AuditBoard Survey Finds DORA Compliance Lagging

thumbnail AuditBoard Survey Finds DORA Compliance Lagging

The latest survey report details how far behind many companies are in terms of several key regulatory frameworks, including the EU AI Act. AuditBoard’s CISO explains why this is important for American companies.

Written By: Victoria Durgin
Feb 13, 2025
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Audit, compliance, and risk management platform vendor AuditBoard recently announced its findings after surveying over 270 professionals about their compliance with DORA, the EU AI Act, and other compliance frameworks. Overall, the research shows that compliance lags behind expected targets. Channel Insider spoke with AuditBoard CISO Richard Marcus to learn more about the research for partners supporting EU businesses and American entities operating in the region.

Compliance lags across the board

The survey findings do not cover the newly in effect DORA regulation exclusively, but the report does show compliance with DORA is much lower than some might think. Further, compliance with frameworks that have been in effect for much longer, such as the EU AI Act and NIS2, remains low.

The survey results report the following levels of compliance with leading regulatory frameworks:

  • NIS2 compliance: 52% of organizations report being compliant, with another 44% expecting to be compliant by the end of 2025
  • DORA adherence: 40% of those surveyed report they have completed the necessary steps to comply with DORA
  • EU AI Act compliance: Respondents reported the lowest rate of compliance out of the three, with only 34% saying they were following the requirements of the act

In addition to the self-reported compliance lagging behind projections, the AuditBoard report highlighted a gap in compliance success. According to the survey data, companies claim compliance while continuing to miss key implementation policies, leaving them subject to non-adherence penalties even if they think they have fulfilled requirements.

The data around these missing elements include standouts such as:

  • 63% of those claiming compliance report having transparency measures in place,
  • 55% say they have implemented risk management frameworks,
  • and just over half (51%) execute comprehensive risk assessments.

IT professionals concerned about increasing workloads

In addition to self-reported data on where businesses stand on their compliance journeys, the survey also focused on how IT professionals feel about the regulatory landscape as they navigate their work. Perhaps unsurprisingly, many report feeling overwhelmed by the amount of work needed.

“Another important takeaway from the findings is that workloads are expected to increase significantly in light of these new regulations,” Marcus said, noting that the survey found that 90% of respondents believe their workloads will be impacted, with InfoSec professionals reporting the highest level of concern.

“With this in mind, businesses should be thinking about automation and AI tools that can help alleviate some of the burden and even reduce burnout.”

Marcus also recommends that companies consider frameworks they already comply with and map them to these new regulations to identify and address the gaps. This should reduce the possibility of duplicative work and give internal teams a starting point as they catch up to regulation deadlines.

What American organizations need to know

While all of the participants in this survey are based in the UK and Germany, and many of the regulations discussed in the findings are tied to European countries, there are still some key takeaways for American businesses. 

“Any U.S.-based financial companies that operate in the EU will also need to ensure compliance, as will information and communications technology (ICT) providers that sell to EU financial services companies,” Marcus said. This affects any organization currently operating in the EU and serves as a notice to those who may want to enter the market in the future.

And, Marcus says, there is always an upside to considering compliance frameworks as you make technical and operational decisions.

“Even for companies that may not be legally required to comply with these regulations, companies should always implement compliance and risk-friendly practices,” Marcus said. “This can help to mitigate incoming risks, while also increasing trust and confidence with both current and prospective customers. It also eliminates the last-minute rush to become compliant when new regulations inevitably do come into effect.”

Compliance remains a priority for many businesses, and channel partners are stepping in to help. Read more about how Omega Systems offers compliance services in highly regulated industries.

thumbnail Victoria Durgin

Victoria Durgin is a communications professional with several years of experience crafting corporate messaging and brand storytelling in IT channels and cloud marketplaces. She has also driven insightful thought leadership content on industry trends. Now, she oversees the editorial strategy for Channel Insider, focusing on bringing the channel audience the news and analysis they need to run their businesses worldwide.

Recommended for you...

Video: Q2 2025 Channel Insights and Trends with the Channel Insider Editorial Team

A fast-paced editorial recap of Q2 2025 in the IT channel covering leadership shakeups at Kaseya, layoffs at Intel, federal obstacles pausing major acquisitions, AI adoption slowdowns, quantum security threats, evolving partner programs, and global economic tensions.

Katie Bavoso
Jul 17, 2025
XTIUM CEO and EMEA Leader on Global Business Opportunities

Global MSP XTIUM formally expands into EMEA with HQ in the Netherlands, unifying services for regional growth and global IT support.

Video: Inside MSP Owners Group: Juan Fernandez’s Vision for MSP 5.0, Rollups, and Employee Ownership

Juan Fernandez shares why he started the newly formed MSP Owners Group and what makes his rollup MSP different from others.

Katie Bavoso
Jul 2, 2025
Video: How Servix Solved Brado’s Remote Logistics IT Challenges with Scale Computing Edge Clusters

Discover how Servix and Brado tackled remote IT infrastructure challenges using Scale Computing edge solutions.

Katie Bavoso
Jul 1, 2025
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.