DORA and identity lifecycle: what Articles 20 and 21 of the technical standard ask for
ILM Reference editors · Published 2026-03-24 · 3 minute read
TRACK: CONTROLS AND STANDARDS · LESSON 6 OF 11
DORA, Regulation (EU) 2022/2554, applies to EU financial entities from 17 January 2025. Its technical standard on ICT risk management, Delegated Regulation (EU) 2024/1774, requires a lifecycle management process for identities and accounts (Article 20) and access control that includes withdrawing access rights when employment ends and reviewing access rights at least once a year for staff with access to ICT assets that support critical or important functions (Article 21). This lesson paraphrases those requirements; read the official text for the exact wording.
Where do these requirements come from?
The Digital Operational Resilience Act sets ICT risk management rules for EU financial entities and applies from 17 January 2025. The detailed requirements sit in regulatory technical standards. Commission Delegated Regulation (EU) 2024/1774, adopted on 13 March 2024, is the one that covers the ICT risk management framework, including identity management and access control.
What does Article 20 ask for?
Article 20 covers identity management. In summary, it asks financial entities to operate a lifecycle management process for identities and accounts. The process covers the creation of accounts, changes to them, their review and update, temporary deactivation, and termination. In lifecycle terms, that is the joiner, mover, review and leaver stages this reference describes, written as a regulatory requirement rather than a best practice.
The requirement is about all accounts, not only the ones a connector reaches. An account in a disconnected application still needs to be created, changed, reviewed and terminated through a defined process.
What does Article 21 ask for?
Article 21 covers access control. Two parts matter most for lifecycle work. First, access rights are withdrawn when employment or the contract ends, which is the leaver stage. Second, access rights are reviewed at least once a year for staff with access to ICT assets that support critical or important functions, which is a floor for the review stage, not a target. Many organizations review higher-risk systems more often.
What evidence should you keep?
| Requirement | Stage | Evidence to keep |
|---|---|---|
| Lifecycle process for identities and accounts (Art. 20) | All stages | A written process covering creation, change, review, deactivation and termination, including the manual path for disconnected applications |
| Withdrawal of access on termination (Art. 21) | Leaver | For each leaver, the termination date and the date each account was disabled, per application |
| Review at least once a year for staff with access to ICT assets supporting critical or important functions (Art. 21) | Review | Campaign scope as a list of applications, reviewer decisions, and proof that revocations were carried out |
The identity audit evidence guide sets these next to SOX and NIST SP 800-53 requirements. The leaver timing lesson shows how to measure the withdrawal step.
Where do programs usually fall short?
- The review covers only connected applications, so ICT assets that support critical functions but sit outside the IGA are never reviewed.
- Leaver evidence exists for the directory account but not for local accounts in the applications themselves.
- Temporary deactivation (for long leave, for example) is handled informally and never recorded.
Sources
Reviewed Sep 2026
Delegated Regulation (EU) 2024/1774 is paraphrased here, not quoted. Check the official EUR-Lex text before relying on specific wording.
Next lesson: Separation of duties
Defining conflicting access, and checking it at the three moments it can appear.