Skip to main content
Manual Compliance Tracking Just Failed Its Biggest TestCompliance Program Frameworks
3 min readFor Compliance Training Managers

Manual Compliance Tracking Just Failed Its Biggest Test

What Happened

On 17 January 2025, the Digital Operational Resilience Act (DORA) came into effect across the EU. Despite two years of preparation, many financial entities struggled to understand what compliance truly required. The issue wasn't about understanding the rules; it was about managing the sheer volume of regulatory changes using outdated methods like spreadsheets and shared inboxes. This challenge was compounded by simultaneous obligations under the EU AI Act, the NIS2 Directive, and diverging UK requirements from the FCA and PRA.

This isn't a one-time event. It's an ongoing structural breakdown in compliance across financial services and tech firms.

Timeline

Before 17 January 2025: Financial entities prepared for DORA while managing existing frameworks. Regulatory updates were handled through shared inboxes, obligation mapping in spreadsheets, and evidence collection in folders.

17 January 2025: DORA took effect, revealing that manual tracking methods couldn't keep up with overlapping standards and guidance.

2 February 2025: Bans on AI systems with unacceptable risk began under the EU AI Act.

2 August 2025: Obligations for general-purpose AI models under Article 53 took effect.

Present day: Many teams still rely on the same manual tools. The EU AI Act's phased obligations add to DORA's demands, with high-risk system requirements due by 2 December 2027.

Which Controls Failed or Were Missing

Three main control failures emerged:

Disconnected horizon scanning and obligation tracking. Regulatory updates from the EBA, ESMA, ICO, and AI Office were managed manually. Updates were assigned via email, and tracking was done in tools not designed for regulatory work. When the EBA clarified Article 30's scope, no automated updates were made to obligation records, leaving compliance records outdated.

Lack of automatic linkage to source requirements. A mid-sized institution needed separate Article 30 assessments for each ICT provider. Spreadsheet columns tracked requirements, and rows tracked providers. Manual updates were required when guidance changed, leading to potential compliance gaps.

Separated evidence collection from obligation records. Evidence was stored in folders, not linked to specific obligations. This made proving compliance difficult and time-consuming.

The real issue is the compound effect. If an obligation isn't logged, it isn't fulfilled, and evidence isn't gathered. This gap often surfaces during supervisory reviews, a critical time to discover it.

What the Relevant Standards Require

DORA Article 30 mandates written agreements with ICT providers, covering service descriptions, data locations, incident notification procedures, and termination rights. Each provider needs a documented assessment with a complete evidence trail.

EU AI Act Annex III requires high-risk AI systems to meet specific obligations by 2 December 2027. Systems already in use have until then, while new systems must comply immediately after 2 August 2026.

The AI Act allows penalties of up to €15 million or 3% of global turnover for non-compliance.

The overlap creates a compliance challenge: An AI system used for credit decisions can be a high-risk system under the AI Act and an ICT service under DORA. This requires mapped obligations across both frameworks with evidence trails that satisfy both.

Lessons and Action Items for Your Team

Map your current process before adopting technology. Understanding where your manual process fails will help you get more value from automation. Document key workflows: how updates reach the right people, how you map obligations to requirements, and where evidence is stored.

Test your cascade workflow. When the EBA updates DORA Article 30 assessments, how quickly does your system reflect the change? If it requires manual updates, you're at risk of falling behind.

Tie evidence to obligations, not folders. Your audit trail should show compliance evidence without piecing together multiple files. If you can't access it on demand, it's not reliable.

Run a December 2027 readiness check now. High-risk AI system obligations are due by 2 December 2027. If you're still using spreadsheets and shared inboxes, consider whether your program will catch failures before regulators do.

Assign obligation-level ownership. DORA compliance involves multiple obligations, each needing a named owner, deadline, and accountability. Teams that succeeded in January 2025 had granular tracking in place well before the deadline.

Your team has the expertise to handle regulatory complexity. The challenge is finding the time to apply it. This failure shows that manual tracking consumes the capacity needed for the judgment work only your team can do.

You Might Also Like