Glossary · DORA

Proportionality Principle

The DORA principle that requirements scale with an entity's size, risk profile, and the criticality of its services.

Explained in depth: DORA overview

DORA Article 4 requires financial entities to implement the regulation's requirements in accordance with the principle of proportionality, taking into account their size, overall risk profile, and the nature, scale, and complexity of their services. Some obligations are explicitly tiered: microenterprises are exempted from several requirements, a simplified ICT risk management framework applies to certain small entities, and only designated significant entities must run TLPT. Proportionality is not a general opt-out. The core obligations, having an ICT risk management framework, classifying and reporting major incidents, managing third-party risk, and maintaining the register of information, apply to essentially all in-scope entities; proportionality shapes their depth, not their existence.

Why it matters

Smaller financial entities should use proportionality actively, and document the reasoning: a written justification of why the chosen level of measures fits the entity's risk profile is exactly what a supervisor expects to see. NIS2 contains a similar proportionality logic in Article 21.

Used in

See also

← All glossary terms