AmCham EU publishes position on Digital Operational Resilience Act (DORA)

The use of technology in financial services is not new. In fact, the financial services industry has always been at the forefront of testing and adopting new technologies to transform the financial services industry, increase competition and efficiency, as well as offering new solutions to its customers. What is new is the speed of innovation we are seeing in recent years covering all aspects of the financial services sector and leading to the development of new business models, services and products.

Amongst these new developments is the use of information and communications technology (ICT), which finds itself at continuously greater use in the sphere of finance, requiring greater security resilience for firms. The Digital Operational Resilience Act (DORA) represents thus a crucial step towards a harmonized EU framework for digital resilience in financial operations. Due to the unique factors coming together in the financial services sector, given its fast evolution, increased diversification and international nature, additional care needs to be taken into consideration in the adoption of the new proposed regulation. Read our position here.

News
7 Mar 2021
Digital, Financial services
AmCham EU publishes position on Digital Operational Resilience Act (DORA)

The use of technology in financial services is not new. In fact, the financial services industry has always been at the forefront of testing and adopting new technologies to transform the financial services industry, increase competition and efficiency, as well as offering new solutions to its customers. What is new is the speed of innovation we are seeing in recent years covering all aspects of the financial services sector and leading to the development of new business models, services and products.

Amongst these new developments is the use of information and communications technology (ICT), which finds itself at continuously greater use in the sphere of finance, requiring greater security resilience for firms. The Digital Operational Resilience Act (DORA) represents thus a crucial step towards a harmonized EU framework for digital resilience in financial operations. Due to the unique factors coming together in the financial services sector, given its fast evolution, increased diversification and international nature, additional care needs to be taken into consideration in the adoption of the new proposed regulation. Read our position here.

As the voice of American businesses invested in Europe, AmCham EU emphasises the transatlantic dimension and the need for a coordinated international approach to ICT risk management in this paper. The recommendations contained within this paper therefore focus on building on existing international practices and call for openness to incorporating international best practices into the implementation of the EU’s digital operational resilience.

The issues addressed in this paper include general principles; cloud computing; third-country provisions; intragroup delegation; ICT risk management; legislative consistency; the designation critical third-party providers; testing; incident reporting; EU oversight of critical third-party providers; contractual arrangements; outsourcing and sub-outsourcing; cyber threat information sharing; sanctions and penalties; oversight fees; and the implementation period.

Related items

Position Paper
13 May 2026

Strengthening Europe’s cybersecurity framework through simplification

The review of the Cybersecurity Act (CSA 2.0) is an opportunity to build a more coherent, outcome-oriented EU cybersecurity framework. While the proposal recognises fragmentation across the Single Market, further simplification is needed to reduce overlaps and support effective compliance.

A harmonised approach to risk assessment and supervision can strengthen resilience while avoiding duplicative obligations. Certification and supply-chain measures should remain risk-based, objective, technical and aligned with international standards. Structured industry engagement and clear designation thresholds under the ICT Supply Chain Framework and a secure-by-design approach to policymaking will be essential to support cybersecurity and global interoperability. Read more on how CSA 2.0 can strengthen resilience across the Single Market.

Digital
Read more
Read more about Strengthening Europe’s cybersecurity framework through simplification
News
4 May 2026

Discussing financial services with policymakers in Paris and Strasbourg

From Monday, 27 to Wednesday, 29 April, AmCham EU travelled to Paris, France and the European Parliament in Strasbourg, France for a series of meetings on EU financial services policy developments. The delegation engaged with representatives from French and European financial authorities, Members of the European Parliament, Accredited Parliamentary Assistants and Group Policy Advisers, to share business perspectives on the EU’s financial services agenda. Discussions focused on how to improve Europe’s competitiveness, deepen capital markets and create the right conditions for innovation in digital finance. Members also highlighted the need for more coherent and interoperable rules that reduce complexity while encouraging long-term investment through risk-based regulation.

Financial services
Read more
Read more about Discussing financial services with policymakers in Paris and Strasbourg
Close-up of a laptop keyboard with blue backlighting, highlighting the shift key and adjacent keys in a soft-focus perspective.
News
13 Apr 2026

Industry calls for ambitious and simplified implementation of the AI Act 

Together with 14 other associations, AmCham EU has signed a joint statement on the European Commission’s Digital Omnibus on AI, calling for a clear, simple and innovation-friendly implementation of the AI Act. Co-legislators should swiftly reach an agreement on an ambitious final text that keeps simplification at its core. Measures to streamline overlaps with existing EU legislation and improve legal certainty are essential, alongside targeted adjustments to ensure the framework remains practical. This includes extending grace periods for generative AI labelling requirements, ensuring greater legal clarity for AI systems entering the EU market, preserving the risk-based approach of the AI Act by exempting non high-risk systems from registration, and supporting fixed compliance deadlines for high-risk systems.

Learn how the EU can support a clear and innovation friendly framework in the joint statement.

Digital
Read more
Read more about Industry calls for ambitious and simplified implementation of the AI Act