Operational resilience beyond technology
DORA has placed digital operational resilience at the center of financial-services agendas. A resilient institution needs more than robust infrastructure, continuity and third-party management; it also needs to govern how responsibilities and access are assigned to people operating those systems. The human factor appears at many points in the operational cycle. Personnel controls can therefore form part of a broader resilience approach, especially when tied to specific functions and privileges.
Critical functions and sensitive access
Banks, insurers and other financial institutions have functions with particularly high potential impact: system administration, payment operations, confidential information, credential management and changes to critical configurations. Job title alone is not enough to measure exposure. A Human Risk model links the function to actual permissions and helps determine what level of verification is reasonable before those permissions are granted or expanded.
The role of external providers
External providers are an essential part of the financial ecosystem. Cloud, development, support or consulting personnel may have temporary or permanent access to sensitive environments. Third-party risk management should therefore consider not only the contracted company but also the controls applied to people delivering the service. This does not require one global screening standard; requirements and evidence should be proportionate to access and service criticality.
Proportionate, not indiscriminate, screening
Effective screening is selective. It can include identity verification and, where relevant and lawful, additional checks on history, qualifications or integrity. Depth should vary by risk. This protects the organization and the candidate by avoiding unnecessary collection. In regulated environments, a clear and documented policy is often more defensible than a broad but inconsistent practice.
CHRO, CISO and Compliance at the same table
DORA reinforces the need to connect resilience, technology and governance. HR brings process and employment proportionality; the CISO brings access criticality; Compliance and Risk bring the control framework. A common policy supports coherent review of critical roles, third parties and changes in responsibility. The goal is to treat the human factor as a normal dimension of operational resilience rather than a separate issue that appears only after an incident.
Want to integrate Human Risk Management into your risk model?
Validato helps organizations design modular, proportionate background checks for candidates and employees, with international reach and data governance in Switzerland and the EU. Contact us to discuss which screening level fits your higher-risk roles.
From