If you’ve been putting off building an operational risk management framework, now is a good time to move it up your priority list.
The European Union has introduced three major regulations that are already in force or gradually taking effect: NIS2, the EU AI Act, and DORA. Together, they affect more than 180,000 organisations across a wide range of industries. However, many businesses are still trying to catch up.
A CSSF Luxembourg survey of 389 financial organisations found that only one considered itself fully prepared for DORA. Meanwhile, PwC Luxembourg reported that just 4% of financial institutions have made DORA compliance part of their day-to-day operations.
We’re way past the point of determining if these regulations apply to your organisation. As long as you operate in the EU or support businesses that do, there’s a good chance that they do. You also have to make sure that you are tackling them as a single framework that’s easier to manage over time.
Putting everything together
Most organisations don’t actually know how to create a single operational risk management framework on their own. Often, they treat each regime as completely separate compliance projects: they allocate individual budgets and teams as well as technologies for each. In reality, these regulations overlap much more than you might think.
Say, a financial institution uses AI to support its credit scoring process. If that AI model is compromised, one incident could trigger requirements under all three regulations.
Under the AI Act, that organisation may need to report a failure involving a high-risk AI system, document what happened, and review its conformity assessment. Meanwhile, the same event could be a major ICT incident that must be reported within required timeframes and investigated to determine the root cause under DORA. The NIS2 could even require the organisation to report the security incident within 24 hours, especially if a third-party AI provider is involved and supply chain security is affected.
That is one incident, but it could involve three different reporting timelines and three sets of reporting requirements, as well as multiple regulatory authorities.
With a single operational risk management framework, you don’t have to handle each regulation separately. These laws may have different wording, but you should remember that they focus on many of the same core areas, from risk management and incident response to third-party oversight and governance.
By documenting which controls satisfy the requirements of each regulation, your organisation can carry out the work once instead of repeating the same tasks three times. This also reduces your risk of different compliance programmes drifting apart over time.
With a unified operational risk management framework, you can support all three regulations by aligning shared controls, including:
Risk management – NIS2 requires cybersecurity risk assessments while DORA focuses on ICT risk management. Meanwhile, the AI Act requires AI risk classification. One well-designed risk management process lets you support each of these requirements.
Incident management – Each regulation has its own reporting timelines and notification rules. However, you can manage everything using one incident response process with clear workflows for each regulatory obligation.
Third-party oversight – With one consistent third-party risk management process, you can cover all three no matter what you’re assessing.
Audit trails and documentation – Every regulation expects your organisation to demonstrate compliance. With your own operational risk management framework, you can easily track who completed each action and when it happened and why. Likewise, you can see how processes have changed over time.
Creating a single framework
Here at Cybersecurity Analytics, we can help you create one operational risk management framework for all three regimes based on your organisation’s needs. Get started today by scheduling your free consultation on this website.


