Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What are the signs that DORA compliance is…
Governance, Ownership & Risk

What are the signs that DORA compliance is becoming unsustainable under manual processes?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 9, 2026 Domain: Governance, Ownership & Risk

The clearest warning signs are repeated evidence hunts before audits, slow incident reporting, inconsistent control records, and teams spending more time assembling proof than improving resilience. Another signal is fragmented visibility across risk, security, and supplier data. When stakeholders cannot get a current view of compliance posture without manual effort, the operating model is already under strain.

When manual DORA compliance stops scaling

Manual compliance tends to break first where DORA asks for repeatable evidence, timely reporting, and coordination across functions. If teams are still chasing attestations, reconciling spreadsheets, and re-building the same audit pack for every request, the issue is no longer administrative inconvenience. It is a sign that resilience, incident, and supplier information are being managed in ways that are too slow and too fragmented for an operational resilience regime. The EU’s own Digital Operational Resilience Act guidance is useful because it keeps the discussion anchored in ongoing governance rather than one-off compliance events.

For practitioners, the key concern is not whether the organisation can pass a single review. It is whether the control model can keep pace with change in assets, suppliers, incidents, and testing without creating backlog and rework. In practice, many teams discover that the first real failure is not a control breach but a delay in proving controls are working, and that delay then spreads into reporting, escalation, and board oversight.

How the breakdown shows up in day-to-day operations

Unsustainable manual compliance is usually visible in the operating rhythm long before it becomes visible in a formal assessment. Evidence requests start to consume more time than actual control improvement. Risk, security, and supplier owners maintain separate records that disagree with one another. Incident timelines are assembled after the fact rather than captured as part of a live process. Each of these conditions creates a different kind of strain, but together they point to the same problem: the organisation is using human effort as the system of record.

That approach can work for a small number of controls, but it becomes brittle when the scope expands across third parties, ICT dependencies, testing, and incident governance. Manual handling also increases the chance that compliance posture reflects the last person who updated a spreadsheet rather than the current state of the environment. DORA is especially unforgiving here because it depends on traceability, consistency, and timeliness across multiple operational domains.

A practical way to judge the situation is to ask whether the business can answer core assurance questions without a coordinated evidence hunt. If the answer requires multiple teams to pause normal work, the model is already inefficient. If the answer cannot be produced quickly during change, incident response, or supplier review, it is not merely inefficient but unreliable. Teams that stay manual for too long often find that exceptions become normal and normal controls become exceptions.

  • Evidence collection is recurring rather than event-driven.
  • Different teams hold different versions of the same control state.
  • Incident and supplier data are updated after deadlines, not during operations.
  • Senior stakeholders need manual consolidation to see current compliance posture.

External frameworks help here because they formalise the difference between managed controls and improvised assurance. The NIST Cybersecurity Framework 2.0 is useful for understanding how governance, identification, protection, detection, and recovery depend on sustained operating discipline, not periodic reporting. This guidance breaks down when the organisation cannot maintain trustworthy records across changes in systems, suppliers, and incidents.

Exceptions, trade-offs, and the point where manual is no longer credible

Tighter compliance handling often increases coordination overhead, so organisations have to balance assurance depth against the cost of repetitive manual work. That trade-off is acceptable for narrow, low-change processes, but it becomes problematic when the control environment is dynamic and the evidence set is large. The practical question is not whether manual work is possible, but whether it still preserves accuracy, timeliness, and accountability at the same time.

There is also a genuine distinction between temporary manual effort and a permanently manual operating model. Temporary manual handling during a remediation programme or control redesign can be reasonable. A persistent dependence on email chains, local spreadsheets, and copied evidence is different, because it hides drift until a deadline forces visibility. Guidance versus consensus is worth stating clearly here: there is broad agreement that manual controls can support early-stage compliance, but there is no serious consensus that they remain sustainable once reporting and assurance become continuous obligations.

The clearest edge case is a mature team with low change volume and a small, stable supplier footprint. Even then, the model becomes fragile if incident volume rises, outsourcing expands, or management wants more frequent assurance. If control ownership, reporting cadence, or supplier complexity increases faster than the process can absorb, manual methods stop being a control choice and become an operational liability.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the technical controls, while DORA define the regulatory obligations.

FrameworkControl / ReferenceRelevance
DORAArt. 11 — ICT Risk Management FrameworkManual compliance strain reflects weak, unsustained ICT governance.
Art. 17 — Advanced ICT Systems, Protocols and ToolsThe question is about when manual processes no longer support ongoing compliance.
Art. 19 — Digital Operational Resilience TestingManual handling often fails when testing evidence and follow-up become recurring.
Recommendation — Use Art. 11 to formalise repeatable control ownership and evidence capture. Adopt advanced tooling where manual coordination no longer delivers timely assurance. Standardise testing records so results and remediation can be tracked continuously.
NIST CSF 2.0GV.OC-03 — Roles, Responsibilities, and AuthoritiesThe strain often comes from unclear ownership across risk, security, and supplier data.
ID.IM-01 — Improvements Are Identified and ManagedRepeated evidence hunts indicate controls are not being improved as the environment changes.
RC.RP-1 — Recovery Plan Executed During or After an IncidentSlow incident reporting weakens the organisation's ability to execute response and recovery.
Recommendation — Clarify control ownership so compliance evidence is maintained by accountable teams. Track recurring manual work as a signal to improve the control operating model. Ensure incident records and reporting steps are executable without manual reconstruction.
CIS Controls v84.1 — Establish and Maintain an Inventory of Enterprise AssetsFragmented visibility often starts with inconsistent records across systems and owners.
17.2 — Establish and Maintain a Risk Management ProcessManual DORA compliance becomes strained when risk evidence is too scattered to govern.
Recommendation — Maintain a current asset inventory so compliance evidence is not rebuilt from scratch. Integrate compliance evidence into the risk process instead of handling it separately.

Practitioner Guidance

What to prioritise: Treat repeat evidence hunting, slow reporting, and conflicting control records as operating-model symptoms, not isolated process defects. The first decision should be whether the organisation is trying to govern too much through ad hoc coordination rather than controlled workflows and shared records.

What to verify: Check whether the same compliance question can be answered from a current source of truth without re-collecting evidence from multiple owners. If the answer depends on who is asked, when they are asked, or which spreadsheet is current, the process is already too fragile for sustained assurance.

What good looks like: Current control status, incident status, and supplier status should be visible without a dedicated evidence project. Teams should spend most of their time fixing weaknesses and only a small, bounded amount of time assembling proof.

Practitioner takeaway: Manual compliance becomes unsustainable when the organisation can still work, but cannot prove its current state quickly enough to support operational resilience, escalation, and governance.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 9, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org