Additional Broadridge resources:
View our Contact Us page for additional information.
One of our sales representatives will email you about your submission.
Welcome back, {firstName lastName}.
Not {firstName}? Clear the form.
Want to speak with a sales representative?
Your sales rep submission has been received. One of our sales representatives will contact you soon.
Our representatives and specialists are ready with the solutions you need to advance your business.
Want to speak with a sales representative?
Table Heading | |
+1 800 353 0103 | North America |
+442075513000 | EMEA |
+65 6438 1144 | APAC |
Your sales rep submission has been received. One of our sales representatives will contact you soon.
Want to speak with a sales representative?
Table Heading | |
+1 800 353 0103 | North America |
+442075513000 | EMEA |
+65 6438 1144 | APAC |
Nos représentants et nos spécialistes sont prêts à vous apporter les solutions dont vous avez besoin pour faire progresser votre entreprise.
Vous voulez parler à un représentant commercial?
Table Heading | |
+1 800 353 0103 | Amérique du Nord |
+1 905 470 2000 | Canada Markham |
+1 416 350 0999 | Canada Toronto |
Votre soumission a été reçue. Nous communiquerons avec vous sous peu.
Vous souhaitez parler à un commercial ?
Table Heading | |
+1 800 353 0103 | Amérique du Nord |
+1 905 470 2000 | Canada Markham |
+1 416 350 0999 | Canada Toronto |
Our digital world is complex, characterised by a multitude of interconnected systems and data that is stored, and widely shared, online.
It’s well known that cyber threats are becoming more sophisticated, posing significant risks to financial stability and security. Outages too, such as the 2024 CrowdStrike IT issue affecting millions of devices around the world, is one recent example of a left hook that caught many by surprise.
Against this backdrop, the EU’s Digital Operational Resilience Act (DORA) has entered into force, with in-scope firms – including banks and investment firms – required to be fully compliant from 17 January 2025. Fintechs must ensure that they are well-positioned to help banks and investment firms comply.
DORA establishes a clearer foundation for security and operational resilience in the financial services sector, while also aligning with other EU measures on cybersecurity and data. It reflects the thinking in other markets around the world, with regulators increasingly demanding that financial institutions bolster their operational resilience, and that of their supply chains.
DORA is structured around five pillars, covering governance, resiliency, incident management, information sharing, and reporting.
The common thread is the protection of data as it passes through both a financial institution and the ecosystem around it. This is particularly pertinent in the proxy world, and the automated solutions that power proxy voting across global markets. Stakeholders must now pay much closer attention to where the data is going, and ensure they are carrying out detailed information security reviews.
Resiliency in the past has tended to be quite inward looking, with firms focusing on ensuring their own house is in order. DORA has shifted the dial, and mandates firms to extend this externally across service providers utilised.
Beyond ensuring their own compliance, asset managers must also assess and make sure that their service providers can help them comply with DORA. Their responsibility doesn’t end with their primary vendors’ services; they also need to be comfortable that any subcontractors who are providing critical service can also help the asset managers to comply. Failure to do so can result in sanctions of an administrative, financial, or even criminal nature – and the asset manager is always on the hook.
If you are providing services to an asset manager, it’s no longer just a case of ensuring that you are fully compliant and fit for purpose; the buyer needs to be sure that any supplier and any subcontractors of critical services can help you comply with DORA.
Here are the six key information requests you should be cascading urgently. If your suppliers can provide positive answers to all of the below, then you are likely to be DORA compliant. If there are gaps, then there are real to-dos for your firm:
DORA compliance isn’t a nice-to-have; it’s mandatory and it is now business as usual. It’s also worth noting that Broadridge’s 2024 Digital Transformation & Next-Gen Technology Study highlighted that cybersecurity is the top concern of C-suite technology executives, usurping timely delivery of projects and sticking to budgets.
If you are still unclear about your firm’s DORA compliance obligations, I’d strongly advise a conversation with your compliance and product leaders. Further information on DORA is also available in our whitepaper on the topic.
Our representatives and specialists are ready with the solutions you need to advance your business.
Want to speak with a sales representative?
Table Heading | |
+1 800 353 0103 | North America |
+442075513000 | EMEA |
+65 6438 1144 | APAC |
Your sales rep submission has been received. One of our sales representatives will contact you soon.
Want to speak with a sales representative?
Table Heading | |
+1 800 353 0103 | North America |
+442075513000 | EMEA |
+65 6438 1144 | APAC |