On 17 January 2025, the Digital Operational Resilience Act (DORA) became applicable across the European Union. After a two-year transition, more than 22,000 financial entities and their critical ICT providers are now inside a single resilience rulebook: incident reporting, resilience testing, and, crucially, third-party risk management.
Your identity vendor is now your risk
DORA's register of information requires financial entities to map every ICT service supporting critical functions. Customer onboarding is a critical function, which puts identity verification providers squarely on the register. Compliance teams spent January asking vendors questions many had never been asked before: where does verification actually run, what happens when your service degrades, and can you evidence your own resilience testing?
Fragmentation is a resilience problem
An onboarding chain stitched from four vendors (document capture from one, liveness from another, screening from a third, signing from a fourth) multiplies the register entries, the exit plans and the concentration analysis. Every seam is a dependency to document and a failure mode to test. Consolidating identity, screening and signing into one audited platform does not just reduce cost; under DORA it measurably reduces reportable surface.
Evidence beats assertion
The regulation rewards providers that can produce evidence rather than assurances. WeVerify's architecture was built evidence-first: every verification, screening and signature event produces a sealed, tamper-evident package, and the platform's EU footprint keeps data-residency answers short. If your DORA register still lists four identity-adjacent vendors, 2025 is the year to shorten it.
Identity Verification · Compliance centre · Talk to us about DORA-ready onboarding
