Regulation (EU) 2022/2554 · In force since January 2025

DORA banking consultant: programme management for financial institutions

As a DORA banking consultant, I lead the full compliance programme for Regulation (EU) 2022/2554: from the initial gap analysis all the way to reporting to the supervisor. And if your organisation still has gaps across the five pillars, the window to close them narrows every month.

DORA banking consultant: an illustration of the Digital Operational Resilience Regulation applied to the European financial sector
30+ Years in IT and banking
5/5 DORA pillars covered
EU AI Act · NIS2 Complementary frameworks

Why mid-sized institutions need a DORA banking consultant in 2026

“Adapting five regulatory pillars in parallel requires cross-functional coordination that rarely exists organically within an organisation.”

The most common mistake is delegating DORA to the cybersecurity team or the compliance function, without a DORA banking consultant to coordinate IT, legal, procurement and the business as a programme director. The result is disconnected workstreams, inconsistent documentation and gaps the regulator will spot on the first review.

On top of that, fines can reach 2% of global annual turnover for legal entities and up to one million euros for the individuals responsible. The reputational cost, however, always outweighs the financial one.

What hiring a DORA banking consultant includes

What hiring me as a DORA banking consultant: five parallel workstreams aligned with the five pillars of the Regulation, with a single point of contact for the board and the supervisor.

01 · Diagnosis

Initial gap analysis

First, an honest assessment against the five pillars. A real diagnosis of which processes exist, which are partial and which are missing. Without it, any action plan is building on sand.

02 · Structure

A programme of parallel workstreams

Next, the design and launch of the five workstreams aligned with the pillars. Each with milestones, owners and a delivery schedule approved by the board.

03 · Coordination

Cross-functional stakeholder management

DORA, however, is not an IT project. I orchestrate the involvement of legal, procurement, the business and senior management without friction, with the right level of dialogue for each.

04 · Suppliers

Third-party ICT management

On the supplier side: identifying, assessing and monitoring ICT providers. Renegotiating contracts to include the required clauses: audit rights, incident notification, exit plans and measurable indicators.

05 · Supervisor

Regulatory reporting

Finally, documentation and reports for the board and the supervisor (Banco de España, CNMV, DGSFP). Managing communications during major incidents within the deadlines DORA requires.

DORA is not a compliance problem. It’s a programme of projects.

A compliance consultant delivers a gap report. A DORA banking consultant with a Project Manager profile runs the programme that closes them, on time and with reporting to the board.

Direct experience in banking

For example, more than six years as Project Director in banking, leading infrastructure and security initiatives in regulated financial environments. I’m not here to learn the sector: I’ve spent decades in it. Get to know the profile of the AI Project Manager running the programme.

Solid technical grounding in cybersecurity

Microsoft MCSA and MCSE Security certifications, too. Managing critical infrastructure since 1995. I understand DORA’s five pillars from the inside, not just from the regulatory framework.

European regulatory perspective

Also, specialisation in the EU AI Act, DORA and NIS2. The ability to engage with the regulator and translate regulatory requirements into concrete project-management actions.

The AI Forge lab

Hence, the practical application of AI to automating regulatory reporting, continuous monitoring of ICT providers and incident management. What works in production, not in theory.

Results that back the DORA banking consultant profile

In short, more than two decades working as a project manager in banking and IT consulting. These are two voices from technology partners I’ve collaborated with on programmes combining management, critical infrastructure and compliance.

“Jose Enrique combines the dual quality of being an excellent professional and an excellent person. Technically impeccable, with long, contextual vision thanks to his many years of experience. Outstanding.”
Vicente Pérez · Account Manager, IBM
“José Enrique is a highly goal-oriented, business-focused person with a great ability to build inter-company relationships. It’s a pleasure doing business with him.”
Javier Álvarez · Program Rise Director, Lenovo

What people ask me most at the start of a programme

Which entities does DORA apply to exactly?

DORA applies to more than twenty types of entities in the European financial sector: banks, payment institutions, electronic money institutions, investment firms, fund managers, insurers, reinsurers, crypto-asset providers and pension fund managers, among others. It also reaches market infrastructures and the critical ICT providers that serve those entities.

My company isn’t financial, but it provides IT services to a bank. Does DORA affect me?

Yes, indirectly. Financial institutions are required to pass DORA’s requirements down to their ICT providers contractually: audit rights, incident notification, exit plans and measurable indicators. If your company provides cloud, cybersecurity, infrastructure or software development services to an entity under DORA, you’ll receive those obligations by contract.

On implementation and risks

How long does it take to implement a serious DORA programme?

DORA isn’t achieved in six months. Mature institutions structure a multi-year plan: year 1 for governance and risk management, year 2 for testing and third-party management, years 2-3 for advanced maturity. What you can accelerate is closing the most visible gaps for the supervisor within the first 90-120 days of the programme.

What are the real fines for breaching DORA?

Fines can reach 2% of global annual turnover for legal entities and up to one million euros for the individuals responsible. But in practice, the reputational cost of a serious incident without the controls DORA requires usually outweighs the financial one, especially for mid-sized institutions that depend on local client trust.

We already have a compliance consultant. Why do we need a programme director?

A compliance consultant delivers a gap report. A programme director coordinates IT, legal, procurement and the business to close those gaps on time, on budget and with reporting to the board. They’re two distinct, complementary roles; the problem appears when you hire only the first and expect the second to emerge organically.

On how working with me actually works

Do you work as a DORA banking consultant remotely or on-site?

A hybrid model. Most of the coordination, documentation and reporting work is done remotely. Critical sessions with the board, workshops with key stakeholders and workstream close-out milestones are held on-site when they add value. Based in Almería, with availability to travel across Spain.

Let’s talk: hiring a DORA banking consultant for your institution

If your organisation is adapting to DORA or needs to review the current state of the programme, the first step is a 30-minute call, no obligation. Tell me where you stand and what’s blocking progress.

Prefer to get straight to the point? Email me at jose@joseenrique.es or via WhatsApp.

Recommended reading DORA: a complete guide for Project Managers in banking and insurance
Jose Enrique Ibarra, AI Project Manager - avatar

About the consultant

Jose Enrique Ibarra is an AI Project Manager and regulatory-compliance consultant with more than 30 years of experience leading technology, cybersecurity and operational-resilience programmes in regulated entities. Specialising in DORA, NIS2 and ICT risk governance, he helps banks, EMIs and mid-sized financial institutions translate the regulation into an executable plan with milestones, evidence and owners.

Tell me about your situation. I’ll reply within 24 working hours.

If your entity is adapting to DORA or needs to review the state of the programme, fill in the form with your current situation. The initial conversation is 30 minutes, no obligation, and focused on clarifying next steps.

I have read and accept the Privacy Policy. I consent to the processing of my data to respond to this enquiry and to maintain related professional communications.*
Data controller: José Enrique Ibarra | Purpose: to handle your enquiry about the DORA Programme | Legal basis: your consent | Recipients: not shared with third parties | Rights: access, rectification and erasure at jose@joseenrique.es. More info in the Privacy Policy.

Prefer to get straight to the point? Email me at jose@joseenrique.es or via WhatsApp.