DORA compliance adds a second, technical layer of obligation on top of a CASP's existing AML/CTF programme | one that most crypto and fintech businesses have never had to formalise before. Outsourcing compliance for DORA is a practical way to build that capability quickly, but it works best when you're clear about what can genuinely be delegated and what has to stay owned internally.

What can be outsourced

  • Framework design. Building the ICT risk management framework itself | policies, roles, control descriptions | is well suited to an outsourced compliance partner who's built these before.
  • Third-party risk assessment. Assessing and documenting critical ICT vendors against DORA's criteria is largely a methodology and documentation exercise that can be run externally, with your input on the vendor relationships themselves.
  • Incident classification procedures. Defining thresholds and reporting workflows can be designed externally, then handed over for your team to operate.
  • Testing coordination. Planning and coordinating resilience testing cycles, including liaising with any external testing providers.
  • Ongoing regulatory monitoring. Tracking DORA-related regulatory technical standards and guidance as they develop, and flagging what changes for your framework.

What should stay in-house

  • Board-level accountability. DORA places ultimate responsibility for ICT risk management with the management body. That accountability cannot be outsourced, even if the supporting work is.
  • Operational knowledge of your own systems. An outsourced partner can design the framework, but your team knows the actual architecture, dependencies and failure points of your systems best.
  • Final risk acceptance decisions. Where a residual risk is identified, the decision to accept, mitigate or avoid it needs to rest with your business, informed by external advice rather than delegated to it.
A useful way to think about it: outsourcing gets you the framework, the documentation and the methodology fast. It doesn't remove the need for your own team to understand and operate the systems that framework governs.

Where outsourced DORA compliance tends to go wrong

The most common failure mode isn't outsourcing too much | it's treating DORA and AML/CTF compliance as two unrelated projects run by two disconnected teams or providers. Incident reporting lines, vendor risk ownership and governance structures should tell one consistent story across both frameworks. A single compliance partner coordinating both tends to avoid the contradictions that show up when they're built in isolation.

A practical starting point

Most CASPs get the most value starting with a gap assessment: what does DORA actually require of your specific operating model, and where are the real gaps against what you have today? From there, framework design and vendor risk assessment can move quickly, with a clear handover plan for what your team will own operationally once the framework is live.

The bottom line

Outsourcing compliance for DORA is an efficient way to build a credible ICT risk management framework without slowing down the rest of the business. The businesses that get the most value from it are clear from the start about what they're delegating (the framework, the documentation, the methodology) and what stays theirs (the accountability, the operational knowledge, the final decisions).