AI & Analytics Legends The knowledge platform for SAP Analytics
Concept card

DORA Operational Resilience for SAP AI

DORA Operational Resilience for SAP AI — Analytics Legends section illustration for the SAP Analytics knowledge base (concepts, studies, Academy)

As of 2026-09-27

What is DORA Operational Resilience for SAP AI?

DORA (Regulation (EU) 2022/2554, applicable since 17 Jan 2025) treats SAP AI in a bank or insurer as ICT: every agent and model belongs in the ICT risk framework and the register of information, a major incident starts a 4h/72h/1-month reporting clock, and since 18 Nov 2025 SAP SE is a designated critical ICT third-party provider under direct EU oversight.

The Digital Operational Resilience Act — Regulation (EU) 2022/2554, applicable since 17 January 2025 — is the EU's single rulebook for ICT risk in the financial sector: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers and further entity types listed in Article 2. It does not mention "AI" as a separate category, and that is precisely why it matters for SAP AI: a Joule agent, a SAP-RPT prediction service on SAP AI Core, a Datasphere or BDC pipeline feeding regulatory reporting, or a Document AI extraction flow are all ICT services and ICT assets. They fall under the same obligations as the core-banking system.

The five pillars, applied to SAP AI

ICT risk management (Chapter II, Articles 5–16). The management body owns an ICT risk-management framework: identification of ICT assets and dependencies, protection, detection, response and recovery, backup and business continuity. For SAP AI this means the BTP subaccounts running AI Core deployments, the generative AI hub model endpoints in use, grounding data sources, Joule agents and their tools all need to be identified, classified by the business functions they support, and covered by continuity arrangements — including what the business does when a model endpoint is unavailable.

Why it matters

  • DORA has applied since 17 Jan 2025 and does not carve out AI: Joule agents, AI Core deployments and AI-fed reporting pipelines are ICT assets and ICT services under the same rules as core systems.
  • A major incident starts a fixed clock (Delegated Regulation (EU) 2025/301): initial notification within 4 hours of classification and ≤24 h of awareness, intermediate report within 72 h, final report within one month.
  • SAP SE was designated a critical ICT third-party provider on 18 Nov 2025 — direct EU oversight of SAP, but the bank or insurer keeps full responsibility for its register, contracts and exit strategy.

Key points

  • Regulation (EU) 2022/2554, applicable since 17 Jan 2025, to financial entities listed in Art. 2 — sector-scoped, unlike the use-case-scoped AI Act.
  • Five pillars: ICT risk management (Art. 5–16) · incidents (Art. 17–23) · resilience testing (Art. 24–27) · ICT third-party risk (Art. 28–44) · information sharing (Art. 45).
  • Incident classification criteria: Delegated Regulation (EU) 2024/1772; reporting deadlines: Delegated Regulation (EU) 2025/301 (4 h / 24 h, 72 h, 1 month).
  • Art. 28(3) register of information, Art. 28(8) exit strategies, Art. 30 key contractual provisions — they apply to SAP BTP, AI Core, Joule and model sub-contractors.
  • 18 Nov 2025: ESAs designated 19 CTPPs incl. SAP SE; oversight via a Lead Overseer does not transfer the entity's own responsibility.
  • Design AI components to be detectable, classifiable and replaceable: output monitoring, runbooks mapping agents to business functions, tested alternative model endpoints.

Terms used on this page

DORA (Digital Operational Resilience Act)
Regulation (EU) 2022/2554 on ICT risk in the financial sector, applicable since 17 January 2025.
Register of information
Art. 28(3) register of all contractual arrangements on the use of ICT services, kept at entity, sub-consolidated and consolidated level; also used by the ESAs to assess provider criticality.
CTPP
Critical ICT third-party service provider designated by the ESAs (first list 18 Nov 2025, incl. SAP SE) and subject to the Union oversight framework.
Lead Overseer
The ESA (EBA, EIOPA or ESMA) appointed to conduct oversight of a given CTPP, with powers to request information, examine and issue recommendations.
Major ICT-related incident
Incident meeting the classification thresholds of Delegated Regulation (EU) 2024/1772; triggers reporting under Delegated Regulation (EU) 2025/301.
Exit strategy
Art. 28(8) plan to leave or replace an ICT service supporting critical or important functions without disrupting them.

Sources

  1. EUR-Lex — Regulation (EU) 2022/2554 (DORA), full text
  2. EUR-Lex — Commission Delegated Regulation (EU) 2025/301 (content and time limits of incident reports)
  3. EUR-Lex — Commission Delegated Regulation (EU) 2024/1772 (classification of ICT-related incidents)
  4. EIOPA — ESAs designate critical ICT third-party providers under DORA (18 Nov 2025)
  5. SAP — SAP designated as a Critical ICT Third-Party Service Provider under DORA (Dec 2025)
  6. ESMA — Digital Operational Resilience Act (DORA)
  7. DORA Article 28 — register of information and exit strategies (reading aid)
  8. EUR-Lex — Regulation (EU) 2026/1744 (Digital Omnibus on AI; AI Act high-risk dates)
  9. SAP News Center — AI agents work at scale: AI Governance Assistant, EU AI Act + NIST classification (22 Sep 2026)
  10. Databricks Docs — AI Search (the renamed Vector Search)
  11. Microsoft Learn — OneLake overview (Microsoft Fabric), including redundancy and disaster recovery
  12. Snowflake Docs — Cortex Analyst semantic model

Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.

Open in the app →