From the journal

ESAs issue guide on DORA oversight activities

The European Supervisory Authorities published a guide on oversight activities under the Digital Operational Resilience Act, focusing on ICT risks from AI in the financial sector.

1 min read

The European Supervisory Authorities (EBA, EIOPA, and ESMA) published a guide on July 15, 2025, detailing oversight activities under the Digital Operational Resilience Act (DORA). The guide outlines the processes used by the ESAs to oversee critical Information and Communication Technology third-party service providers.

The guide is not legally binding and does not replace existing EU legal requirements. It provides high-level explanations regarding the CTPP Oversight framework, governance structure, oversight processes, founding principles, and available tools for overseers.

The ESAs invite public financial entities and third-party providers to utilize this document to prepare for oversight implementation. The guide aims to enhance governance and supervision to address ICT risks associated with frontier AI models in the EU financial sector.

Source: ESMA, official publication, retrieved 2026-08-01