Source: Deutsche Nachrichten
The EU Digital Operational Resilience Act (DORA) requires banks, insurers and other financial entities to maintain a robust and documented ICT risk-management framework. This includes governance, identification of functions and assets, access controls, training and strengthened management of ICT third-party risk. DORA does not, however, impose a general obligation to conduct employee background checks.
For Validato, the relevance lies in the risk-based approach. “DORA requires financial institutions to understand and control their ICT risks. For certain functions with sensitive access rights, proportionate screening can form part of a broader control environment – provided there is a valid legal basis and data-protection and employment-law limits are respected,” says André Naef, CEO of Validato.
Validato recommends that HR, Security and Legal jointly review controls for critical functions and third-party personnel with comparable access rights. The due diligence on ICT providers required by DORA does not automatically authorise screening of their personnel: any screening must be justified separately under the GDPR, Spain’s LOPDGDD and applicable sector-specific law.
