Back to blog

The management body's responsibility under DORA (and what it really implies)

DORA places ICT resilience under the management body's responsibility. What that means for a board, committee and executive.

By Arthur Chédeville··Read time : 6 min·For Executives, board, committees
Management body responsibility under DORA

There is a persistent misunderstanding around DORA: believing it « technical ». Many entities treated it as an IT or CISO project. Yet the regulation places digital operational resilience under the direct responsibility of the management body — board of directors, executive board, management committee depending on the structure. This is not a governance detail: it is a point the supervisor examines, and one of its control priorities for 2026 concerns precisely ICT risk management frameworks and the identification of the control function.

What DORA expects from the management body

The management body cannot simply be informed. DORA assigns it a final and active responsibility across several dimensions:

  • The resilience strategy. Defining and approving the entity's digital operational resilience strategy.
  • ICT risk appetite. Setting the acceptable level of risk — the risk appetite — regarding information technology.
  • Steering and trade-offs. Allocating resources, arbitrating budgets, tracking remediation. Resilience has a cost, and it is for the management body to bear it.
  • The organisation of controls. Ensuring clear roles, the independence of control functions, an audit mechanism and regular reporting.

The underlying message: you do not delegate responsibility, even when you outsource the technical side.

The notion of « evidence » applied to governance

What makes this responsibility concrete is that the supervisor expects evidence of its effective exercise. Governance that exists on the org chart but leaves no traces is not enough. The typical evidence expected:

  • Decisions and minutes of committees dealing with ICT matters.
  • Regular reporting to the management body on the state of resilience.
  • ICT KPIs and KRIs tracked over time.
  • Documented budget trade-offs and resource allocations.
  • Follow-up of remediation plans and their progress.

In other words, the question is not « is your management body responsible? » (the regulation says so), but « can you demonstrate it? ».

The 2026 focus: completeness of narrative reports

The ACPR has announced particular vigilance on the completeness of narrative reports, with enhanced expectations on two areas that directly touch governance: the risk profile (including exposure to ICT and provider risks) and the risk management system, with the explicit identification of the control function for the ICT risk management framework. A report that stays vague on « who controls what » is now a negative signal.

The sectoral obligations that call the management body to its duties

The link between DORA and governance bodies also materialises in regulatory submissions. On the banking side, an annex on ICT risk management must be submitted with the internal control report. On the insurance side, RSR-related reports now integrate DORA information. ICT resilience thus enters the documents the management body validates and formally assumes.

What the management body should be able to affirm

In practice, a management body well positioned on DORA should be able to answer « yes, and here is the evidence » to questions such as:

  • Have we approved an ICT resilience strategy, and when?
  • Is our ICT risk appetite defined and documented?
  • Do we receive regular, usable reporting on the subject?
  • Are our control functions clearly identified and independent?
  • Are our decisions and trade-offs traced?
  • Are our narrative reports complete on the risk profile?

If any of these answers is vague, it is a priority undertaking — because it is exactly what the 2026 control comes to examine.

Making governance demonstrable

The challenge is not to invent governance, but to make it traceable and presentable. Many entities do things without easily being able to prove them: decisions exist, but scattered; reporting exists, but rebuilt at each request. Structuring this evidence on a continuous basis avoids the painful exercise of reconstruction before each committee or each control.

Where Axenia fits in. Axenia links governance evidence — decisions, indicators, remediation tracking — to the corresponding DORA requirements, and facilitates the production of consolidated reporting for your committees and board. The management body's responsibility becomes demonstrable on the record, not merely asserted.


This article is educational in purpose and does not constitute legal advice. Refer to the official texts and your competent authority's guidance.

See how Axenia equips your governance reporting. Book a demo →