Navigating Data Management for BCBS 239, DORA, ESG Compliance & Reporting

Datatrust Associates

17 Dec 25

5min read

Blog & Whitepapers

DORA has been fully applicable across the EU since January 17, 2025. 2026 is the year supervisors shift from readiness checks to active enforcement. For CDOs and CIOs in financial services, that shift is not abstract. The first formal fines are expected in the second half of 2026, targeting entities with no demonstrable compliance effort.

And DORA is only part of the picture.

Financial institutions are simultaneously managing BCBS239; the Basel Committee's principles for effective risk data aggregation; alongside tightening ESG reporting obligations. Three frameworks, different deadlines, different regulators, and one underlying problem: data. Specifically, data that is incomplete, inconsistent, or sitting in systems that were never designed to feed regulatory reporting.

That combination is where most organisations get stuck. According to Deloitte research, only 50% of institutions expected to reach full compliance with DORA by end of 2025. A further 38% pushed their target into 2026. The reasons are familiar to any CDO who has tried to build a data quality framework under time pressure: low data maturity meets high regulatory ambition, and the gap is wider than anyone admitted at the project kickoff.

The instinct is to treat each framework separately: a DORA workstream here, a BCBS239 gap analysis there, an ESG data collection project somewhere else. That approach is expensive and slow. It also misses the point. The underlying requirement across all three is the same: you need to know where your data is, trust its quality, and demonstrate that to a regulator on demand.

Organisations that solve this at the data layer: building a governance framework, data quality controls, and reporting infrastructure that serves multiple regulatory needs: move faster and spend less. In our experience, the firms that handle DORA well treat it as an operating model change, not a one-time compliance project. The same logic applies to BCBS239 and ESG. Compliance is the output. Sound data management is the input.

The results bear that out. Institutions that take this approach have come out of ECB and NBB supervisory reviews with a lighter regulatory regime: a direct consequence of demonstrating a functioning data quality framework, not just a project plan.

The Register of Information is not just a reporting exercise. It is a supervisory intelligence tool. For the first time, regulators have machine-readable data covering the entire ICT supply chain of every in-scope financial institution across the EU. Regulators now have more visibility into your organisation than most of your own leadership teams do.

So the question worth sitting with: if your lead supervisor asked for a real-time view of your data quality, your ICT resilience, and your ESG reporting accuracy today, which of those three would you be most confident answering?