The Digital Operational Resilience Act (DORA) has a significant impact on the insurance sector. Insurers must comply with this new European regulation by January 17, 2025. In practice, insurers are working hard to meet these requirements.
01
Practical support from the association
The Dutch Association of Insurers has launched several initiatives to help insurers implement DORA effectively.
One key initiative is the development of DORA clauses for IT supplier contracts. These standardized clauses were created in collaboration with DUFAS, the Pension Federation, and other industry bodies. They help ensure contracts meet DORA compliance requirements.
Additionally, the Association:
- Hosts webinars to encourage knowledge sharing
- Provides platforms for insurers to exchange experiences
- Acts as a liaison with the Dutch Central Bank (DNB) to streamline communication between the sector and the regulator
02
Valuable industry insights
The Association shares practical DORA implementation insights through expert interviews and articles. Here are a few highlights:
Tips from EY's cybersecurity expert
In the article “DORA Implementation: Tips from Rudrani Djwalapersad”, EY’s Partner highlights four priorities:
- Focus on must-haves like the Register of Information
- Document your non-gaps (where you already comply)
- Build a realistic roadmap for closing gaps—even beyond the deadline
DNB’s vision on DORA
In “5 Questions about DORA to DNB”, Marcel Verhoeven emphasizes:
- Performing thorough gap analyses
- Ensuring board-level accountability
- Managing outsourcing risks
- Establishing IT continuity measures
European impact
The article “Europe and the Impact of DORA Legislation” features Martin van Vessem, chair of the Insurance-ISAC. He stresses that DORA is a sector-wide challenge and urges collaboration: “You can only keep the bad guys out if you work well together.”
Legal perspective
In “5 Questions about DORA”, Anne-Mieke Dumoulin-Siemens explains the importance of conducting a gap analysis: “Insurers are already expected to comply with certain security frameworks.”
Cyber testing and DORA
In “Rob Wassink (DNB) on Cyber Testing”, the importance of TIBER tests is emphasized as a key part of ensuring digital resilience under DORA.
03
Working together toward compliance
These examples show how the Dutch Association of Insurers is supporting the sector in a practical, collaborative way. From standardized contract language to direct engagement with DNB, their efforts are helping insurers tackle DORA’s complex requirements.
Discover how our solutions can help simplify DORA compliance or Contact us
Originally published on DORA Solutions Insights.