Dutch supervisors are reviewing trading-venue control files to see whether ICT controls work during failures. The review covers monitoring, access, logs, emergency changes, continuity plans and supplier records. The licensed firm must show who made each decision and what happened.
Why this matters
DORA has applied since 17 January 2025. The licensed venue remains responsible when a group company or supplier runs its systems. Its supplier register must identify the critical function, service, access and recovery route. Across the wider AFM-supervised population, EBA-approved registers rose from 40% in 2025 to 94% in 2026. Approval means little if the register misses the live supplier chain. An outage brings customer calls, recovery work and supplier disputes.
Example
At 02:17, monitoring flags unusual activity in a trading access system. An outside supplier hosts it. A group team monitors it. An engineer requests an emergency change before opening. The operations manager needs named authority, usable logs and portal access. If classified as major, the first notice is due within four hours and no later than 24 hours after detection. An intermediate report follows within 72 hours. A final report follows within one month of that report.
XTROVERSO tips
- Map the critical chain. List each critical system, business function, supplier and subcontractor. Link the list to current contracts, access rights and recovery plans.
- Separate policy from procedure. Use policy to assign responsibility and approval. Use procedures to show who receives an alert, authorizes a change, classifies the incident and records the decision.
- Test the reporting route overnight. Run a short exercise outside office hours. Check management escalation, portal access, reporting authority, contact details and evidence retention.
- Review logs and emergency changes. Sample recent records. Confirm who approved each change, what changed, whether rollback was possible and whether a later review occurred.
- Check group services locally. Compare group documents with the licensed entity's systems and duties. Record any missing local owner, reporting route or trading connection.
- Keep the supplier register current. Replace broad service labels with clear descriptions. State what the supplier operates, which function depends on it and where subcontractors enter the chain.
Ask XTROVERSO to test whether your DORA controls, records and reporting route work under pressure
The data, sourcing, and analysis behind this article were conducted by Paolo Maria Pavan. AI was not used to identify sources, build the factual basis, or produce the analytical judgment contained here. AI was used only as a drafting aid. The final English text was personally reviewed, edited, and approved by Paolo Maria Pavan before publication.
References
- Autoriteit Financiële Markten — Handelssystemen vragen om scherpere ICT-risicobeheersing onder DORA
- Autoriteit Financiële Markten — DORA implementation update
- De Nederlandsche Bank — DORA supplier registers and subcontracting
- De Nederlandsche Bank — Reporting serious ICT-related incidents
- Autoriteit Financiële Markten — DORA notifications and reporting authority
- Autoriteit Financiële Markten — Digital operational resilience testing


