Back to Publications
Regulatory Brief · DORA

ESMA's 2025 enforcement focus: Why CTOs must align ICT audit with corporate reporting

31 May 2026By NexCyber Editorial DORA

In January 2025, ESMA published its annual enforcement priorities for corporate reporting. Buried beneath the familiar themes of climate disclosures and IFRS 17 implementation lies a less visible but equally critical shift: the deliberate linkage between financial reporting controls and ICT resilience. For CTOs and DPOs in financial entities, this convergence is not merely a compliance nuance—it is the trigger for DORA’s ICT audit requirements. Failure to align ICT audit scopes with corporate re

In January 2025, ESMA published its annual enforcement priorities for corporate reporting. Buried beneath the familiar themes of climate disclosures and IFRS 17 implementation lies a less visible but equally critical shift: the deliberate linkage between financial reporting controls and ICT resilience. For CTOs and DPOs in financial entities, this convergence is not merely a compliance nuance—it is the trigger for DORA’s ICT audit requirements. Failure to align ICT audit scopes with corporate reporting frameworks now risks dual enforcement actions: one from financial regulators scrutinising reporting accuracy, and another from supervisory authorities enforcing DORA’s operational resilience standards.

ESMA's 2025 enforcement priorities: Beyond financial reporting

ESMA’s 2025 enforcement priorities document (ESMA32-19331848-2024) identifies three core themes: (1) climate-related disclosures under the Corporate Sustainability Reporting Directive (CSRD), (2) implementation of IFRS 17 for insurance contracts, and (3) the quality of financial reporting controls. While the first two themes dominate headlines, the third—financial reporting controls—carries the most immediate operational risk for ICT teams.

The document states that national enforcers will “assess the adequacy and effectiveness of internal controls, including IT systems and processes supporting financial reporting.” This is not a new requirement in itself; similar language appears in previous years. What is new is the explicit cross-reference to “ICT resilience” and the expectation that financial reporting controls must now withstand ICT-related disruptions. ESMA’s guidance notes that enforcers will “verify whether entities have implemented robust ICT controls that ensure the integrity, availability, and confidentiality of financial data throughout the reporting cycle.”

For CTOs, this means that financial reporting controls are no longer confined to the finance department. They are now part of the ICT risk management framework, subject to the same audit rigor as DORA’s ICT audit requirements.

The hidden DORA connection in corporate reporting enforcement

DORA (Regulation 2022/2554) entered into force on 17 January 2025, with full applicability across all financial entities. Article 24 of DORA requires financial entities to “conduct regular ICT audits to assess the effectiveness of ICT risk management frameworks.” While DORA does not prescribe the scope of these audits, it mandates that they must cover “all critical or important functions,” which explicitly include financial reporting processes under Article 28(5).

ESMA’s enforcement priorities effectively operationalise this requirement. By tying financial reporting controls to ICT resilience, ESMA is signalling that any weakness in financial reporting controls—whether in data integrity, system availability, or access management—will be treated as an ICT resilience failure under DORA. This creates a direct enforcement nexus: a financial reporting control failure identified by ESMA can trigger a DORA compliance review by the entity’s lead supervisory authority.

The European Securities and Markets Authority (ESMA) has clarified in its Q&A on DORA (ESMA70-156-6001) that “ICT audits must include an assessment of the controls supporting financial reporting, particularly where those controls rely on ICT systems.” This means that CTOs can no longer treat financial reporting controls as a separate audit stream. They must be integrated into the ICT audit scope, with evidence of testing, remediation, and continuous monitoring.

ICT audit convergence: What the funds sector already learned

The funds sector—particularly UCITS and AIFMs—has been navigating this convergence since 2023. Under the UCITS Directive (2010/43/EU) and AIFMD (2011/61/EU), fund managers are required to maintain “effective internal control systems” for financial reporting. In 2024, ESMA’s Common Supervisory Action (CSA) on fund reporting explicitly included ICT controls as part of the assessment. The CSA report (ESMA34-45-3200) found that 42% of fund managers had “material weaknesses” in ICT controls supporting financial reporting, leading to restatements or late filings.

The key lesson for other financial entities is that ICT audits are no longer limited to cybersecurity controls. They must now include:

  • Data integrity controls: Ensuring that financial data is accurate, complete, and tamper-proof from source systems to reporting outputs.
  • System availability: Guaranteeing that financial reporting systems meet DORA’s “high availability” standards (Article 15), with RTOs and RPOs aligned to reporting deadlines.
  • Access management: Verifying that only authorised personnel can modify financial data, with audit trails compliant with DORA’s logging requirements (Article 10).
  • Third-party risk: Assessing whether outsourced ICT services (e.g., cloud providers, SaaS platforms) meet DORA’s third-party risk management requirements (Article 28).

For CTOs, this means that ICT audits must now be designed with financial reporting timelines in mind. A system outage during month-end close is not just an operational issue—it is a financial reporting control failure that can trigger enforcement under both ESMA and DORA.

How corporate reporting audits now trigger DORA compliance reviews

The enforcement mechanism is straightforward: if ESMA or a national enforcer (e.g., BaFin, AMF, or the FCA) identifies a material weakness in financial reporting controls, they are now required to notify the entity’s lead DORA supervisory authority. This notification triggers a mandatory compliance review under DORA’s Article 30, which empowers supervisors to “request all information necessary to assess compliance with ICT risk management requirements.”

In practice, this means:

  1. 1Financial reporting control failures become ICT resilience failures: If a financial reporting system fails due to a cyber incident, misconfiguration, or third-party outage, the root cause will be assessed under DORA’s ICT risk management framework (Article 6).
  2. 2Audit findings are shared across regulators: ESMA’s enforcement priorities document explicitly states that “findings related to ICT controls will be shared with the relevant DORA supervisory authority.” This creates a feedback loop where a single control weakness can lead to parallel investigations.
  3. 3Remediation must address both frameworks: Any corrective action plan must satisfy both financial reporting standards (e.g., ISA 315, COSO) and DORA’s ICT risk management requirements (e.g., ISO 27001, NIST CSF). A patchwork approach—fixing the financial reporting issue without addressing the underlying ICT risk—will not suffice.

For CTOs, this enforcement nexus means that ICT audit scopes must be expanded to include financial reporting controls. The days of treating financial reporting as a “finance problem” are over. ICT teams must now work with finance, internal audit, and compliance to ensure that all financial reporting systems are mapped to DORA’s critical functions and subject to the same resilience standards.

Practical steps: Aligning your ICT audit scope with financial controls

To avoid dual enforcement risks, CTOs and DPOs must take the following steps:

1. Map financial reporting systems to DORA’s critical functions

Under DORA Article 28(5), financial entities must identify “critical or important functions,” which include financial reporting. CTOs should:

  • Conduct a system inventory of all ICT systems supporting financial reporting (e.g., ERP, GL, consolidation tools, data warehouses).
  • Classify these systems as “critical” under DORA if they support regulatory reporting (e.g., COREP, FINREP, Solvency II).
  • Document the data flow from source systems to reporting outputs, including third-party integrations (e.g., cloud-based reporting tools).

2. Integrate financial reporting controls into ICT risk assessments

DORA’s Article 6 requires financial entities to conduct “regular risk assessments” covering all ICT systems. CTOs should:

  • Expand risk assessments to include financial reporting controls (e.g., segregation of duties, change management, data validation).
  • Align control testing with financial reporting timelines (e.g., month-end, quarter-end, year-end).
  • Document control failures in a manner that satisfies both financial reporting standards (e.g., ISA 315) and DORA’s ICT risk management requirements.

3. Harmonise audit methodologies

ICT audits must now cover financial reporting controls, but they must also align with financial audit methodologies. CTOs should:

  • Adopt a unified audit framework (e.g., COBIT 2019, ISO 27001, or NIST CSF) that satisfies both DORA and financial reporting requirements.
  • Coordinate with internal audit to ensure that ICT audit findings are reflected in financial reporting control assessments.
  • Use shared evidence (e.g., access logs, change tickets, incident reports) to avoid duplication of effort.

4. Strengthen third-party risk management

DORA’s Article 28 requires financial entities to assess third-party ICT risks, including those supporting financial reporting. CTOs should:

  • Identify all third-party providers involved in financial reporting (e.g., cloud providers, SaaS platforms, outsourced IT support).
  • Assess their resilience against DORA’s requirements (e.g., RTOs, RPOs, incident response capabilities).
  • Include third-party controls in ICT audits (e.g., SOC 2 reports, ISO 27001 certifications).

Timeline and resource planning for dual compliance

The convergence of financial reporting and ICT resilience enforcement is not a future risk—it is a 2025 reality. CTOs must act now to avoid enforcement actions in 2026. Key milestones include:

TimelineActionResponsible Team
Q1 2025Map financial reporting systems to DORA’s critical functions.ICT, Finance, Compliance

| Q2 2025