DORA for Maltese Financial Institutions: Six Questions Your Board Should Be Asking

Six questions the board of a Maltese financial institution should be asking its technology function about DORA — and what credible answers actually look like.

DORA has been applicable since 17 January 2025. For Maltese financial institutions — banks, payment institutions, EMIs, investment firms, fund managers, insurance undertakings, CASPs — the regulation is in force and the MFSA is the competent authority. The first wave of supervisory engagement has begun. Some boards have been ahead of this. Most are still finding their footing.

This is a reading of the six questions a Maltese board should be asking the technology function, in plain language, with what a credible answer sounds like.

Free · 4 minutes

Do you know where AI is already being used in your business — and what it can see?

Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.

Who this is for

  • The non-executive director on the audit or risk committee of a Maltese-licensed financial institution who wants a board-level reading of DORA exposure.
  • The chair of a Maltese FI who needs to satisfy themselves that the management body’s DORA accountability is being exercised meaningfully.
  • The CEO of a Maltese FI translating between board concerns and the technology function’s compliance programme.

The six questions

1. Have we identified our critical and important functions, and do they match what MFSA would expect us to identify?

DORA pivots on the concept of “critical or important function” — services whose disruption would materially impact the firm, its clients, or the market. Maltese FIs sometimes inherit this list from a group-level identification exercise that does not fit Maltese operations. A credible answer names each critical or important function, identifies the business owner, and shows that the list has been reviewed against MFSA’s expectations for an entity of this size and complexity.

2. Do we have an ICT risk management framework that satisfies DORA Article 6 — and has the management body approved it?

Article 6 makes the management body ultimately responsible for the framework. A credible answer references a specific framework document, the date of board approval, the date of the most recent annual review, and the ICT risk appetite statement that flows from it. “We have a security policy” is not an answer to this question.

3. Who is on our register of ICT third parties — and have we identified our concentration risks?

DORA Article 28 requires a register of all ICT third-party contractual arrangements. For Maltese firms operating in a small vendor market, the register frequently reveals concentration the firm did not previously articulate — the same cloud region, the same managed service provider, the same custody sub-provider across multiple critical functions. A credible answer produces the register, identifies the material concentrations, and describes the mitigation.

4. Can we report a major ICT-related incident within DORA’s timelines?

DORA Article 19 establishes the major-incident reporting regime. The initial notification clock is hours, not days. A credible answer describes the incident classification procedure, names the people who can classify, and points to a tested playbook. If the playbook has never been exercised, the answer is incomplete.

5. What is our digital operational resilience testing programme — and have we been told we are in scope for TLPT?

DORA Chapter IV requires every financial entity to have a digital operational resilience testing programme. For most Maltese FIs this means annual basic testing — vulnerability scans, scenario-based tests, source code reviews. For those identified as significant by MFSA, threat-led penetration testing under Article 26 applies. A credible answer says what testing the firm does, on what cycle, and whether MFSA has indicated TLPT scope.

6. Where is the gap between where we are and where MFSA expects us to be?

This is the meta-question. A credible answer is honest about what is in good shape, what is in progress, and what is still missing. The worst answers are the ones that claim full compliance. Few firms are at full compliance eighteen months in. MFSA knows this; supervisors are looking for evidence of credible progress rather than claims of completion.

How MFSA reads the answers

MFSA’s supervisory style emphasises substance over form. The recurring patterns in early DORA engagement:

Inherited group frameworks are scrutinised closely. A Maltese subsidiary of a continental group cannot rely on the parent’s compliance programme without demonstrating that the parent’s controls are operating at the Maltese entity. Group reporting is acceptable; group-only controls are not.

“Proportionality” is not a get-out. Smaller firms have less depth of obligation. They do not have an absence of obligation. The framework, the register, the testing programme, the incident reporting — all of these exist for a small firm too, at proportional depth.

Board engagement is tested explicitly. MFSA inspectors ask board members what they have seen and approved. Board members who cannot describe the ICT framework in their own terms fail the test.

How we engage with this

We read DORA programmes from a board perspective. As part of a Technology Control Review scoped to a Maltese FI’s DORA position, we work through the six questions, identify the gaps, and write the assessment in language a non-executive director can read and challenge against.

We do not implement DORA programmes. We do not run incident response. We do not sell GRC software. We read what is there, identify what is missing, and write it down for the board.

Pricing is published at /pricing/. If your board is preparing for the next supervisory engagement on DORA, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming