties and user access review processes create compliance risk under Provision 29?
- How should security and compliance teams automate DORA compliance without creating more operational overhead?
- How should security teams govern non-human identities for compliance?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org