Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No cookies to display.

Woccu secures proportional treatment for credit unions in EU’s digital regulation

‘The agreement provides for robust ICT risk management, testing and reporting requirements while at the same time future-proofing the legislation’

Credit unions in Europe will receive proportional treatment when it comes to the requirements of a new EU digital resilience regulation, according to a provisional agreement reached by The European Council presidency and European Parliament last week.

The agreement marks a win for the World Council of Credit Unions (Woccu) and its partner, the European Network of Credit Unions (ENCU), which had called for a proportional approach to be included in the regulation that would allow policymakers to consider the size, nature, scale and complexity of credit union services, activities and operations.

The Digital Operational Resilience Act (DORA) sets out a number of regulatory requirements for financial institutions around security risks for information and communications technology (ICT). These incude implementing governance frameworks to manage risks, carrying out digital resilience testing, managing ICT third-party risk and reporting major ICT-related incidents.

MEP Billy Kelleher, lead MEP responsible for the regulation, described DORA as “a key step in building up the EU’s cyber-resilience at the point where financial services and ICT interact”, adding: “The agreement provides for robust ICT risk management, testing and reporting requirements while at the same time future-proofing the legislation, adhering to the principle of proportionality and protecting competition.”

A key way in which the agreement takes proportionality into account is by allowing member states to establish rules for institutions that are exempt under the EU Capital Requirements Directive. 

Woccu’s senior vice president of advocacy and general counsel, Andrew Price, has previously stressed the need for international bodies to allow for the tailoring of regulations when it comes to community-based financial institutions such as credit unions. 

Mr Price said: “We thank the European Parliament for listening to our needs and tailoring rules that are appropriate for credit unions, while also accomplishing our mutual goal of protecting our members’ information from ICT breaches and ensuring the safe and sound operations of financial institutions.” 

The provisional agreement on DORA must now be approved by the European Parliament before it is formally adopted, and then passed into law by each EU member state. Woccu and ENCU have said they will continue to be engaged throughout the formal adoption process.