Skip to content
Digital, Innovation, Payments

DORA: how mutualised audits can strengthen resilience while reducing costs

Published on 22 June 2026

Several Luxembourg financial institutions have joined forces to conduct a mutualised ICT audit under DORA. Discover how collaboration can strengthen resilience, improve oversight and reduce costs.

Summary

    Luxembourg banks join forces to audit a critical ICT provider

    As financial institutions continue to implement the Digital Operational Resilience Act (DORA), one challenge is becoming increasingly apparent: how to meet growing oversight requirements on critical ICT providers without multiplying audits, costs and operational burden.

    A mutualised audit initiative coordinated by the ABBL offers a practical answer, allowing several institutions to assess a shared service provider through a single, coordinated exercise.

    The challenge: stronger oversight without duplication

    DORA has raised the bar for the management of ICT and third-party risks across the financial sector. Banks are expected to demonstrate robust oversight of the technology providers on which they rely for critical services.

    While these requirements are designed to strengthen operational resilience, they can also lead to significant duplication. When several institutions depend on the same provider, multiple audits covering largely identical topics may be carried out independently, creating inefficiencies for both financial institutions and service providers.

    Finding ways to achieve high levels of assurance while avoiding unnecessary duplication is therefore becoming an important operational and regulatory challenge.

    A collective response to a common issue

    To address this challenge, several Luxembourg financial institutions came together to conduct a mutualised external ICT audit of key LuxTrust services used across the sector.

    The initiative was coordinated with the support of the ABBL and relied on the active involvement of a lead bank representing the participating institutions. This role proved essential in structuring the request-for-proposal process, consolidating expectations and ensuring that the audit reflected both operational realities and regulatory requirements.

    The audit itself was entrusted to Wavestone, whose expertise in cybersecurity, operational resilience and financial-sector regulation provided an independent assessment of the services under review.

    Alongside the participating institutions, LuxTrust played a central role by engaging in a single audit process covering areas of common interest to multiple clients.

    This initiative demonstrates that regulatory requirements can be transformed into collaborative opportunities. A shared audit framework reduces the burden on audited entities by limiting duplicate assessments, while enabling participating institutions to achieve deeper audit coverage, stronger assurance, and greater cost efficiency.

    Ananda Kautz

    Member of the Management Board of the ABBL

    One audit, multiple benefits

    The initiative demonstrates how collaboration can transform a regulatory obligation into an opportunity for greater efficiency.

    For participating institutions, the approach provides access to a common, high-quality audit framework while reducing duplicated effort. It also promotes a more consistent assessment of risks and controls across the sector.

    The value of a mutualised audit lies in its ability to combine efficiency with quality. By working together, institutions can strengthen oversight of a shared provider while reducing the operational burden associated with individual audits.

    Ludovic Raymond

    Head of ICT and Security Risk Management, Banque Raiffeisen

    For service providers, a mutualised audit offers a more structured way to respond to clients’ resilience and security expectations without being confronted with multiple separate reviews covering similar topics.

    This approach creates a constructive framework for dialogue around resilience, security and transparency. It allows us to address common expectations in a coordinated and efficient manner.

    Fabrice Aresu

    CEO of LuxTrust

    The involvement of an independent auditor also contributes to the credibility and consistency of the exercise, ensuring that participating institutions can rely on a robust and recognised assessment framework.

    Mutualised audits are an effective way to reconcile regulatory assurance with operational efficiency. By providing a common assessment framework, they help institutions address shared risks while promoting greater consistency across the financial sector.

    Jérôme de Lisle

    Head of Cybersecurity Luxembourg at Wavestone

    More broadly, the exercise contributes to stronger third-party risk governance and helps create a common understanding of resilience expectations among market participants.

    A blueprint for future DORA initiatives

    Beyond the audit itself, the project offers a model that could eventually be replicated for other critical ICT providers.

    As DORA implementation progresses, mutualised approaches may become an increasingly valuable tool for balancing regulatory compliance, operational efficiency and sector-wide resilience. By pooling resources and coordinating efforts, financial institutions can obtain stronger assurance while reducing administrative burden.

    DORA implementation is not only about individual compliance. It is about building a more resilient ecosystem. When institutions face common challenges, coordinated action can deliver better outcomes for the entire market.

    Andrey Martovoy

    Senior Adviser - Innovation & Digital, ABBL

    The initiative also illustrates a broader lesson of DORA: resilience is not only built institution by institution. In areas where firms face common risks and depend on shared infrastructures, collective action can help strengthen the resilience of the financial ecosystem as a whole.

    By bringing together financial institutions, service providers and independent experts around a common objective, the initiative demonstrates how cooperation can transform regulatory requirements into an opportunity to enhance resilience, efficiency and trust across the Luxembourg financial sector.

    Andrey Martovoy

    Andrey Martovoy

    Senior Adviser - Innovation & Digital, ABBL

    Published on 22 June 2026