EU Clearing Houses Face Cloud Vendor Diversification Mandate Under DORA
European clearing houses are being compelled to diversify their cloud providers to ensure compliance with the Digital Operational Resilience Act (DORA), a new regulatory framework designed to strengthen the digital operational resilience of the financial sector. The move is driven by clarifications from the German Federal Financial Supervisory Authority (BaFin) regarding DORA’s requirements.
DORA and the Single Cloud Risk
According to Dmitrij Senko, chief risk officer at Eurex Clearing IMD, BaFin has clarified that relying on a single cloud provider is insufficient to meet DORA standards. “In Europe, or at least in Germany, from BaFin there were clarifications around Dora that a single cloud is not sufficient, so there should be fallbacks – either two clouds or on-premises,” Senko stated as reported by Risk.net on February 27, 2026.
BaFin’s Implementation of DORA
DORA has been applicable to companies in the financial sector since January 17, 2025. BaFin has been actively guiding institutions through the implementation process, emphasizing the importance of robust ICT risk management. In February 2025, BaFin published key guidance on the DORA Information Register, requiring financial institutions to submit ICT agreements by April 11, 2025. Zeidler Group highlights this guidance.
Implications for Clearing Houses
This requirement for diversification necessitates that clearing houses establish fallback arrangements, either through the use of multiple cloud providers or by maintaining on-premises infrastructure. This aims to mitigate the risk of operational disruptions stemming from a single point of failure within a cloud environment.
Dmitrij Senko’s Expertise
Dmitrij Senko brings extensive experience in risk management within the financial sector. His LinkedIn profile details his expertise as a C-Level executive, chief risk officer and board member, with a focus on financial risks, operational risks, and information security.
The push for cloud diversification underscores the growing emphasis on operational resilience within the European financial landscape, driven by the implementation of DORA and the proactive oversight of regulators like BaFin.