<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Financial Services on Sovereign Shift</title>
    <link>https://sovereignshift.eu/tags/financial-services/</link>
    <description>Recent content in Financial Services on Sovereign Shift</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Wed, 25 Mar 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://sovereignshift.eu/tags/financial-services/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>DORA Concentration Risk: How to Build an Exit Strategy Your Regulator Will Accept</title>
      <link>https://sovereignshift.eu/blog/dora-concentration-risk-exit-strategy/</link>
      <pubDate>Wed, 25 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://sovereignshift.eu/blog/dora-concentration-risk-exit-strategy/</guid>
      <description>&lt;p&gt;The Digital Operational Resilience Act (Regulation 2022/2554), which applies from 17 January 2025, introduces a concept that no previous EU regulation stated so explicitly: financial entities must identify, assess, and manage the risk of depending too heavily on a single ICT provider. And they must have documented exit plans for their critical providers.&lt;/p&gt;&#xA;&lt;p&gt;This is not optional. DORA applies to credit institutions, investment firms, insurance undertakings, payment institutions, crypto-asset service providers, and virtually every other regulated financial entity in the EU. The European Supervisory Authorities (EBA, ESMA, EIOPA) are developing Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) to specify the details.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
