Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What happens when a financial institution cannot prove…
Cyber Security

What happens when a financial institution cannot prove DORA readiness during an audit or regulatory inquiry?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 8, 2026 Domain: Cyber Security

When readiness cannot be demonstrated, compliance becomes a commercial and supervisory problem. Institutions risk remediation demands, contract pressure from clients, weaker RFP outcomes, and greater scrutiny of governance and controls. DORA expects evidence, not assurance statements, so organisations that cannot show documented testing, escalation, and oversight may lose market credibility as well as regulatory confidence.

What auditors are really testing when DORA readiness cannot be shown

Audit failure here is not just about missing paperwork. The real issue is whether the institution can demonstrate that digital operational resilience is governed, tested, and evidenced in a way a supervisor can trust. Under DORA, the burden is on the firm to show that controls, escalation, and oversight are not informal promises but documented operating reality.

That matters because an inability to produce evidence usually signals a broader control gap: incomplete testing records, unclear accountability, weak issue tracking, or resilience arrangements that exist on paper but are not managed consistently. In a regulatory inquiry, that gap can shift the conversation from “are you compliant?” to “how do you know?” and that is a much harder position to defend.

For institutions that rely on third parties, the problem is even sharper because readiness evidence must also cover dependencies, not just internal teams. The DORA rule set is practical, not aspirational, and the DORA — Digital Operational Resilience Act makes clear that supervisory confidence depends on demonstrable governance, testing, and recovery discipline. In practice, many financial institutions discover missing evidence only when an audit or inquiry forces them to reconstruct it retrospectively rather than through routine control ownership.

How the non-demonstration problem shows up in day-to-day supervision

When readiness cannot be proved, the institution is usually dealing with a traceability problem, not only a control problem. The underlying controls may exist, but if they cannot be linked to current policies, test artefacts, exception handling, and accountable owners, the organisation cannot show that the control environment is operating as intended. Supervisors and clients tend to treat that as a credibility issue because resilience claims are only as strong as the evidence behind them.

In practice, the most important evidence sets are straightforward: documented governance decisions, current testing results, remediation tracking, and proof that significant issues were escalated and closed or formally accepted. Where those records are fragmented, a firm may still be doing some of the right work, but it cannot prove continuity between policy, execution, and oversight. That is why readiness failures often surface as documentation gaps during reviews rather than as a single catastrophic technical finding.

  • Evidence of resilience testing should be current enough to support the question being asked, not merely historically interesting.
  • Governance records should show who owns remediation, who accepted risk, and when decisions were made.
  • Third-party oversight should be visible in the same evidence trail, not buried in separate vendor files.
  • Regulatory reviewers usually care less about narrative reassurance than about whether the institution can produce artefacts on demand.

This is where DORA differs from a soft assurance model: the institution is expected to demonstrate repeatable control operation, not simply a stated intent to improve. The guidance breaks down when readiness evidence is assembled ad hoc, because a retrospective pack can expose inconsistent ownership and incomplete control coverage.

Where DORA readiness claims become fragile or contested

Tighter resilience assurance often increases evidence burden, so organisations have to balance operational effort against the need for regulator-ready proof. That tradeoff becomes visible in edge cases such as newly integrated entities, outsourced services, and controls that span multiple lines of defence. A firm may be genuinely improving, but if the evidence chain is incomplete, the review outcome still tends to be negative.

There is also a distinction between a control that is not yet mature and a control that cannot be evidenced. Those are related but not identical problems. The first may justify a remediation plan; the second suggests that oversight itself is weak because the institution does not know, in a verifiable way, whether the control works. Guidance in the market is aligned on this point even where implementation detail varies: supervisors generally expect traceable evidence, while firms often underestimate how much residual risk remains when evidence is scattered across teams and tools.

For cross-border groups, the challenge can become organisational rather than technical. Different business units may describe resilience using different artefacts, which makes a single audit response difficult. That is why readiness should be treated as a managed evidence capability, not a one-off submission exercise. When an institution cannot reconcile its control story quickly, the limitation is usually systemic rather than isolated.

Risk and Threat Considerations

A failure to prove DORA readiness creates supervisory, contractual, and resilience risk at the same time. The immediate exposure is not only a compliance finding; it is the possibility that the institution cannot demonstrate control over important operational dependencies when challenged by regulators, clients, or counterparties.

Failure mechanism: The risk materialises when governance, testing, issue management, and third-party oversight are not recorded in a way that can be reconstructed under audit pressure. That creates an evidence gap, and an evidence gap is often treated as a control weakness because the institution cannot verify that resilience measures are operating consistently.

Impact: The institution may face remediation demands, heightened supervisory scrutiny, weaker procurement or RFP outcomes, and reduced confidence in its operational resilience claims. In severe cases, weak proof of readiness can also expose concentration and dependency issues that were not visible until the inquiry forced a full evidence review.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 set the technical controls, while DORA define the regulatory obligations.

FrameworkControl / ReferenceRelevance
DORAArt. 5 — Governance and organisational frameworkDirectly addresses demonstrable governance and accountability for digital operational resilience.
Art. 9 — ICT risk managementRelevant to the control environment an audit asks the institution to prove is operating.
Art. 11 — Digital operational resilience testingAudit readiness depends on being able to evidence regular testing and its outcomes.
Recommendation — Document governance ownership and decision trails so resilience claims can be evidenced during supervisory review. Show that ICT risk controls are operating, reviewed, and traceable to current risk decisions. Retain test evidence and remediation status so you can prove resilience testing actually occurred.
NIST CSF 2.0GV.OV-01 — OversightThe question centers on governance proof and supervisory confidence in resilience oversight.
Recommendation — Maintain oversight evidence that shows leaders review resilience status and follow up on gaps.

Practitioner Guidance

What to prioritise: Treat evidence ownership as a control in its own right. If the institution cannot produce a current, traceable pack for governance, testing, remediation, and third-party oversight, the first task is to close the evidence chain before trying to polish the narrative.

What to verify: Verify that each resilience claim can be tied to a dated artefact, a named owner, and a clear outcome. If any of those three are missing, the claim is probably too weak for audit use even if the underlying work has happened.

Practitioner takeaway: Readiness is judged less by what an institution says it does than by what it can prove quickly, consistently, and without reconstruction under pressure.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 8, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org