DORA is often discussed as banking regulation. It is not. Insurance and reinsurance undertakings and intermediaries are explicitly in scope, and the insurance operating model creates implementation problems that banking-shaped guidance does not address.
Three Sector-Specific Pressure Points
Delegated authority. A significant share of insurance business is written, administered and sometimes claims-handled by managing general agents, coverholders and third-party administrators. These parties operate ICT systems that support functions the insurer would readily classify as critical — policy administration, claims payment, sanctions screening.
The question of whether a delegated authority arrangement is an ICT third-party service arrangement for DORA purposes turns on the substance of what is provided. Where the arrangement includes the provision of ICT services supporting the insurer's functions, the DORA contractual and register obligations engage. Many delegated authority agreements were drafted long before DORA and contain nothing resembling its required provisions on audit access, incident notification timelines, subcontracting or transition assistance.
Remediating a delegated authority book is slower than remediating a supplier book because the counterparties are distribution partners with commercial leverage, and because there are frequently hundreds of them. Prioritise by function criticality and premium volume, and accept that the tail will take multiple renewal cycles.
Legacy policy administration. Insurers run some of the oldest production systems in financial services — closed books on platforms whose vendors no longer meaningfully support them, sometimes with no realistic migration path. These systems sit at the centre of critical functions and fail every reasonable ICT hygiene test.
The wrong answer is to exclude them from the inventory. The right answer is documented risk acceptance with compensating controls: network isolation, restricted access, enhanced monitoring, verified restore capability, and a board-level acceptance with a review cycle. Supervisors understand legacy. What they do not accept is legacy that nobody has assessed.
The actuarial model estate. Internal models, reserving models, pricing engines and capital calculators are ICT assets supporting critical functions. They also sit under a separate governance regime — Solvency II model governance and validation, and, where applicable, the Technical Actuarial Standards.
DORA does not replace model governance. It adds ICT-layer obligations: the model's hosting, access control, change management, data pipeline integrity, and recovery. The failure mode is a gap where the actuarial function assumes IT covers the platform and IT assumes the actuarial function covers the model. Assign both explicitly.
Mapping to Solvency II
Insurers already operate a system of governance under Solvency II, with the risk management function, the actuarial function, compliance and internal audit. DORA's requirements attach to that structure rather than displacing it.
| DORA requirement | Existing Solvency II anchor | Gap to close |
|---|---|---|
| ICT risk management framework | Risk management system, ORSA | ICT-specific framework and asset-to-function mapping |
| Management body responsibility | Administrative, management or supervisory body duties | ICT-specific tolerance, budget, training evidence |
| Third-party arrangements | Outsourcing requirements | Prescribed contract terms, register format, exit plans |
| Incident reporting | National supervisory notification | Classification thresholds and three-report sequence |
| Resilience testing | Not equivalently prescribed | Annual programme scoped by critical function |
The ORSA is a natural place to reflect material ICT and operational resilience risk, and doing so gives the board a single view rather than a parallel resilience narrative.
Intermediaries and Proportionality
Insurance intermediaries are in scope, subject to exclusions for certain micro, small and medium-sized enterprises, and many will qualify for the simplified ICT risk management framework. That framework is genuinely lighter, but as discussed in the main DORA guide, the entitlement to it must itself be assessed and documented.
For a small intermediary, a defensible DORA position is achievable in weeks rather than months: a short framework document, an asset and provider inventory, an incident process with a named classifier, tested backups, a third-party register covering the handful of platforms the business actually depends on, and an annual board review with minutes. The failure mode at this end of the market is not over-engineering — it is doing nothing on the assumption that DORA is for large institutions.
Claims Continuity as the Defining Scenario
For most insurers, the scenario that best tests the whole framework is loss of claims payment capability during a catastrophe event — precisely when volumes spike, when reputational exposure is highest, and when the delegated chain is under most strain.
Running that scenario end to end exercises the policy administration platform, the delegated administrator's systems, the payment rails, the surge staffing model, the incident classification decision and the customer communication obligation simultaneously. It is worth more than a year of component-level testing, and it maps directly to the programme design set out in the testing article.
Key Takeaways
- Delegated authority arrangements frequently constitute ICT third-party services and are the slowest part of an insurer's remediation.
- Legacy policy platforms belong on the register with documented board-level risk acceptance, not excluded from it.
- Actuarial models need explicit ownership at both the model-governance and ICT layers, or the gap between them goes unowned.
- DORA attaches to the Solvency II system of governance; the ORSA is a sensible place to reflect material ICT risk.
- Small intermediaries can reach a defensible position quickly; the real risk is assuming DORA does not apply.
Frequently Asked Questions
Is a managing general agent an ICT third-party service provider? It depends on what the arrangement actually provides. Where the MGA supplies ICT services supporting the insurer's functions — policy administration, claims systems, data processing — the DORA obligations engage in respect of those services. The label on the agreement does not determine the answer.
Do Lloyd's market participants have separate obligations? Market participants must satisfy their own applicable regulatory requirements as well as market-level standards, and EU-domiciled entities within a group are in DORA's scope in their own right. Group frameworks need entity-level application.
How does DORA interact with Solvency II outsourcing requirements? For ICT services, DORA's requirements are more prescriptive and generally set the operative standard. Solvency II outsourcing requirements continue to apply to non-ICT outsourcing, so most insurers run one register with an ICT scope flag.
About the author
Jonas Mohamed Osman Abdelghafour is a risk and compliance expert advising banks, insurers, payment institutions and asset managers on operational resilience, ICT and third-party risk, financial crime and enterprise governance across EU and UK regimes. He works at the point where digital operational resilience obligations meet the evidence a board and a supervisor actually ask for. See qualifications and services, or get in touch to discuss an engagement.
*This article discusses regulatory frameworks in general terms and is not legal advice. Jurisdictional interpretation should be confirmed with qualified counsel.*
Frequently asked questions
What should risk leaders know about three Sector-Specific Pressure Points?
**Delegated authority.** A significant share of insurance business is written, administered and sometimes claims-handled by managing general agents, coverholders and third-party administrators. These parties operate ICT systems that support functions the insurer would readily classify as critical — policy administration, claims payment, sanctions screening.
What should risk leaders know about mapping to Solvency II?
Insurers already operate a system of governance under Solvency II, with the risk management function, the actuarial function, compliance and internal audit. DORA's requirements attach to that structure rather than displacing it.
What should risk leaders know about intermediaries and Proportionality?
Insurance intermediaries are in scope, subject to exclusions for certain micro, small and medium-sized enterprises, and many will qualify for the simplified ICT risk management framework. That framework is genuinely lighter, but as discussed in the [main DORA guide](/insights/dora-regulation-compliance-guide), the entitlement to it must itself be assessed and documented.
What should risk leaders know about claims Continuity as the Defining Scenario?
For most insurers, the scenario that best tests the whole framework is loss of claims payment capability during a catastrophe event — precisely when volumes spike, when reputational exposure is highest, and when the delegated chain is under most strain.
What should risk leaders know about frequently Asked Questions?
**Is a managing general agent an ICT third-party service provider?** It depends on what the arrangement actually provides. Where the MGA supplies ICT services supporting the insurer's functions — policy administration, claims systems, data processing — the DORA obligations engage in respect of those services. The label on the agreement does not determine the answer.