FundFrame is publicly sharing its progress toward Digital Operational Resilience Act (DORA) compliance, a regulatory framework reshaping EU financial services operations.
New Expertise
The company recently hired Alexander Møller Rønfeldt, who previously built compliance infrastructure at Polaris. His experience has deepened FundFrame's understanding of practical implementation challenges that financial institutions face.
Current Compliance Initiatives
We are advancing on multiple fronts:
- European server hosting alternatives to US-based systems
- Comprehensive sub-provider documentation and compliance tracking
- Contract updates to meet DORA standards
Transparency Efforts
FundFrame created a publicly accessible Provider Gallery displaying key technology partners, their compliance status, geographic reach, and uptime metrics.
Automated Monitoring
We use automated systems to update vendor data daily and are developing incident detection capabilities to ensure continuous compliance visibility.
What DORA Requires
For financial institutions, DORA implementation means:
- More detailed documentation and reporting
- Enhanced incident management protocols
- Vendor contract reviews against specific ICT requirements
- Ongoing monitoring of third-party providers
Looking Ahead
We plan to:
- Provide regular compliance updates to customers
- Engage directly with customers on specific requirements
- Maintain transparent communication about operational changes
- Adapt processes as regulatory guidance evolves
Practical Implementation Advice
Based on our experience, successful DORA implementation requires:
- Start with vendor inventory - Know who you're working with
- Review contracts systematically - Check against the 13 mandatory provisions
- Build monitoring capabilities - Compliance isn't one-time
- Document decisions - Audit trails matter
The regulatory landscape will continue to evolve, and we're committed to sharing our learnings along the way.
Need help navigating DORA compliance? Contact us to discuss how FundFrame supports operational resilience.