DORA Article 5 doesn’t ask the board collectively to understand ICT risk. It requires each individual board member to maintain sufficient knowledge and skills — a personal obligation, not a collective one. That single drafting choice reshapes what board reporting on technology risk actually needs to look like.
Boards have received technology briefings for years without much scrutiny of format or depth. DORA changes the standard being applied to those briefings specifically: supervisors assess management body oversight by examining minutes, board papers, decision logs, and reporting packs — verbal briefings without documentation don’t demonstrate compliance. This is what that shift actually requires of board reporting, read against Article 5’s specific text and how supervisors have signalled they’ll test it.
Who this is for
- The board secretary or CTO responsible for the technology content of board papers at a DORA-scope entity.
- The board member who wants to know what “sufficient knowledge and skills” actually requires of them individually, not just of the board as a body.
The individual obligation, not the collective one
Article 5(4) is specific: each member of the management body must actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk, including regular training commensurate with the ICT risk being managed. This is not satisfied by the board having one technically fluent member who briefs the others informally — every individual member carries the obligation, and supervisors have been signalled to interview board members directly during SREP assessments specifically on DORA compliance. A board reporting pack built to inform “the board” as an undifferentiated group, without a training record showing each individual member has kept pace, satisfies the collective spirit of good governance but not the letter of Article 5(4).
Free · 4 minutes
Do you know where AI is already being used in your business — and what it can see?
Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.
What the board must specifically approve, not just receive
Article 5(2) sets out specific board duties that go beyond general oversight: bearing ultimate responsibility for ICT risk, approving the digital operational resilience strategy and risk tolerance level, approving and periodically reviewing the ICT business continuity policy and response and recovery plans, approving and reviewing ICT internal audit plans, and approving the policy governing third-party ICT provider arrangements — including the specific reporting channels that escalate material changes and major incidents to the board. Each of these is an approval action, not a briefing — a board paper that presents the ICT risk framework as background information, without a specific resolution recording the board’s approval, hasn’t satisfied the requirement even if every board member read and understood the content.
The “paper governance” trap
Supervisors, the CSSF among them explicitly, describe a specific failure pattern they watch for: a formally approved ICT risk management framework that exists on paper, alongside a board that cannot demonstrate it actually oversaw, budgeted, and periodically reviewed it in practice. During inspections, supervisors request board minutes, ICT audit plan follow-ups, evidence of individual director training, and proof of a budget line specifically allocated to digital operational resilience. The absence of any of these — even where the underlying framework document is technically sound — is treated as a governance failure in its own right. A board reporting process needs to produce this evidence as a natural by-product of how meetings run, not as a retrospective reconstruction exercise once an inspection is announced.
The third-party monitoring role, made explicit
Article 5(3) requires entities beyond microenterprises to establish a specific role monitoring ICT third-party arrangements, or designate a senior management member as responsible for the related risk exposure and documentation. This role’s reporting line to the board needs to be a named, standing item in board reporting — not folded into a general risk update — since it’s the mechanism through which the Article 5(2)(i) escalation of material third-party changes and major incidents is meant to actually reach the board.
What’s actually at stake for individual board members
This isn’t an abstract governance-best-practice conversation. Senior managers can face personal fines of up to €1,000,000 under DORA’s penalty provisions, and delegating ICT risk oversight to a CISO or IT leadership team, without the board itself maintaining documented, active oversight, does not discharge the board’s own liability. Beyond financial penalties, supervisors can suspend or prohibit specific ICT services, require appointment of a special manager, or temporarily ban individual senior managers from exercising management functions — consequences that attach to individuals, not just the entity.
What board reporting needs to produce
- Documented individual training records for every board member, commensurate with the entity’s ICT risk profile, refreshed on a regular cadence.
- Board papers structured around specific approval resolutions for strategy, risk tolerance, BCP/recovery plans, and audit plans — not general awareness briefings.
- A visible, allocated budget line for digital operational resilience, reviewed and reapproved on a standing cycle.
- A named third-party ICT monitoring role reporting to the board as a standing agenda item, not merged into general risk reporting.
- Board minutes that record the substance of ICT risk discussion and decisions, not just the fact that a paper was tabled.
How we engage with this
We read board reporting structures against what DORA Article 5 specifically requires — individual accountability, documented approval, and evidence a supervisor would actually accept — as a Technology Control Review. The output is a written assessment identifying where board papers inform without documenting approval, the specific gap supervisors are trained to find.
We don’t sit on boards. We don’t deliver director training. We don’t represent entities to supervisors. We read what’s there, identify what’s missing, and write it down for the people who have to decide what to do about it.
Pricing is published at /pricing/. If your board reporting hasn’t been tested against Article 5’s specific approval and documentation requirements, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Governance is what happens when nobody is watching.
Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming