2026-06-24-fi-dora-compliance-warning
FI Warns: Companies Fail to Meet Digital Resilience Requirements (DORA)
The Swedish Financial Inspectorate (FI) has issued a serious warning in its latest stability report: many financial companies in Sweden do not meet the requirements for digital resilience under the DORA regulation. The report is based on an examination of 50 banks, insurance companies, payment institutions, and trading platforms and shows systematic deficiencies in companies' IT security and crisis preparedness.
DORA Regulation in Practice
DORA (Digital Operational Resilience Act) came into full effect in January 2025 and sets high requirements for financial institutions' ability to manage digital risks. FI's mapping shows that many companies still do not meet these requirements:
Core Requirements Under DORA
- Comprehensive continuity plans: Companies must have plans to continue operations during disruptions
- Crisis preparedness: Systems for managing and limiting the effects of disruptions
- Recovery plans: Methods for restoring systems and functions after incidents
- IT asset documentation: Complete overview of critical systems and components
Mapping of Deficiencies
FI has mapped 50 financial companies and found that many lack basic components of DORA requirements:
- 30% of companies: Lack comprehensive continuity plans
- 25% of companies: Have inadequate crisis preparedness procedures
- 40% of companies: Do not sufficiently document their IT assets
Specific Risk Areas
FI's report identifies several specific risk areas where financial companies have particularly significant deficiencies:
AI-Related Risks
A new and growing concern is the connection to artificial intelligence. FI's Director General Johan Almenberg specifically mentioned AI as a risk, particularly regarding the Anthropic Mythos model:
"AI was mentioned as a specific risk (Anthropic Mythos model)"
These risks include:
- Understanding of AI systems' decision-making processes
- Secure handling of AI training data
- Ability to detect and counter AI-driven attacks
Third-Party Risks
Many financial companies rely on external providers for critical systems, but have insufficient control over these providers' IT security:
- Undetermined contractual terms for IT security
- Lack of regular security audits of providers
- Unclear allocation of responsibilities in incidents
Companies' Reactions
According to FI's report, companies have different reactions to DORA requirements:
Positive Developments
Some companies have taken DORA requirements seriously and implemented robust systems:
- Larger banks have invested in advanced cybersecurity platforms
- Insurance companies have developed more sophisticated risk analyses
- Payment institutions have improved their incident handling
Challenges for Smaller Companies
Small and medium-sized financial companies face particular challenges:
- Limited resources to implement requirements
- Lack of specialized expertise in IT security
- Complexity of understanding and implementing DORA
FI's Advice and Recommendations
FI has provided several concrete recommendations to financial companies to improve their digital resilience:
Immediate Actions
- Implement basic documentation of IT assets
- Develop at least one basic continuity plan
- Establish procedures for handling IT incidents
Long-term Strategies
- Build a dedicated IT security organization
- Implement regular security testing and penetration testing
- Develop systematic ways to handle third-party risks
Consequences of Inadequate Compliance
Companies that do not meet DORA requirements risk several serious consequences:
Liability for Damages
Under DORA, companies that cause disruptions in financial systems may be liable to pay compensation to other affected parties:
- Burden on affected companies
- Potentially large financial losses
- Lost trust among customers and the market
Supervisory Measures
FI can take several types of supervisory measures against companies that do not meet requirements:
- Changed supervision plans with increased monitoring
- Administrative fines
- In extreme cases, revocation of licenses
Impact on the Payments Market
DORA deficiencies have broad consequences for the Swedish payments market:
Systemic Risks
Weak digital resilience in individual companies can create systemic risks:
- Cascade effects during disruptions
- Risk of market disturbances
- Impact on financial stability
Competitive Situation
Companies that quickly adapt to DORA gain a competitive advantage:
- Trust among customers and partners
- Lower risk of operational disruptions
- Better opportunities to grow in an increasingly regulated environment
New Skill Needs
DORA has created a great need for new skills in:
- Cybersecurity
- IT risk management
- Regulatory compliance
- Continuity planning
Next Steps for FI
FI has planned measures to improve the situation:
Increased Supervision
For 2026, FI plans to:
- Deepen examination of IT security in financial companies
- Conduct targeted examinations of particularly critical areas
- Monitor companies' implementation of DORA requirements
Industry Collaboration
To support smaller companies, FI plans to:
- Arrange training on DORA and IT security
- Develop industry-common tools and templates
- Create forums for experience sharing between companies
Questions for the Future
DORA implementation raises several important questions for the financial sector:
AI Regulation
Handling of AI risks is a new area that requires special focus:
- Need for specific AI regulations in finance
- Development of expertise for AI security
- Balancing innovation and risk management
Third-Party Risks in a Digital World
Financial companies' increasing dependence on external providers requires new solutions:
- Transparency in supply chains
- Standardized security requirements
- Shared responsibility in incidents
Sources
- Swedish Financial Inspectorate (FI) stability report 2026, published May 20, 2026
- DORA Regulation (EU) 2022/2554
- FI's supervision report on financial stability 2026