Home  ›  DORA and operational resilience
Regulatory

The map you already owe your regulator

UK operational resilience rules and DORA both require firms to understand how their work actually runs. Most firms build that map twice, use it once, and let it go stale.

Two regimes, one underlying artefact

The UK operational resilience regime has been fully in force since 31 March 2025, the end of the transitional period during which firms had to be able to remain within their impact tolerances for each important business service. DORA has applied across the EU since 17 January 2025.

They are different instruments with different emphases. The UK regime is outcome-focused and service-centred: identify your important business services, set an impact tolerance for each, map what supports them, and test that you can stay within tolerance under severe but plausible disruption. DORA is more prescriptive and ICT-centred: ICT risk management, incident classification and reporting, digital operational resilience testing, third-party risk, and information sharing.

What they share is a dependency. Neither can be evidenced without a granular, current, maintained understanding of how work actually runs: the processes, the people, the systems, the third parties, the controls, and the points at which it fails.

A firm in scope of both frequently produces two mapping exercises, in two formats, owned by two teams, neither of which is used for anything else. That is not a compliance problem. It is a waste problem.

What the mapping actually has to support

Obligation areaWhat the map has to be able to answer
Important business servicesWhich services, delivered to whom, and which processes constitute them end to end. That includes the parts that run outside core systems.
Impact toleranceWhere the intolerable harm threshold sits, and which steps in the chain determine whether you breach it.
Dependency mappingThe people, processes, technology, facilities, information and third parties each service relies on, and the substitutability of each.
Critical or important functionsWhich functions qualify, what supports them, and how that assessment was reached.
Third-party dependencyWhere an external provider sits inside the flow, what happens when it is unavailable, and what the firm does instead.
Scenario testingA model detailed enough to run a severe but plausible disruption against, rather than a diagram that stops at the department boundary.
Governance and reviewNamed owners, evidence of review, and a change history showing what was altered, by whom and when.

Where the resilience map and the AI question converge

The overlap is larger than most firms notice, because the two exercises are usually commissioned by different people at different times.

Resilience mapping asks: what is this process, who owns it, what does it depend on, what controls sit on it, and how does it break?

An AI opportunity assessment asks: what is this process, who owns it, what does it depend on, what controls sit on it, and which steps could a machine do?

Five of six inputs are identical. Only the final question differs. Captured once, properly, with owners, controls, volumes, dependencies and exception paths, the same structured record answers both, and continues to answer both as the firm changes. The scoring method is applied to the same map, not a second one.

Why most maps go stale, and what fixes it

The failure mode is consistent. A mapping exercise is commissioned, runs for eight weeks, delivers a set of documents, and is filed. Within two quarters the firm has changed, the documents have not, and the next regulatory question triggers a fresh exercise from close to zero.

The cause is the container, not the effort. A map delivered as a document has no reason to be opened again. A map that is the operating record, one that gets consulted when something changes, re-scored when a process is redesigned, and cited when someone asks how a decision was made, stays current because using it and maintaining it are the same act.

What this is not

PinpointProof produces evidence for your own governance. It is not a compliance product: it does not calculate regulatory outcomes, produce filings, issue opinions or attest to anything. Whether a given artefact satisfies a particular obligation is a judgement for the firm and its advisers, and firms should take their own regulatory and legal advice. This page is general information, not advice.

The practical route

Start with one important business service. Map the processes that constitute it to the level of detail a scenario test would need. That includes the steps that run on email, spreadsheets and portals, which is usually where the tolerance actually gets breached. Record owners, controls, dependencies and volumes as you go, because retrofitting them costs more than capturing them.

Then score the same map for AI and automation potential. You will have paid once for an artefact that serves the resilience obligation, the AI decision, and the next reorganisation.

FAQ

Common questions.

Does DORA require process mapping?

DORA requires financial entities to identify and document the business functions, roles and responsibilities that depend on ICT, to map the assets and dependencies supporting critical or important functions, and to keep that documentation current and reviewed. It does not use the phrase "process mapping", but an entity cannot evidence those obligations without a maintained, granular understanding of how the work runs.

What is the difference between UK operational resilience rules and DORA?

The UK regime, in force since 31 March 2025, is outcome-focused: firms identify important business services, set impact tolerances for each, map the people, processes, technology, facilities and information that support them, and test their ability to stay within tolerance during severe but plausible disruption. DORA, applying since 17 January 2025, is more prescriptive and ICT-centred, covering ICT risk management, incident reporting, resilience testing, third-party risk and information sharing. A firm in scope of both is doing overlapping mapping work twice unless it is deliberate about the artefact.

Can the same map serve resilience obligations and AI decisions?

Yes, and it is the most efficient thing available to an operations team. Both need the same underlying record: what the process is, who owns it, which systems and third parties it depends on, what controls sit on it, and where it can fail. Resilience asks how it breaks. AI opportunity asks which steps a machine could do. Captured once, the same structure answers both.

Is PinpointProof a compliance product?

No. Everything produced is an input to the firm’s own governance. It is evidence the firm can use, not a verdict issued on its behalf. PinpointProof does not calculate regulatory outcomes, produce filings, or attest to anything. Firms should take their own regulatory and legal advice.

One map. Two obligations.

Bring one important business service. Thirty minutes, and you will see what a map that serves both looks like.

Thirty minutes. Bring one process.