For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/compliance/dora-continuity-and-response-plans.md.
Compliance ↗

DORA continuity planning: functions, recovery and exercises

Continuity plans should follow the services the firm must sustain. Map dependencies, set recovery objectives and exercise the decisions as well as the technology.

AI-generated illustration: Coordinator planning recovery order with an offline call tree.

The cover image is an AI-generated editorial illustration. Screens and documents are illustrative concepts.

An ICT continuity plan needs to explain how the firm sustains or restores its important functions during disruption. A list of backup jobs is only part of that answer.

DORA Articles 11 and 12 address response, recovery and backup arrangements. The detailed duties depend on the applicable framework and exemptions. Confirm those before copying a plan from another organisation.

Start with the business impact

Identify the functions that matter, the consequences of interruption and the systems and suppliers they depend on. Set recovery objectives that reflect those consequences.

A server being available does not necessarily mean the business function has recovered. Authentication, data integrity, network access and supplier interfaces may all be necessary. Include those dependencies in the sequence.

Write instructions that remain usable during an outage

Define activation criteria, roles, contact routes and the authority to make disruptive changes. Keep the plan accessible when the primary network or identity system is unavailable.

Address plausible scenarios such as cyberattack, supplier failure, loss of infrastructure and unavailable personnel. Explain both short-term workarounds and the route back to normal service.

Management-body oversight applies to the continuity policy and response and recovery plans under Article 5. Record the relevant approval and review, with enough detail to identify the version and decisions.

Exercise the service, not just the document

Article 11(6) requires testing at least yearly and after substantive changes to ICT systems supporting critical or important functions, within the applicable regime. It also specifies cyberattack and switchover scenarios for entities other than microenterprises.

Plan exercises safely with system and supplier owners. Check decision-making, communications, recovery steps and whether the expected data is available and trustworthy. Record what did not work and how it will be corrected.

Do not confuse a successful backup job with demonstrated restoration. Equally, an exercise should not create avoidable production risk merely to make it feel realistic.

Keep improvement attached to ownership

Track corrective actions through verification and update the plan after meaningful changes. Preserve the exercise record and management decisions so the next review can see what improved.

Incident reporting runs alongside continuity work and has its own triggers. The DORA reporting guide covers that distinction. FM’s compliance service can help connect the plans, requirements and evidence into an agreed programme.

← Back to all insights
Questions or inquiry? [email protected] Contact us →