DORA banking consultant: programme management for financial institutions
As a DORA banking consultant, I lead the full compliance programme for Regulation (EU) 2022/2554: from the initial gap analysis all the way to reporting to the supervisor. And if your organisation still has gaps across the five pillars, the window to close them narrows every month.
Why mid-sized institutions need a DORA banking consultant in 2026
“Adapting five regulatory pillars in parallel requires cross-functional coordination that rarely exists organically within an organisation.”
The most common mistake is delegating DORA to the cybersecurity team or the compliance function, without a DORA banking consultant to coordinate IT, legal, procurement and the business as a programme director. The result is disconnected workstreams, inconsistent documentation and gaps the regulator will spot on the first review.
On top of that, fines can reach 2% of global annual turnover for legal entities and up to one million euros for the individuals responsible. The reputational cost, however, always outweighs the financial one.
What hiring a DORA banking consultant includes
What hiring me as a DORA banking consultant: five parallel workstreams aligned with the five pillars of the Regulation, with a single point of contact for the board and the supervisor.
Initial gap analysis
First, an honest assessment against the five pillars. A real diagnosis of which processes exist, which are partial and which are missing. Without it, any action plan is building on sand.
A programme of parallel workstreams
Next, the design and launch of the five workstreams aligned with the pillars. Each with milestones, owners and a delivery schedule approved by the board.
Cross-functional stakeholder management
DORA, however, is not an IT project. I orchestrate the involvement of legal, procurement, the business and senior management without friction, with the right level of dialogue for each.
Third-party ICT management
On the supplier side: identifying, assessing and monitoring ICT providers. Renegotiating contracts to include the required clauses: audit rights, incident notification, exit plans and measurable indicators.
Regulatory reporting
Finally, documentation and reports for the board and the supervisor (Banco de España, CNMV, DGSFP). Managing communications during major incidents within the deadlines DORA requires.
DORA is not a compliance problem. It’s a programme of projects.
A compliance consultant delivers a gap report. A DORA banking consultant with a Project Manager profile runs the programme that closes them, on time and with reporting to the board.
Direct experience in banking
For example, more than six years as Project Director in banking, leading infrastructure and security initiatives in regulated financial environments. I’m not here to learn the sector: I’ve spent decades in it. Get to know the profile of the AI Project Manager running the programme.
Solid technical grounding in cybersecurity
Microsoft MCSA and MCSE Security certifications, too. Managing critical infrastructure since 1995. I understand DORA’s five pillars from the inside, not just from the regulatory framework.
European regulatory perspective
Also, specialisation in the EU AI Act, DORA and NIS2. The ability to engage with the regulator and translate regulatory requirements into concrete project-management actions.
The AI Forge lab
Hence, the practical application of AI to automating regulatory reporting, continuous monitoring of ICT providers and incident management. What works in production, not in theory.
Results that back the DORA banking consultant profile
In short, more than two decades working as a project manager in banking and IT consulting. These are two voices from technology partners I’ve collaborated with on programmes combining management, critical infrastructure and compliance.
“Jose Enrique combines the dual quality of being an excellent professional and an excellent person. Technically impeccable, with long, contextual vision thanks to his many years of experience. Outstanding.”Vicente Pérez · Account Manager, IBM
“José Enrique is a highly goal-oriented, business-focused person with a great ability to build inter-company relationships. It’s a pleasure doing business with him.”Javier Álvarez · Program Rise Director, Lenovo
What people ask me most at the start of a programme
Which entities does DORA apply to exactly?
DORA applies to more than twenty types of entities in the European financial sector: banks, payment institutions, electronic money institutions, investment firms, fund managers, insurers, reinsurers, crypto-asset providers and pension fund managers, among others. It also reaches market infrastructures and the critical ICT providers that serve those entities.
My company isn’t financial, but it provides IT services to a bank. Does DORA affect me?
Yes, indirectly. Financial institutions are required to pass DORA’s requirements down to their ICT providers contractually: audit rights, incident notification, exit plans and measurable indicators. If your company provides cloud, cybersecurity, infrastructure or software development services to an entity under DORA, you’ll receive those obligations by contract.
On implementation and risks
How long does it take to implement a serious DORA programme?
DORA isn’t achieved in six months. Mature institutions structure a multi-year plan: year 1 for governance and risk management, year 2 for testing and third-party management, years 2-3 for advanced maturity. What you can accelerate is closing the most visible gaps for the supervisor within the first 90-120 days of the programme.
What are the real fines for breaching DORA?
Fines can reach 2% of global annual turnover for legal entities and up to one million euros for the individuals responsible. But in practice, the reputational cost of a serious incident without the controls DORA requires usually outweighs the financial one, especially for mid-sized institutions that depend on local client trust.
We already have a compliance consultant. Why do we need a programme director?
A compliance consultant delivers a gap report. A programme director coordinates IT, legal, procurement and the business to close those gaps on time, on budget and with reporting to the board. They’re two distinct, complementary roles; the problem appears when you hire only the first and expect the second to emerge organically.
On how working with me actually works
Do you work as a DORA banking consultant remotely or on-site?
A hybrid model. Most of the coordination, documentation and reporting work is done remotely. Critical sessions with the board, workshops with key stakeholders and workstream close-out milestones are held on-site when they add value. Based in Almería, with availability to travel across Spain.
Let’s talk: hiring a DORA banking consultant for your institution
If your organisation is adapting to DORA or needs to review the current state of the programme, the first step is a 30-minute call, no obligation. Tell me where you stand and what’s blocking progress.
Prefer to get straight to the point? Email me at jose@joseenrique.es or via WhatsApp.

About the consultant
Jose Enrique Ibarra is an AI Project Manager and regulatory-compliance consultant with more than 30 years of experience leading technology, cybersecurity and operational-resilience programmes in regulated entities. Specialising in DORA, NIS2 and ICT risk governance, he helps banks, EMIs and mid-sized financial institutions translate the regulation into an executable plan with milestones, evidence and owners.
Tell me about your situation. I’ll reply within 24 working hours.
If your entity is adapting to DORA or needs to review the state of the programme, fill in the form with your current situation. The initial conversation is 30 minutes, no obligation, and focused on clarifying next steps.
Prefer to get straight to the point? Email me at jose@joseenrique.es or via WhatsApp.