Ariadnah
Platform
DORA Understand the responsibilities, common operating gaps, and the path from shared knowledge to evidence. AML & KYC Customer due diligence with the ownership look-through resolved as data. Risk & Control One control catalogue, read through every framework it answers to. Governance & Policies Policies drafted, mapped to requirements clause by clause, and approved in the platform.

Platform

  • Platform overview
  • AI assistant
  • Security & trust
  • Impact & access

Domains and services

  • Register of Information
  • Suppliers & Contracts
  • Asset Management
  • Risk & Control
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • Governance & Policies
  • Incident Management
  • All solutions →

By sector

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services
  • All sectors →
About Pricing Insights Resources Contact
Book a Discovery Call
Home About Platform Solutions Sectors Pricing Insights Resources DORA Guide NIS2 Guide Contact
Book a Discovery Call
Insights

Business functions in DORA; The cornerstone of your ICT Risk management

Ariadnah Solutions DORA 26 Aug 2025 3 min read

Business functions are the cornerstone of your entire ICT risk management framework. Think of it as creating a blueprint of your organization, you need to know what you do (functions), what's essential (criticality), and what each function needs to operate (dependencies). Without this map, you're managing ICT risks blindfolded.


01

1. What are business functions?

In the DORA context, a business function is any set of activities or services your organization performs. These are the building blocks of your operations, everything from customer-facing services to supporting activities.

Examples include:

  • Core functions: portfolio management, investor relations, payment processing, lending, trading, claims handling, etc.
  • Supporting functions: finance, IT operations, HR, compliance, risk management, customer support, etc.

DORA requires you to identify all functions performed by the entities in scope of your ICT risk management framework. You need to define your own functions based on your business model, there’s no pre-defined regulatory list. Your internal taxonomy should reflect how your organization actually operates.


02

2. Determining criticality

Not all functions are equal. According to DORA Article 3(22), a function is “critical or important” if its disruption would:

  • Materially impair your financial performance – causing significant financial losses or affecting your firm’s viability
  • Materially impair the soundness or continuity of your services and activities – disrupting operations in a way that affects service delivery to customers or counterparties
  • Materially impair your regulatory compliance – preventing you from meeting authorization conditions or other obligations under financial services law (AIFMD, MiFID II, PSD2, Solvency II, etc.)

Simple test: If this function stopped working, would it materially damage your finances, disrupt your services, or cause regulatory non-compliance? If yes, it’s critical or important.

Key word: “Materially” the impact must be significant, not minor. DORA uses a risk-based approach, focusing on functions where failure would have serious consequences for your firm, customers, or the financial system.


03

3. Mapping dependencies and connections

For each function, DORA requires you to document and maintain an inventory of:

  • Licensed Activities – Which regulated business activity does this function support?
  • Roles and Responsibilities – Who owns, operates, and oversees this function?
  • Information Assets – What data does this function process or depend on?
  • ICT Assets – Which systems, applications, databases, and infrastructure components are involved?
  • ICT Services – What technology services (intra-group or third-party) enable this function?
  • Processes – What processes depend on ICT third-party service providers? (These processes can be linked to one or more business functions)

This inventory creates a clear dependency map showing exactly what each function needs to operate and highlights all third-party dependencies.

Per Article 8.6 DORA regulation, these inventories must be kept current through regular updates (at least annually) and whenever major changes occur in your ICT environment or business operations.


04

4. Why this matters

Identifying, classifying, and mapping functions isn’t bureaucratic busy-work. It’s fundamental because:

  • Functions are your risk assessment starting point – you can’t protect what you don’t know you have
  • Criticality drives resource allocation – knowing what’s critical helps you prioritize security investments and controls
  • Impact analysis depends on this mapping – when incidents occur, you need to quickly understand what’s affected
  • Regulatory compliance requires it – demonstrating control over critical functions is core to DORA

05

5. How the platform helps

The platform streamlines business function management the cornerstone of your ICT risk management framework.

Inventory maintenance

Keep your mandatory DORA inventories current and complete:

  • Automated periodic reviews – no manual tracking needed
  • Automatic updates triggered by changes
  • Review notifications sent to function owners
  • Full audit trail of completion

Comprehensive mapping

Visualize and manage all your dependencies:

  • Simple maintenance of connections between functions, roles, services, and assets
  • Quick identification of critical interdependencies
  • Real-time view of all dependencies
  • Instant impact assessment for incidents

The platform handles the compliance workload, letting you focus on actual risk management rather than documentation.

Originally published on DORA Solutions Insights.

Continue with DORA

Put this question in context.

The DORA guide connects this issue to governance, ICT risk, incidents, resilience testing, third-party risk and the Register of Information.

Recommended next Read the DORA compliance guide →
Explore the operating approach See the asset and dependency approach Related analysis How to Map ICT Services to Business Functions: A Complete Yet Proportionate Approach Related analysis illustrative example: business functions of a venture capital fund manager
Manage Consent
We use cookies to keep this site reliable and to understand how it is used. You can accept, deny, or adjust your preferences at any time.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ariadnah

Compliance advisory & technology

Regulatory specialists and technology that help organisations simplify compliance, strengthen operational resilience, and build lasting trust.

ISO/IEC 27001 certified (DNV)

Platform

  • Platform Overview
  • DORA Guide
  • NIS2 Guide
  • Regulatory Library
  • Register of Information
  • Risk & Control
  • Governance & Policies
  • Incident Management
  • Asset Management
  • Suppliers & Contracts
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • AI
  • Security

Sectors

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services

Company

  • About Ariadnah
  • Pricing
  • Our Experts
  • Impact
  • FAQ
  • Insights
  • Contact

Legal

  • General Terms
  • Data & Privacy
  • Cookie Policy
  • Accessibility

© 2026 Ariadnah Solutions B.V.