Walk into most DORA programmes and you'll find the same artefact: a spreadsheet with several hundred rows, one per regulatory requirement, each mapped to a policy, a control, an owner and a RAG status. Months of work. Mostly green. And almost entirely beside the point.
That spreadsheet answers one question: can we show a supervisor that a document exists for each thing the regulation mentions? DORA asks a different question: when something critical breaks, does your firm keep operating? Those are not the same question, and the gap between them is where firms are quietly failing right now — with fully green trackers.
The 2am test
Here is the scenario the regulation is actually about. It's 2am. Your payments processor — or your cloud platform, or the SaaS product your operations team lives in — has gone down, and their status page is lying to you. Their account manager isn't answering. Your service desk is fielding calls.
Now the questions that matter. Who in your firm has the authority to invoke the contingency? Not "who is accountable on the RACI" — who will actually make the call, at 2am, without convening a committee? Do they know they have that authority? Have they ever used it? What triggers the decision to fail over, and what triggers the harder one — to tell customers, to tell the regulator, to start counting the hours against your impact tolerance?
If the honest answer is "it depends who's on call", your operating model has already failed the test. No register entry fixes that. The register can be immaculate and the firm can still stand in the corridor at 2am arguing about who's allowed to spend money.
DORA is not a documentation standard. It is a behavioural test, administered at the worst possible moment, with no opportunity to resit.
This is what the regulation means by resilience, underneath the articles and the technical standards. Can the firm absorb the failure of things it depends on but doesn't control? That is an operating-model property. It lives in decision rights, escalation paths, rehearsed muscle memory and contracts you've actually read. It does not live in a spreadsheet.
The register is a symptom, not the disease
The information register gets the attention because it's tangible and auditable, and because filling it in feels like progress. Fine — you need one, and a sloppy one will earn you awkward supervisory letters. But watch what happens when a firm treats the register as the deliverable.
The register says the vendor is "critical". Nobody has decided what the firm does in the first hour of that vendor failing. The register records an exit strategy. The exit strategy is a paragraph, written by someone who left last year, describing a migration that would in reality take nine months and has never been priced. The register lists a substitute provider. Nobody has ever run so much as a tabletop of the substitution, so nobody knows the substitute needs six weeks of onboarding and a data format you don't produce.
Paper resilience. It maps beautifully. It survives contact with an auditor and dies on contact with an outage. Supervisors have started noticing the difference, and the firms getting uncomfortable follow-up questions are not the ones with gaps in their registers — they're the ones whose registers are perfect and whose people can't describe what happens next.
What good actually looks like
Good is smaller and harder than the programme plan suggests. It looks like this.
For each genuinely critical third party — the handful, not the hundreds — there is a severance decision that has been tested, not filed. Someone senior has sat in a room and made the call under exercise conditions: we are leaving this provider, now, and here is the sequence. The exercise found the gaps a document never would: the licence that doesn't transfer, the person who is single-handedly load-bearing, the backup that restores in twelve hours rather than two.
The playbooks are written in plain English, short enough to use at 2am, and the people named in them know they're named. A playbook nobody can follow under stress is a compliance artefact wearing a hard hat.
And every arrangement passes the one-sentence test we apply to everything: the person living with it can say what it's for, in one sentence, without mentioning the regulator. "If Provider X dies, I switch to Y, it takes four hours, and I'm allowed to do it on my own authority." That sentence is resilience. Forty pages of mapped controls are not.
The irony is that firms which build this way find the compliance falls out of the bottom almost for free. The register describes reality instead of aspiration. The testing evidence exists because the tests actually happened. The board reporting writes itself, because there is something real to report.
DORA didn't create the weakness in your operating model. It just scheduled the exam.
Fix how your firm decides under stress, and DORA becomes paperwork; fix only the paperwork, and DORA becomes prophecy.
