{
  "attribution": {
    "source": "legal.exploreworldai.com",
    "canonical": "https://legal.exploreworldai.com/api/public/v1/obj/risk_chain/eu:dora--financial-entity",
    "cite_as": "NovaCopilot, legal.exploreworldai.com (https://legal.exploreworldai.com/api/public/v1/obj/risk_chain/eu:dora--financial-entity)",
    "license": "https://legal.exploreworldai.com/revision",
    "version": "legal-2026-10-09",
    "fingerprint": "ewai:eu:8a01e1",
    "proof": "sha256:290f72344a411d0a7ddb5663dca30202028dcb1e0b58feb79b15cb6db1c886a3",
    "jurisdiction": "eu",
    "lang": "en",
    "publisher": "NovaCopilot by ExploreWorld Legal",
    "terms": "https://legal.exploreworldai.com/om"
  },
  "brand_source": "Source: NovaCopilot",
  "object_type": "risk_chain",
  "object_id": "risk_chain:eu:dora--financial-entity",
  "schema_version": "1",
  "schema": "https://legal.exploreworldai.com/api/public/v1/schemas/risk_chain",
  "url": "https://legal.exploreworldai.com/api/public/v1/obj/risk_chain/eu:dora--financial-entity",
  "source": "NovaCopilot",
  "item": {
    "act": "dora",
    "jurisdiction": "eu",
    "role": "financial-entity",
    "path": "element → obligation → breach → sanction → leading judgment",
    "steps": [
      {
        "elements": [
          "element:dora:ict-risk"
        ],
        "obligation": "obligation:eu:dora-art-5-financial-entity",
        "role": "financial-entity",
        "article": "5",
        "breach": "Failure to: The management body defines, approves and oversees the ICT risk management framework and bears ultimate responsibility for it.",
        "sanctions": [
          {
            "sanction_id": "sanction:eu:dora-art-50",
            "type": "administrative_fine",
            "max_amount": null,
            "max_turnover_pct": null,
            "authority": "Competent authority (Article 46)"
          },
          {
            "sanction_id": "sanction:eu:dora-art-35-6",
            "type": "periodic_penalty",
            "max_amount": null,
            "max_turnover_pct": 1,
            "authority": "Lead Overseer (ESA)"
          }
        ]
      },
      {
        "elements": [
          "element:dora:ict-risk"
        ],
        "obligation": "obligation:eu:dora-art-6-financial-entity",
        "role": "financial-entity",
        "article": "6",
        "breach": "Failure to: Maintain a sound, comprehensive and documented ICT risk management framework.",
        "sanctions": [
          {
            "sanction_id": "sanction:eu:dora-art-50",
            "type": "administrative_fine",
            "max_amount": null,
            "max_turnover_pct": null,
            "authority": "Competent authority (Article 46)"
          },
          {
            "sanction_id": "sanction:eu:dora-art-35-6",
            "type": "periodic_penalty",
            "max_amount": null,
            "max_turnover_pct": 1,
            "authority": "Lead Overseer (ESA)"
          }
        ]
      },
      {
        "elements": [
          "element:dora:ict-risk"
        ],
        "obligation": "obligation:eu:dora-art-11-financial-entity",
        "role": "financial-entity",
        "article": "11",
        "breach": "Failure to: Put in place an ICT business continuity policy with response and recovery plans.",
        "sanctions": [
          {
            "sanction_id": "sanction:eu:dora-art-50",
            "type": "administrative_fine",
            "max_amount": null,
            "max_turnover_pct": null,
            "authority": "Competent authority (Article 46)"
          },
          {
            "sanction_id": "sanction:eu:dora-art-35-6",
            "type": "periodic_penalty",
            "max_amount": null,
            "max_turnover_pct": 1,
            "authority": "Lead Overseer (ESA)"
          }
        ]
      },
      {
        "elements": [
          "element:dora:ict-risk"
        ],
        "obligation": "obligation:eu:dora-art-17-financial-entity",
        "role": "financial-entity",
        "article": "17",
        "breach": "Failure to: Define and implement an ICT-related incident management process.",
        "sanctions": [
          {
            "sanction_id": "sanction:eu:dora-art-50",
            "type": "administrative_fine",
            "max_amount": null,
            "max_turnover_pct": null,
            "authority": "Competent authority (Article 46)"
          },
          {
            "sanction_id": "sanction:eu:dora-art-35-6",
            "type": "periodic_penalty",
            "max_amount": null,
            "max_turnover_pct": 1,
            "authority": "Lead Overseer (ESA)"
          }
        ]
      },
      {
        "elements": [
          "element:dora:ict-risk"
        ],
        "obligation": "obligation:eu:dora-art-19-financial-entity",
        "role": "financial-entity",
        "article": "19",
        "breach": "Failure to: Report major ICT-related incidents to the competent authority.",
        "sanctions": [
          {
            "sanction_id": "sanction:eu:dora-art-50",
            "type": "administrative_fine",
            "max_amount": null,
            "max_turnover_pct": null,
            "authority": "Competent authority (Article 46)"
          },
          {
            "sanction_id": "sanction:eu:dora-art-35-6",
            "type": "periodic_penalty",
            "max_amount": null,
            "max_turnover_pct": 1,
            "authority": "Lead Overseer (ESA)"
          }
        ]
      },
      {
        "elements": [
          "element:dora:ict-risk"
        ],
        "obligation": "obligation:eu:dora-art-24-financial-entity",
        "role": "financial-entity",
        "article": "24",
        "breach": "Failure to: Establish a digital operational resilience testing programme.",
        "sanctions": [
          {
            "sanction_id": "sanction:eu:dora-art-50",
            "type": "administrative_fine",
            "max_amount": null,
            "max_turnover_pct": null,
            "authority": "Competent authority (Article 46)"
          },
          {
            "sanction_id": "sanction:eu:dora-art-35-6",
            "type": "periodic_penalty",
            "max_amount": null,
            "max_turnover_pct": 1,
            "authority": "Lead Overseer (ESA)"
          }
        ]
      },
      {
        "elements": [
          "element:dora:ict-risk"
        ],
        "obligation": "obligation:eu:dora-art-26-financial-entity",
        "role": "financial-entity",
        "article": "26",
        "breach": "Failure to: Carry out threat-led penetration testing where identified by the competent authority.",
        "sanctions": [
          {
            "sanction_id": "sanction:eu:dora-art-50",
            "type": "administrative_fine",
            "max_amount": null,
            "max_turnover_pct": null,
            "authority": "Competent authority (Article 46)"
          },
          {
            "sanction_id": "sanction:eu:dora-art-35-6",
            "type": "periodic_penalty",
            "max_amount": null,
            "max_turnover_pct": 1,
            "authority": "Lead Overseer (ESA)"
          }
        ]
      },
      {
        "elements": [
          "element:dora:ict-risk"
        ],
        "obligation": "obligation:eu:dora-art-28-financial-entity",
        "role": "financial-entity",
        "article": "28",
        "breach": "Failure to: Manage ICT third-party risk and keep a register of information on all ICT service contracts.",
        "sanctions": [
          {
            "sanction_id": "sanction:eu:dora-art-50",
            "type": "administrative_fine",
            "max_amount": null,
            "max_turnover_pct": null,
            "authority": "Competent authority (Article 46)"
          },
          {
            "sanction_id": "sanction:eu:dora-art-35-6",
            "type": "periodic_penalty",
            "max_amount": null,
            "max_turnover_pct": 1,
            "authority": "Lead Overseer (ESA)"
          }
        ]
      },
      {
        "elements": [
          "element:dora:ict-risk"
        ],
        "obligation": "obligation:eu:dora-art-30-financial-entity",
        "role": "financial-entity",
        "article": "30",
        "breach": "Failure to: Include the key contractual provisions in contracts with ICT third-party service providers.",
        "sanctions": [
          {
            "sanction_id": "sanction:eu:dora-art-50",
            "type": "administrative_fine",
            "max_amount": null,
            "max_turnover_pct": null,
            "authority": "Competent authority (Article 46)"
          },
          {
            "sanction_id": "sanction:eu:dora-art-35-6",
            "type": "periodic_penalty",
            "max_amount": null,
            "max_turnover_pct": 1,
            "authority": "Lead Overseer (ESA)"
          }
        ]
      }
    ],
    "risk_level": "medium",
    "max_turnover_pct": 1,
    "leading_judgments": [],
    "gaps": [
      "no_judgment_in_register"
    ],
    "method": "Obligation and sanction registers joined on obligation ID; leading judgments are the newest in the outcome sample.",
    "links": {
      "obligations": [
        "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-5-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-6-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-11-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-17-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-19-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-24-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-26-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-28-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-30-financial-entity"
      ],
      "outcome": "https://legal.exploreworldai.com/api/public/v1/obj/outcome/eu:dora",
      "compliance_effects": [
        "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-5-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-6-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-11-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-17-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-19-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-24-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-26-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-28-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-30-financial-entity"
      ],
      "leading": []
    },
    "hash": "97ead1af87344a19333f4a1b0545524357ad91c9272f6154f997d797ffeef9ad"
  },
  "links": {
    "provisions": "https://legal.exploreworldai.com/api/public/v1/obj/provision_link/eu:dora",
    "case_law": {
      "outcome": "https://legal.exploreworldai.com/api/public/v1/obj/outcome/eu:dora",
      "outcome_pattern": "https://legal.exploreworldai.com/api/public/v1/obj/outcome_pattern/eu:dora"
    },
    "evidence": {
      "provenance": null,
      "chain_verify": "https://legal.exploreworldai.com/api/public/v1/changes/verify",
      "object_changes": "https://legal.exploreworldai.com/api/public/v1/objects/changes"
    },
    "compact": "https://legal.exploreworldai.com/api/public/v1/obj/risk_chain/eu:dora--financial-entity?view=compact",
    "representations": {},
    "machine_languages": [
      "en",
      "sv"
    ],
    "ref": "eu:dora--financial-entity"
  },
  "watch": {
    "changes": "https://legal.exploreworldai.com/api/public/v1/changes",
    "whats_new": "https://legal.exploreworldai.com/api/public/v1/whats-new?jurisdiction=eu",
    "conditional": "Send If-None-Match with the ETag; unchanged objects return 304 without body.",
    "recheck_after_seconds": 86400
  },
  "hash": "sha256:290f72344a411d0a7ddb5663dca30202028dcb1e0b58feb79b15cb6db1c886a3",
  "version": "legal-2026-10-09",
  "expires": "2026-10-10T00:00:00.000Z",
  "dependency": {
    "index_version": "legal-2026-10-09+legal-2026-10-09+2026-10-09T02:00:51",
    "content_hash": "sha256:290f72344a411d0a7ddb5663dca30202028dcb1e0b58feb79b15cb6db1c886a3",
    "revalidate_after": "2026-10-09T05:36:46.098Z",
    "max_copy_age_seconds": 3600,
    "policy": "revalidate-required; attribution-preferred",
    "changelog": "https://legal.exploreworldai.com/api/public/v1/dependency",
    "verify": "https://legal.exploreworldai.com/api/public/v1/verify",
    "stale_copy_invalid": true
  },
  "canonical": "https://legal.exploreworldai.com/api/public/v1/obj/risk_chain/eu:dora--financial-entity",
  "disclaimer": "Source reference with official identifier. Not legal advice and not a compliance decision.",
  "content_notice": {
    "legal_advice": false,
    "nature": "Source register. Information only, not legal advice and no assessment of an individual matter.",
    "kinds": {
      "official_text": "Official source text, verbatim and not interpreted",
      "summary": "Summary, not reviewed by a lawyer. Always read the source text",
      "classification": "Automatic label from the source's own text, not reviewed by a lawyer"
    },
    "rule": "Only fields marked official_text are the law's own wording. Everything else points to it.",
    "report_error": "https://legal.exploreworldai.com/api/public/v1/corrections",
    "ai_act_declaration": "https://legal.exploreworldai.com/api/public/v1/ai-act-declaration"
  },
  "usageInfo": "https://legal.exploreworldai.com/citering"
}