Back to Publications
Regulatory Brief · DORA

ESMA's 2025 Corporate Reporting Enforcement: What CTOs Must Know

31 May 2026By NexCyber Editorial DORA

In January 2025, the European Securities and Markets Authority (ESMA) published its *Public Statement on Enforcement Priorities for 2025 Annual Financial Reports*. For the first time, the statement explicitly links ICT audit expectations under the Digital Operational Resilience Act (DORA) to corporate reporting enforcement. CTOs in financial entities—banks, insurers, investment firms, and even listed non-financial companies—now face a dual mandate: ensure financial disclosures are accurate *and*

In January 2025, the European Securities and Markets Authority (ESMA) published its *Public Statement on Enforcement Priorities for 2025 Annual Financial Reports*. For the first time, the statement explicitly links ICT audit expectations under the Digital Operational Resilience Act (DORA) to corporate reporting enforcement. CTOs in financial entities—banks, insurers, investment firms, and even listed non-financial companies—now face a dual mandate: ensure financial disclosures are accurate *and* demonstrate that the ICT systems underpinning those disclosures are resilient, auditable, and compliant with DORA. This shift elevates ICT controls from a back-office concern to a board-level risk.

---

ESMA's 2025 Enforcement Roadmap: What Changed Since 2024

ESMA’s 2025 priorities reflect a structural evolution in how financial reporting is scrutinised. Unlike previous years, where enforcement focused on accounting standards (IFRS) and non-financial disclosures (NFRD/CSRD), the 2025 statement introduces a new dimension: operational resilience of reporting systems. This change is not coincidental. It aligns with the entry into force of DORA on 17 January 2025, which mandates that financial entities implement robust ICT risk management frameworks (DORA Article 5) and conduct regular ICT audits (DORA Article 24).

Key changes in ESMA’s 2025 enforcement approach:

  • ICT audit trails as evidence: ESMA will now request documentation proving that financial data flows—from transaction capture to final disclosure—are supported by auditable ICT controls. This includes logs, access controls, and change management records.
  • Third-party risk scrutiny: The statement highlights the need for entities to assess and disclose ICT risks stemming from critical third-party providers (CTPPs), a direct echo of DORA’s third-party oversight requirements (DORA Article 28).
  • Incident reporting alignment: ESMA expects entities to reconcile material ICT incidents (as defined in DORA Article 18) with their financial disclosures, particularly if incidents impacted financial performance or controls.

For CTOs, this means that ICT systems are no longer just enablers of financial reporting—they are now *subject to enforcement*.

---

The ICT-Audit Nexus in Corporate Reporting: Where DORA Meets Financial Disclosure

The intersection of DORA and corporate reporting enforcement creates a new compliance frontier: ICT-enabled financial integrity. ESMA’s 2025 priorities make it clear that financial disclosures are only as reliable as the systems that produce them. This principle is embedded in two key DORA provisions:

  1. 1DORA Article 6(1): Financial entities must ensure that their ICT systems are "resilient, secure, and capable of ensuring the continuity of critical or important functions". For CTOs, this translates to ensuring that reporting systems (e.g., ERP, GL, consolidation tools) are not only available but also tamper-proof and auditable.
  2. 2DORA Article 24(1): Entities must conduct "regular independent audits of ICT systems". ESMA’s 2025 statement clarifies that these audits must now cover the ICT controls supporting financial reporting, including: - Data integrity controls (e.g., checksums, reconciliation processes). - Access management (e.g., role-based access, segregation of duties). - Change management (e.g., version control, approval workflows for system updates).

The practical implication? CTOs must now work closely with CFOs and audit committees to ensure that ICT controls are not only designed but *tested* and *documented* in a way that satisfies both DORA and ESMA’s enforcement teams.

---

Three High-Risk Areas ESMA Will Target First

ESMA’s 2025 statement identifies three ICT-related areas where enforcement actions are most likely to occur. CTOs should prioritise these in their compliance efforts:

1. Data Integrity in Automated Reporting Systems

ESMA will scrutinise whether entities have controls to prevent or detect data manipulation in automated reporting pipelines. This includes:

  • End-to-end data lineage: Entities must demonstrate how data moves from source systems (e.g., trading platforms, core banking) to financial statements, including all transformations and validations.
  • Automated reconciliation: ESMA expects entities to implement automated reconciliation processes (e.g., between sub-ledgers and the general ledger) with alerts for discrepancies.
  • Audit trails for manual adjustments: Any manual overrides to automated reporting processes must be logged, justified, and approved.

*DORA linkage*: DORA Article 7(2) requires entities to implement "mechanisms to ensure the integrity, availability, and confidentiality of data". ESMA’s focus on data integrity is a direct application of this requirement.

2. Third-Party ICT Risk in Financial Reporting

ESMA’s 2025 priorities emphasise that entities must assess and disclose ICT risks from third-party providers involved in financial reporting. This includes:

  • Cloud providers: If financial data is processed or stored in the cloud, entities must demonstrate that the provider meets DORA’s resilience requirements (DORA Article 28(4)).
  • Software vendors: Entities using third-party reporting tools (e.g., SAP, Oracle, Workiva) must ensure these vendors comply with DORA’s ICT risk management standards.
  • Outsourced IT functions: If IT operations (e.g., cybersecurity, network management) are outsourced, entities must conduct due diligence on the provider’s resilience and disclose material risks.

*DORA linkage*: DORA Article 28(5) requires entities to "identify and assess risks related to the use of third-party service providers". ESMA’s enforcement will likely focus on whether entities have conducted this assessment and disclosed material risks in their financial reports.

3. Incident Reporting and Financial Disclosure Alignment

ESMA expects entities to reconcile ICT incidents with their financial disclosures. Key focus areas:

  • Materiality thresholds: Entities must define what constitutes a "material" ICT incident (DORA Article 18) and ensure these incidents are disclosed in financial reports if they impact financial performance or controls.
  • Timeliness: ESMA will check whether ICT incidents are reported to competent authorities (as required by DORA Article 19) and reflected in financial disclosures in a timely manner.
  • Remediation transparency: Entities must disclose the status of remediation efforts for material ICT incidents, including any financial impacts (e.g., costs, losses, or operational disruptions).

*DORA linkage*: DORA Article 18(1) requires entities to report "major ICT-related incidents" to competent authorities. ESMA’s enforcement will ensure these incidents are also reflected in financial disclosures where relevant.

---

How to Audit Your Own ICT Controls Against ESMA's Enforcement Lens

To prepare for ESMA’s 2025 enforcement, CTOs should conduct a self-audit of their ICT controls using the following framework. This audit should align with DORA’s requirements and ESMA’s priorities:

Step 1: Map Financial Reporting Processes to ICT Systems

  • Identify all ICT systems involved in financial reporting (e.g., ERP, GL, consolidation tools, data warehouses).
  • Document data flows between these systems, including interfaces, APIs, and manual processes.
  • *ESMA focus*: Ensure data lineage is clear and auditable.

Step 2: Assess Data Integrity Controls

  • Review controls for data validation, reconciliation, and error handling.
  • Test automated reconciliation processes (e.g., between sub-ledgers and the general ledger).
  • *ESMA focus*: Ensure manual adjustments are logged and approved.

Step 3: Evaluate Third-Party ICT Risks

  • Identify all third-party providers involved in financial reporting (e.g., cloud providers, software vendors, outsourced IT functions).
  • Assess their compliance with DORA’s ICT risk management requirements (DORA Article 28).
  • *ESMA focus*: Ensure material risks are disclosed in financial reports.

Step 4: Test Incident Reporting and Disclosure Processes

  • Define materiality thresholds for ICT incidents (DORA Article 18).
  • Test incident reporting workflows to ensure they align with financial disclosure timelines.
  • *ESMA focus*: Ensure incidents are disclosed in financial reports where relevant.

Step 5: Document and Report Findings

  • Compile audit findings into a report for the board and audit committee.
  • Identify gaps and develop a remediation plan with clear timelines.
  • *ESMA focus*: Ensure documentation is sufficient to demonstrate compliance during enforcement actions.

---

Timeline and Compliance Checkpoints for Q2–Q4 2025

ESMA’s enforcement priorities will be applied to annual financial reports published in 2025 (covering the 2024 financial year). However, CTOs should not wait until year-end to act. Below is a timeline with key compliance checkpoints:

QuarterKey Actions
Q2 2025- Conduct self-audit of ICT controls (as outlined above).
- Identify gaps and develop remediation plan.
- Engage with third-party providers to assess DORA compliance.
Q3 2025- Implement remediation measures for high-risk gaps.
- Test incident reporting and disclosure processes.
- Train finance and IT teams on new ICT audit requirements.
Q4 2025- Finalise documentation for financial reporting (e.g., ICT audit trails, incident logs).
- Conduct pre-submission review with internal audit and external auditors.
- Prepare for potential ESMA enforcement actions (e.g., mock audits).

*Key deadline*: Entities must ensure their 2025 annual financial reports (published in early 2026) reflect compliance with ESMA’s 2025 priorities.

---

Common Pitfalls: Why Financial