Back to Publications
Regulatory Brief · DORA

DORA meets MiFID II: How compliance audits must evolve for sustainability reporting

30 May 2026By NexCyber Editorial DORA

The European Securities and Markets Authority (ESMA) has sent a clear signal: supervision of MiFID II sustainability disclosures will be "proportionate." For CTOs and compliance leads in investment firms and fund managers, this might sound like regulatory breathing room. It is not. The Digital Operational Resilience Act (DORA) remains unyielding on internal audit rigor, creating a compliance audit gap that demands immediate attention. Sustainability reporting is no longer a standalone ESG exerci

The European Securities and Markets Authority (ESMA) has sent a clear signal: supervision of MiFID II sustainability disclosures will be "proportionate." For CTOs and compliance leads in investment firms and fund managers, this might sound like regulatory breathing room. It is not. The Digital Operational Resilience Act (DORA) remains unyielding on internal audit rigor, creating a compliance audit gap that demands immediate attention. Sustainability reporting is no longer a standalone ESG exercise—it is now a material ICT risk, and DORA’s Chapter III redefines what "effective" internal audit means in practice.

---

ESMA’s Proportionate Supervision Signal: What It Means for Compliance Teams

In its 2024 Corporate Reporting Enforcement Priorities, ESMA stated that National Competent Authorities (NCAs) should apply a "proportionate approach" when assessing compliance with MiFID II sustainability-related disclosures (EUR-Lex Regulation 2019/2088, Article 3). This proportionality is not a relaxation of standards. It is a risk-based calibration: smaller firms with limited product ranges or simpler client profiles may face lighter scrutiny, but the substantive requirements remain unchanged.

For compliance teams, this means two things:

  1. 1No safe harbors: Proportionality does not equal exemption. Firms must still document how they meet MiFID II’s sustainability preferences (Article 25(2a)) and product governance rules (Article 9(9a)).
  2. 2Audit expectations shift: ESMA’s signal is about *supervision*, not *compliance*. DORA’s internal audit requirements (Chapter III) are independent of ESMA’s enforcement stance. Firms cannot assume that lighter NCA scrutiny translates to lighter audit burdens.

The key takeaway: ESMA’s proportionality is a supervisory tool, not a compliance shortcut. DORA’s audit standards are absolute.

---

The DORA Compliance Audit Gap: Why Proportionality Doesn’t Exempt You

DORA’s Article 25 requires financial entities to establish an internal audit function that is "independent, objective, and technically competent." This function must assess the "adequacy and effectiveness" of the firm’s ICT risk management framework (Article 6(5)). Critically, DORA does not carve out exceptions for sustainability reporting—even if ESMA’s supervision is proportionate.

The compliance audit gap emerges here:

  • MiFID II treats sustainability disclosures as conduct and transparency obligations.
  • DORA treats them as operational risks tied to ICT systems, data integrity, and third-party dependencies.

For example, a fund manager using a cloud-based ESG data provider to populate client reports must now audit that provider under DORA’s Article 28(5) (third-party risk management). ESMA’s proportionality stance does not alter this obligation. The gap is not regulatory—it is perceptual. Firms that view sustainability reporting as a "soft" disclosure exercise will fail DORA’s audit standards.

---

How DORA Chapter III Redefines ‘Effective’ Internal Audit in Funds and Investment Firms

DORA’s Chapter III (Articles 25–27) elevates internal audit from a periodic check to a continuous governance function. Three provisions are particularly transformative for sustainability reporting:

1. **Scope Expansion: From Financial to Operational Resilience**

DORA’s Article 25(2) requires internal audit to cover "all material risks," including those arising from ICT systems. Sustainability data—whether sourced from internal databases, third-party providers, or client questionnaires—is now a material ICT risk. Auditors must test:

  • Data lineage: Can the firm trace ESG metrics back to their source?
  • System integrity: Are sustainability data fields protected against unauthorized changes?
  • Access controls: Who can modify sustainability preferences in client portals?

2. **Frequency and Depth: The End of Annual Audits**

DORA’s Article 26 mandates that internal audit plans be "risk-based and proportionate," but it does not specify a minimum frequency. ESMA’s 2025 roadmap clarifies the expectation: firms must align audit cycles with the velocity of their sustainability data flows. For high-frequency traders or firms with dynamic ESG product offerings, this could mean quarterly or even real-time audits of sustainability data pipelines.

3. **Board Accountability: The Buck Stops with the CISO**

DORA’s Article 27 requires the management body to "oversee" the internal audit function. For sustainability reporting, this means:

  • The CISO must attest that ICT controls for ESG data meet DORA’s standards.
  • The board must review audit findings on sustainability data risks as part of its Article 5 governance obligations.
  • Audit reports must explicitly link sustainability disclosures to ICT risk management (e.g., "Client sustainability preferences are stored in System X, which has the following control gaps...").

---

Sustainability Reporting as an ICT Risk: The Convergence Point

The collision between MiFID II and DORA crystallizes around one reality: sustainability reporting is no longer a disclosure exercise—it is an ICT risk management challenge. Three convergence points demand attention:

1. **Data Integrity as a Systemic Risk**

MiFID II’s Article 25(2a) requires firms to collect and act on client sustainability preferences. DORA’s Article 9 requires firms to ensure the "accuracy, integrity, and availability" of data. For sustainability reporting, this means:

  • Accuracy: Are ESG metrics free from errors or manipulation?
  • Integrity: Are changes to sustainability preferences logged and immutable?
  • Availability: Can the firm retrieve historical sustainability data during a DORA incident report (Article 19)?

2. **Third-Party Providers: The Weakest Link**

Many firms rely on external ESG data providers (e.g., MSCI, Sustainalytics) or SaaS platforms for sustainability reporting. DORA’s Article 28 requires firms to:

  • Classify these providers as "critical or important" if they support sustainability disclosures.
  • Conduct due diligence on their ICT resilience (e.g., do they meet DORA’s Article 11 requirements?).
  • Include them in the firm’s Article 28(9) register of third-party ICT service providers.

3. **Incident Reporting: Sustainability as a Trigger**

DORA’s Article 19 requires firms to report "major ICT-related incidents" to NCAs. A sustainability data breach—such as unauthorized changes to client ESG preferences—could qualify as a reportable incident if it:

  • Affects the firm’s ability to meet MiFID II disclosure obligations.
  • Results in financial loss or reputational damage.
  • Involves a third-party provider (e.g., a cloud outage at an ESG data vendor).

---

Practical Steps: Audit Scope, Documentation, and Third-Party Validation

To close the compliance audit gap, firms must take five concrete steps:

1. **Map Sustainability Data Flows to ICT Systems**

  • Identify all systems that store, process, or transmit sustainability data (e.g., CRM, portfolio management, client portals).
  • Document data lineage: Where does ESG data originate, and how does it flow through the firm?
  • Classify systems by criticality under DORA’s Article 8.

2. **Align Internal Audit Scope with DORA’s Chapter III**

  • Update audit charters to explicitly include sustainability reporting as an ICT risk.
  • Test controls for: - Data integrity (e.g., checksums, change logs). - Access management (e.g., role-based access to ESG data fields). - Third-party resilience (e.g., contractual clauses for ESG data providers).

3. **Document Proportionality Rationale**

  • If applying ESMA’s proportionality principle, document why (e.g., "Our firm has 50 clients and offers only two ESG-aligned funds").
  • Ensure this rationale is auditable and linked to DORA’s risk-based approach (Article 26).

4. **Third-Party Validation: Beyond Contractual Clauses**

  • Require ESG data providers to demonstrate compliance with DORA’s Article 28(5) (e.g., SOC 2 Type II reports, ISO 27001 certifications).
  • Conduct on-site audits or request evidence of their own internal audit functions.

5. **Board-Level Reporting: Connect the Dots**

  • Present audit findings in a format that links sustainability risks to ICT resilience (e.g., "System Y, which stores client ESG preferences, has the following control gaps...").
  • Ensure the board’s Article 5 oversight includes sustainability data risks.

---

Timeline and Enforcement Priorities from ESMA’s 2025 Corporate Reporting Roadmap

ESMA’s 2025 Corporate Reporting Enforcement Priorities provide a clear timeline for compliance teams:

MilestoneAction Required
Q1 2025NCAs begin proportionate supervision of MiFID II sustainability disclosures.
Q2 2025DORA’s internal audit requirements (Chapter III) fully applicable.
Q3 2025ESMA’s first thematic review of sustainability reporting in financial statements.
Q4 2025NCAs expected to issue guidance on DORA-MiFID II convergence.

Enforcement priorities for 2025:

  1. 1Data integrity: Firms must demonstrate that sustainability disclosures are accurate and tamper-proof.
  2. 2Third-party risk: NCAs will scrutinize contracts with ESG data providers for DORA compliance.
  3. 3Audit trails: Firms must maintain immutable logs of changes to sustainability preferences and disclosures.

---

Next Step with NexCyber

The collision between DORA’s audit rigor and MiFID II’s sustainability requirements