Back to Blog

Due Diligence

Navigating DORA Together: Our Journey Toward Enhanced Operational Resilience

FundFrame shares its progress toward Digital Operational Resilience Act (DORA) compliance and practical implementation insights for financial institutions.

Alexander Rønfeldt• Operations Lead
September 11, 2025
7 min read

FundFrame is publicly sharing its progress toward Digital Operational Resilience Act (DORA) compliance, a regulatory framework reshaping EU financial services operations.

New Expertise

The company recently hired Alexander Møller Rønfeldt, who previously built compliance infrastructure at Polaris. His experience has deepened FundFrame's understanding of practical implementation challenges that financial institutions face.

Current Compliance Initiatives

We are advancing on multiple fronts:

  • European server hosting alternatives to US-based systems
  • Comprehensive sub-provider documentation and compliance tracking
  • Contract updates to meet DORA standards

Transparency Efforts

FundFrame created a publicly accessible Provider Gallery displaying key technology partners, their compliance status, geographic reach, and uptime metrics.

Automated Monitoring

We use automated systems to update vendor data daily and are developing incident detection capabilities to ensure continuous compliance visibility.

What DORA Requires

For financial institutions, DORA implementation means:

  • More detailed documentation and reporting
  • Enhanced incident management protocols
  • Vendor contract reviews against specific ICT requirements
  • Ongoing monitoring of third-party providers

Looking Ahead

We plan to:

  • Provide regular compliance updates to customers
  • Engage directly with customers on specific requirements
  • Maintain transparent communication about operational changes
  • Adapt processes as regulatory guidance evolves

Practical Implementation Advice

Based on our experience, successful DORA implementation requires:

  1. Start with vendor inventory - Know who you're working with
  2. Review contracts systematically - Check against the 13 mandatory provisions
  3. Build monitoring capabilities - Compliance isn't one-time
  4. Document decisions - Audit trails matter

The regulatory landscape will continue to evolve, and we're committed to sharing our learnings along the way.


Need help navigating DORA compliance? Contact us to discuss how FundFrame supports operational resilience.

Bring the ideas in this post to your own portfolio.

Book Demo