概述

Why Is DORA Important to Alohi?

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) has applied since 17 January 2025. It establishes requirements for ICT risk management, incident reporting, resilience testing, and ICT third-party risk management across the EU financial sector.

Financial institutions rely on technology providers for everyday operations, including document exchange and electronic signatures. Assessing these providers forms part of their responsibility to understand dependencies, manage disruption, and maintain oversight of outsourced services.

Alohi supports these assessments as an ICT third-party service provider. Our governance, incident management, continuity, and supplier processes help financial-sector customers evaluate our services against their requirements. Each institution remains responsible for its own DORA compliance and for assessing how our services fit its operations.

This page is provided for general informational purposes and does not constitute legal advice. Financial institutions should consult their own counsel to confirm DORA compliance for their specific use case.

Operational Resilience

How Does Alohi Support Financial Institutions’ DORA Requirements?

Supporting digital operational resilience requires clear responsibilities, documented controls, and evidence that customers can assess. Alohi’s approach builds on our information security, risk management, incident response, and business continuity practices, alongside the contractual requirements applicable to each customer relationship.

‍

ICT Risk Management & Governance

Alohi’s digital operational resilience strategy builds on our existing information security management framework. It connects risk assessments, service responsibilities, management oversight, and corrective actions to help identify and address risks affecting customer-facing services.

‍

Incident Management & Customer Communications

Our incident procedures cover assessment, escalation, containment, recovery, and follow-up. A dedicated customer-notification procedure addresses service impact and communications for regulated customers, taking applicable contractual requirements into account. Financial institutions remain responsible for their own regulatory incident classification and reporting.

‍

Business Continuity & Recovery

Alohi’s continuity and backup policies address recovery priorities, restoration procedures, and service dependencies. Our resilience strategy incorporates restoration exercises and disaster recovery simulations. Customers should review the recovery arrangements relevant to their selected services against their own operational requirements.

‍

Change Management & Continuous Improvement

Changes follow a documented process that includes risk and impact assessment, testing, fallback planning, approval, and verification. Findings from incidents and recovery exercises inform corrective actions and risk reviews, helping improve resilience as services and dependencies evolve.

‍

Supplier & Dependency Management

Alohi’s supplier governance covers onboarding, monitoring, and controlled offboarding. Our documented framework addresses service dependencies, data-processing roles, locations, and contractual considerations. These processes support the assessment of third-party risks that may affect delivery of our services.

‍

Contractual Requirements & Customer Oversight

Financial institutions should assess whether their ICT service arrangements meet the requirements applicable to their use case. Alohi’s due diligence process supports questions about service scope, incident assistance, continuity, audit arrangements, and data handling. Specific commitments should be confirmed in the applicable agreement.

‍

Exit Planning & Service Transitions

Alohi’s supplier exit planning procedure addresses the feasibility of replacing critical dependencies, including technical constraints, transition risks, and data handling. Financial institutions should separately assess their own exit strategy for our services and confirm relevant export, retention, deletion, and transition arrangements with our team.

‍

Due Diligence & Supporting Documentation

Alohi maintains a controlled process for responding to security questionnaires and customer assurance requests using approved documentation. Relevant supporting materials can be requested through our team, subject to confidentiality and release requirements, to help institutions assess our controls and service arrangements.

‍

For your institution’s DORA assessment:

‍

  • Identify the services and business functions involved in your fax and signature workflows.
  • Assess service dependencies and whether the arrangement supports a critical or important function.
  • Review applicable contractual terms, oversight arrangements, and available supporting documentation.
  • Confirm incident contacts, notification arrangements, and responsibilities for regulatory reporting.
  • Evaluate continuity, recovery, and exit arrangements against your institution’s requirements.