A Belgian financial services organisation is reviewing its proposed response to the National Bank of Belgium (NBB) on the Digital Operational Resilience Act (DORA), covering two regulated entities. As a Senior DORA Regulatory Compliance Consultant, you will provide an independent DORA compliance assessment, applying risk management and the proportionality principle to selected ICT governance and operational resilience domains.
The mission
The assignment focuses on whether the organisation’s compliance positions are reasonable, defensible and aligned with DORA, related RTS/ITS guidance, and supervisory expectations. You will examine how proportionality is applied across selected domains, including ICT risk management, third-party risk management (TPRM), information security and operational resilience. The review supports a formal regulatory response in the Belgian financial sector, where clarity of interpretation and evidence of governance are important. The work is advisory and independent, with findings intended for decision-makers preparing the final response.
Your day-to-day scope combines document review, regulatory analysis, structured challenge and stakeholder discussions with the teams responsible for compliance, ICT governance and risk. You will test key assertions and assumptions, identify gaps or inconsistencies, and assess whether proposed positions can withstand supervisory scrutiny. The core deliverables are a proportionality assessment across selected DORA domains, a high-level review of the NBB response, and a concise advisory memorandum with observations and recommendations. You may also present the conclusions to executive management.
Your responsibilities
- Assess selected DORA domains against regulatory requirements, RTS/ITS guidance and supervisory expectations, documenting the basis for each conclusion.
- Challenge proposed compliance positions, interpretations and assumptions to determine whether they are reasonable and defensible from a supervisory perspective.
- Evaluate the application of the proportionality principle across ICT governance, ICT risk management and related control areas.
- Identify regulatory gaps, weaknesses and inconsistencies through structured gap analysis and second-line review techniques.
- Recommend improvements to governance, third-party risk management, compliance documentation and the overall regulatory response.
- Prepare the advisory memorandum and, where required, present key findings and recommendations to executive management.
Your profile
Essential skills
- Demonstrate senior-level experience in DORA regulatory compliance and risk management within the financial services regulatory environment.
- Apply ICT risk management frameworks and ICT governance principles to regulatory compliance assessments.
- Conduct regulatory assessments, gap analysis, compliance reviews or second-line reviews with clear supporting evidence.
- Interpret the proportionality principle within European financial regulations and assess its practical application.
- Evaluate third-party risk management, operational resilience and information security frameworks.
- Bring experience interacting with financial regulators or supporting regulatory inspections and supervisory reviews.
- Communicate independent challenge clearly to compliance, risk, ICT and executive stakeholders, both in writing and in discussion.
Languages
- English at a professional working level, sufficient for regulatory analysis, advisory reporting and executive presentations.