How Does DraftKings Proprietary Exchange Launch Licensing Look Like in the Prediction Market Space?
DORA isn’t just a document dump. We explain the real requirements, give you a practical checklist, and show what operational resilience looks like when regulators come knocking. Let’s get you ready.
Anyone who have been through the DORA implementation process with enough clients can say this with confidence: it’s not a paperwork exercise. You don’t draft a pile of documents, file them away somewhere, and move on.
The regulation doesn’t ask you to maintain a list of policies. It puts duties directly on the management board and directors to make sure the organization actually follows these rules day in and day out, and keeps everything current.
In our work, we always see two sides to this. There’s the client’s side, the business operator who has to make all of this work in practice. And there’s our side, as the legal team helping to get it all written down and structured.
Now what is DORA compliance? The acronym itself means Digital Operational Resilience Act. From where we sit, the sheer volume of documentation you have to produce is one thing. But what really takes time is seeing how tightly all these pieces connect: the strategies, policies, procedures, protocols, and tools; and how they’re supposed to work together in practice.
These aren’t abstract exercises. They’re the technical backbone of any modern financial firm. The regulatory push started after 2008, but it picked up steam after events like Mt. Gox in 2014, FTX in 2022, and the wave of cyberattacks during the COVID lockdowns. DORA needs to be read against that background. It’s meant to keep the EU financial system stable and to stop individual incidents from turning into wider crises.
One thing that often gets overlooked is how DORA interacts with sector-specific rules like MiFID II (for investment services) and MiCAR (for crypto-assets). You can’t look at DORA in isolation, it sits within a broader regulatory framework.
Take MiCAR, for example. The most obvious intersection is around private key management for crypto wallets. If a private key is compromised or lost, that’s not just a security breach anymore. Under DORA, it’s a major ICT incident that triggers reporting obligations.
So when we map out compliance for a client, we’re looking at how DORA’s general requirements and the sector-specific rules fit together.
Read our study: Why the Regulator Sees Your Compliance Team as a Single Brain
To give you a sense of scale: the guidebook we give our clients to help them navigate the documentation package runs to about 20 pages. And that’s just the summary, the underlying primary documents run into the hundreds of pages. The guidebook, which one can say a DORA compliance checklist, is there to help clients understand what each document is for, how to use it, and what we need from them to make it work.
Once a client gets that 20-page guidebook, plus all the supporting material and explanations, the real work begins.
The hard part isn’t identifying the obligations, but rather applying them to an actual organization with real people, real workflows, and real constraints.
Compliance officers, technical leads, key contacts; all of these documents only come to life through the efforts of people inside the organization. And from a practical standpoint, planning, executing, overseeing, and improving this stuff is as much a management challenge as it is a compliance one.
Let’s make this less abstract. One of the documents in a proper DORA compliance suite will cover physical access to server rooms or other premises housing critical ICT hardware. It’ll set out rules for who can enter, how access is monitored, and what you can and can’t do in those spaces.
But drafting the policy is the easy part. The harder questions come next: who actually does the monitoring? Who approves access? Who’s the backup if the primary person is unavailable? Have they been trained? Do they know what to do if something goes wrong? And from a purely legal standpoint, does their employment contract actually cover these duties, or could they refuse to carry them out?
This is why we always tell clients to set clear expectations, both formally and informally. Working for a DORA-regulated entity brings a lot of specific requirements, and people need to understand that upfront. A strong compliance culture is essential.
Also read: When Does an In-Game Virtual Money Trigger a License?
Someone looking at this from the outside might think, “this is just another set of documents to prepare and file away,” and assume it only affects traditional banks with branch networks. That would be a mistake.
If you’re in scope, you’ll find yourself:
spending a significant amount of time working through the documentation (or trying to produce it all in-house, which is a massive undertaking) and figuring out what each piece is actually for;
updating employment contracts to reflect DORA-related duties, and training staff on how to follow them, including handling questions and edge cases;
setting up secure communication channels and document repositories, with access rights tied to specific roles;
rethinking organizational roles so that existing teams take on DORA-specific tasks, which might mean, for example, that HR suddenly has compliance functions they never had before;
procuring the hardware and software needed to run a compliant ICT system, and critically vetting third-party providers thoroughly and maintaining a register of information that authorities can access.
This isn’t something you can knock out in a weekend. And it’s not something you can fully outsource on a “pay and forget” basis. The management board remains fully and personally liable for any failures.
The smart move is to invest early, get feedback, and prepare for organization-wide implementation with ongoing support from professionals who know what they’re doing.
When business stakeholders ask us about compliance risks, the questions usually come down to: what’s the worst that can happen, how likely is enforcement, and how bad would the consequences be?
Here’s the reality:
Regulators can order you to stop operating. They have the power to require you to cease any non-compliant activity, temporarily or permanently. For a digital-first business or a crypto-asset service provider, that doesn’t mean locking an office door, it means suspending your license, shutting down online operations, cutting off API integrations, and halting transactions. Your business grinds to a halt, and you’re left dealing with the fallout from clients, partners, and counterparties.
The company can be fined up to 10% of turnover. That means someone from management has to authorize the payment, explain it to shareholders and investors, and adjust the budget accordingly.
Directors can be fined personally, up to €500,000 or more. DORA makes individual liability explicit. In some member states, it goes higher. Belgium and Italy allow up to €5 million. That comes out of the director’s own pocket.
You’ll need to find compliant providers fast. That means market research, contract negotiations, and signing agreements under pressure.
Then you have to manage the internal implementation. Which is its own challenge.
And if Murphy’s Law kicks in? Consider the following:
the payment system fails or liquidity dries up?
the market is undersupplied, or you can’t get a contract signed?
key managers go on sick leave?
a major partnership falls apart because of a cease-operations order, leaving you with early-termination penalties or irrecoverable costs?
The position you want to be in is having the guidance document and core compliance materials well in advance, so you have time to ask questions and work through the details.
That means assessing early whether DORA applies to your business model and recognizing that this is a framework that requires ongoing effort, not just a one-off documentation exercise.
Aim to be in a position where, on three days’ notice, you or your team can explain your compliance setup to a regulator without dropping your day-to-day operations. And where you can confidently send someone to an in-person meeting with the regulator or handle an audit.
Compare two scenarios:
Three months to prepare: you already have the documentation in place, internal processes running, and specific staff trained. Those three days are just for final alignment and review.
Three weeks to prepare: you’re scrambling to outsource most of the work to external providers at emergency rates. Those three days are spent just figuring out how to respond while everything else gets put on hold and you’re staring down serious regulatory risk.