Digital resilience is a matter for top management | ALLES LEGAL #102

🎧 In this third part, learn about DORA’s requirements for risk management.

Listen now:

Podcast: https://paymentandbanking.podigee.io/721-digitale-resilienz-ist-chefsache-was-dora-beim-risikomanagement-verlangt/

In the third episode of our podcast series ‘Alles Legal – Fintech-Recht kompakt’, Josefine Spengler, lawyer at Annerton, talks to host Dana Wondra from Payment & Banking about a key innovation in financial supervisory law: What does DORA require in terms of ICT risk management – and why is digital resilience now a top priority?

🔍 What you’ll learn

A paradigm shift in risk management

Moving away from pure IT security towards integrated, proactive risk management. Risks need to be identified, assessed, managed and documented at an early stage. The crisis resilience of a company is also coming into focus.

ICT risks as a management task

DORA makes management the central authority in the area of digital resilience. It is responsible for strategy, resources, processes and communication – including regular training in IT risks.

Pragmatic implementation in the company

Josefine Spengler shows how DORA requirements can be implemented with structure and a sense of proportion: through clear responsibilities, uniform templates and, where necessary, targeted outsourcing. Even smaller institutions can find practical ways to effectively meet the requirements.

👤 To whom is this episode relevant?

  • Managing directors and board members of regulated institutions
  • Compliance and risk managers
  • IT security officers and internal control functions
  • In-house lawyers and specialists in financial companies

Stay tuned, next week the podcast will look at ICT incidents and reporting and answer the question: What to do in an emergency?

Annerton DORA Monitor Adjust processes, review systems, document evidence: DORA’s requirements are diverse, and implementation calls for clarity and structure.

The Annerton DORA Monitor supports you on your journey to digital resilience: We summarise developments and practical tips for you in a concise format.

📥 Download the first edition free of charge now. – And sign up for our mailing list to be automatically notified by email whenever a new edition is released – ensuring you are reliably guided through the DORA jungle.

About this podcast

Alles Legal – Fintech Recht Kompakt delivers sharp, weekly insights into legal and compliance matters in the world of banking. (in German only)
This podcast is a collaboration between Payment & Banking and PayTechLaw.
Each Wednesday, we unpack the legal developments shaping the financial world – clearly, concisely, and without the legal jargon.
Since 2021, PayTechLaw authors and Annerton attorneys have brought depth and clarity to complex topics.
Whether it’s PSD3, DORA, or FiDA – we provide the legal context you need.
In 20 minutes. No detours.



By continuing, you accept our privacy policy.
You May Also Like
PFOF-Verbot
Read More

The PFOF ban comes into force: What the new BaFin supervisory statement means for brokers and neobrokers

Since 1 July 2026, the ban on Payment for Order Flow (“PFOF”) has also been in force for purely domestic business relationships in Germany. On 22 July 2026, BaFin published a supervisory statement on this matter, in which it sets out in concrete terms for the first time which business models it considers to be compliant with the rules - and which are not.
Read More
FIU-Jahresbericht 2025 – Wesentliche Entwicklungen im Überblick FIU Annual Report 2025 – Key Developments at a Glance
Read More

FIU Annual Report 2025 – Key Developments at a Glance

Germany's FIU recorded a historic number of suspicious activity reports in 2025, while the number of analytical reports declined significantly. Alongside new regulatory requirements and a stronger international focus, neobanks have emerged as a key pillar of reporting activity. This article analyses the most important developments and highlights the questions that remain unanswered in the annual report.
Read More
EuGH schafft Klarheit: Nicht jede Weiterleitung von Geldern Dritter ist ein Zahlungsdienst im Sinne der PSD2 ECJ Clarifies the Scope of PSD2: Not Every Transfer of Third-Party Funds Constitutes a Payment Service
Read More

ECJ Clarifies the Scope of PSD2: Not Every Transfer of Third-Party Funds Constitutes a Payment Service

The ECJ has further clarified the distinction between payment services and other business models. The judgment confirms that merely receiving and forwarding third-party funds does not automatically trigger licensing requirements under PSD2. The decision provides greater legal certainty for FinTechs, platform operators and other businesses handling payment flows, while emphasising that the specific business model remains decisive.
Read More