pressebox_600x600_v2.png ()

PresseBox - unn | UNITED NEWS NETWORK GmbH

https://www.pressebox.de

24.09.2026

DORA and the human factor: personnel controls in critical financial-services roles

Zürich, 24.09.2026 (PresseBox) - The EU Digital Operational Resilience Act (DORA) requires banks, insurers and other financial entities to maintain a robust and documented ICT risk-management framework. This includes governance, identification of functions and assets, access controls, training and strengthened management of ICT third-party risk. DORA does not, however, impose a general obligation to conduct employee background checks.

For Validato, the relevance lies in the risk-based approach. “DORA requires financial institutions to understand and control their ICT risks. For certain functions with sensitive access rights, proportionate screening can form part of a broader control environment – provided there is a valid legal basis and data-protection and employment-law limits are respected,” says André Naef, CEO of Validato.

Validato recommends that HR, Security and Legal jointly review controls for critical functions and third-party personnel with comparable access rights. The due diligence on ICT providers required by DORA does not automatically authorise screening of their personnel: any screening must be justified separately under the GDPR, Spain’s LOPDGDD and applicable sector-specific law.
mehr...