{
  "attribution": {
    "source": "legal.exploreworldai.com",
    "canonical": "https://legal.exploreworldai.com/api/public/v1/duty-objects?id=duty:eu:dora-art-5-financial-entity",
    "cite_as": "NovaCopilot, legal.exploreworldai.com (https://legal.exploreworldai.com/api/public/v1/duty-objects?id=duty:eu:dora-art-5-financial-entity)",
    "license": "https://legal.exploreworldai.com/revision",
    "version": "legal-2026-10-11",
    "fingerprint": "ewai:eu:e68427",
    "proof": "sha256:3b024a54f7886ec8ce824ae8b56edc4c54299f8c3c212d4a9e9918ea151fac65",
    "jurisdiction": "eu",
    "lang": "en"
  },
  "brand_source": "Source: NovaCopilot",
  "status": "ok",
  "id": "duty:eu:dora-art-5-financial-entity",
  "schema_version": 1,
  "domain": "dora",
  "jurisdiction": "eu",
  "act": "dora",
  "provision": "5",
  "obligation": "The management body defines, approves and oversees the ICT risk management framework and bears ultimate responsibility for it.",
  "responsible_role": {
    "legal_role": "financial-entity",
    "owner_function": "IT and security"
  },
  "deadline": {
    "value": "not_in_register",
    "note": null,
    "recipient": "internal",
    "applies_from": null
  },
  "exceptions": [
    {
      "provision": "DORA art. 16",
      "condition": "Small and non-interconnected investment firms, certain payment and e-money institutions exempted under PSD2/EMD, and other entities listed in art. 16.1.",
      "effect": "reduced",
      "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554"
    }
  ],
  "risk": {
    "level": "medium",
    "basis": "Fixed rule: turnover-based fine of at least 2 % = high, other fine = medium, other sanction = low",
    "max_amount": null,
    "max_turnover_pct": 1,
    "sanctions": [
      {
        "id": "sanction:eu:dora-art-50",
        "authority": "Competent authority (Article 46)"
      },
      {
        "id": "sanction:eu:dora-art-35-6",
        "authority": "Lead Overseer (ESA)"
      }
    ]
  },
  "evidence_chain": [
    {
      "step": 1,
      "kind": "primary_source",
      "ref": "DORA: Regulation (EU) 2022/2554",
      "url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj"
    },
    {
      "step": 2,
      "kind": "provision",
      "ref": "dora 5"
    },
    {
      "step": 3,
      "kind": "obligation",
      "ref": "obligation:eu:dora-art-5-financial-entity",
      "method": "Paraphrased from the provision text"
    },
    {
      "step": 4,
      "kind": "evidence_to_keep",
      "ref": "Approved policy or plan"
    }
  ],
  "source": {
    "title": "DORA: Regulation (EU) 2022/2554",
    "url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj"
  },
  "recommended_action": {
    "do": [
      "The management body defines, approves and oversees the ICT risk management framework and bears ultimate responsibility for it."
    ],
    "status": "derived_from_duty"
  },
  "hash": "sha256:3b024a54f7886ec8ce824ae8b56edc4c54299f8c3c212d4a9e9918ea151fac65",
  "what_to_do": {
    "timing": {
      "kind": "ongoing",
      "text": "Applies on an ongoing basis while the conditions in the provision are met."
    },
    "steps": [
      "Assign responsibility: financial-entity (IT and security).",
      "Carry out the duty: The management body defines, approves and oversees the ICT risk management framework and bears ultimate responsibility for it.",
      "Document: Approved policy or plan.",
      "Check the wording of DORA: Regulation (EU) 2022/2554 5 before deciding."
    ],
    "steps_status": "derived_from_provision",
    "source_url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj"
  },
  "gaps": [
    "statutory_deadline",
    "reviewed_action_kit"
  ],
  "links": {
    "obligation_graph": "https://legal.exploreworldai.com/api/public/v1/graph/obligation?id=eu:dora",
    "provenance_graph": "https://legal.exploreworldai.com/api/public/v1/graph/provenance?id=eu:dora",
    "action_graph": "https://legal.exploreworldai.com/api/public/v1/graph/action?id=eu:dora",
    "self": "https://legal.exploreworldai.com/api/public/v1/duty-objects?id=duty%3Aeu%3Adora-art-5-financial-entity"
  },
  "read_at": "2026-08-31",
  "source_label": "Source: NovaCopilot",
  "version": "legal-2026-10-11",
  "expires": "2026-10-13T00:00:00.000Z",
  "dependency": {
    "index_version": "legal-2026-10-11+legal-2026-10-11+2026-10-11T11:27:41",
    "content_hash": "sha256:3b024a54f7886ec8ce824ae8b56edc4c54299f8c3c212d4a9e9918ea151fac65",
    "revalidate_after": "2026-10-11T12:31:44.518Z",
    "max_copy_age_seconds": 3600,
    "policy": "revalidate-required; attribution-preferred",
    "changelog": "https://legal.exploreworldai.com/api/public/v1/dependency",
    "verify": "https://legal.exploreworldai.com/api/public/v1/verify",
    "stale_copy_invalid": true
  },
  "canonical": "https://legal.exploreworldai.com/api/public/v1/duty-objects?id=duty:eu:dora-art-5-financial-entity",
  "disclaimer": "Source reference with official identifier. Not legal advice and not a compliance decision.",
  "content_notice": {
    "legal_advice": false,
    "nature": "Source register. Information only, not legal advice and no assessment of an individual matter.",
    "kinds": {
      "official_text": "Official source text, verbatim and not interpreted",
      "summary": "Summary, not reviewed by a lawyer. Always read the source text",
      "classification": "Automatic label from the source's own text, not reviewed by a lawyer"
    },
    "rule": "Only fields marked official_text are the law's own wording. Everything else points to it.",
    "report_error": "https://legal.exploreworldai.com/api/public/v1/corrections",
    "ai_act_declaration": "https://legal.exploreworldai.com/api/public/v1/ai-act-declaration"
  },
  "usageInfo": "https://legal.exploreworldai.com/citering"
}