The EU’s DORA regulation has exposed how firms operating in private markets face a set of risks that is not purely about IT.
Designed to reduce financial sector reliance on a small number of infrastructure vendors, the regulation came into force last year. Since implementation it continues to throw a spotlight on risks arising from continued use of manual methods and over-reliance on individual employees’ subject matter expertise.
The regulation is forcing firms to examine how their operating models work under pressure and where risk resides inside workflows.
A private equity or private credit manager may sit on robust cloud infrastructure at one end of its technology stack, while still relying on spreadsheets, manual handoffs and offline approvals at the other. In that kind of environment, resilience is only as strong as the least controlled part of the workflow.
The real risk often sits inside the workflow
This is where risk accumulates in an organisation – in processes that are not properly systemised. This is amplified when they rely on manual intervention or a small number of people who know how to make them work.
A month-end close supported by spreadsheets and a sequence of offline steps may function well enough in normal conditions. However, it looks far less resilient when deadlines tighten, a key individual is unavailable or an investor query lands at exactly the wrong moment.
DORA, in effect, acts as a pressure test on whether resilience has been built into the operating model or simply assumed. Private markets firms have lived with this kind of exposure for years, often because experienced teams compensate for process weaknesses. Regulation leaves no room for that comfort. The question now is whether the workflow holds up under strain.
With DORA, accountability has moved to the top
One of the clearest shifts under DORA is the level at which accountability now sits. Historically, operational resilience could be treated as a technology matter and delegated accordingly. If a firm had a CTO, responsibility was often there. If it did not, it shifted into finance or operations. DORA has since changed that dynamic. Responsibility now sits with the management body, which is held accountable for the ICT risk management framework. It means resilience is now a governance issue with clear ownership at the top of the business.
That changes the conversation both inside firms and with suppliers. Firms increasingly want hard evidence from their providers. They want to understand incident processes, failover arrangements, access controls and recovery expectations in practical terms. They also want to know when documentation was last reviewed, whether controls have been tested – and what would happen if a system failed.
The weakest point is often internal
For many private markets firms, however, the central issue is not whether a major external provider is resilient in principle. It is whether the firm’s own workflows can withstand increased pressure.
Key-person risk is at the heart of this issue. Many firms have built effective processes around capable individuals who know every workaround and hidden dependency. That may keep the machine running, but it is not the same as resilience. If knowledge is not captured and supported by the underlying platform, the process is weaker than it appears, severely increasing dangers when individuals leave or are unavailable.
The same applies once essential work starts moving outside the core platform into spreadsheets, email chains or offline approvals. Control weakens, visibility drops, auditability becomes harder and recovery becomes more uncertain. In private markets, where reporting expectations are high and investor scrutiny remains intense, that is not a side issue. It goes to the heart of whether the operating model is fit for purpose.
That matters particularly in fund accounting, where complexity has only increased. Reporting expectations are higher, structures are more demanding, and firms need stronger control across workflows. A system built for a different era often pushes work outside the main platform at exactly the point where clarity and control matter most. Once reporting becomes a scramble and key numbers are being pieced together manually, the workflow has already become more fragile than it should be.
DORA is the prompt, not the end goal
Operational resilience has often been treated too narrowly as a compliance cost. In practice, stronger resilience usually brings clearer process ownership, better visibility across workflows and faster responses when investors, auditors or regulators ask harder questions. It also reduces key-person risk and makes growth easier to support because the process does not have to be rebuilt every time complexity increases.
DORA will not solve every vulnerability in private markets operations, nor was it meant to. What it does is raise the bar for accountability, testing and supplier oversight. It shines a harsher light on brittle processes that have survived largely through habit and human intervention. It also makes clear that operational resilience depends not just on policies and providers, but on whether the underlying systems and platforms are strong enough to support controlled, auditable workflows under pressure.
That is the real wake-up call. Resilience has to run through the whole operating model, from the infrastructure underneath it to the controls and workflows used every day. That’s the real underlying lesson of DORA that private markets firms need to heed.
Learn more at lemonedge.com
- Cybersecurity
- Cybersecurity in FinTech
- Digital Strategy
- InsurTech























