Operational Resilience Is Not a Document. It Is a Data Problem.

DORA is already law. Most institutions are still working out whether they can actually comply with it.

That distinction matters. There is a wide gulf between an organisation that has spent eighteen months building a compliance framework and one that can answer the questions the framework exists to answer. The first is visible. The second is rare. The gap between them is not a regulatory problem, it is an infrastructural one the industry has quietly avoided for years.

The March 2026 Information Register submission is about to make that avoidance very loud.

The Room That Went Quiet

Early in 2025, I sat with the CRO of a mid-sized financial institution. DORA had just become enforceable. Her team had done what looked, by any reasonable standard, like serious work. Eighteen months of it. Policy documents. Risk registers. Governance structures. Third-party mapping. They had the architecture of compliance. It was genuinely impressive, the kind of work that gets presented well in a board pack.

Then someone in the room asked about the March 2026 Information Register submission.

The room went quiet.

Not the polite quiet of people organising their thoughts. The other kind, where everyone is doing rapid mental arithmetic and arriving at the same uncomfortable answer. The data needed to populate that register simply did not exist in a usable form. It was distributed across systems that did not talk to each other, owned by teams with different definitions of the same terms, stored in formats that made aggregation a manual project measured in weeks, not hours.

Eighteen months of compliance work. The underlying data layer: untouched.

I have been in enough of these rooms to know this silence is not unique to that institution. I have seen versions of it in London, in Dubai, in Mumbai. Different organisations, different regulators, identical pause. What struck me that day was not the gap itself, I had expected to find gaps. It was the specific shape of it. The team had built compliance theatre. Beautifully documented. Operationally hollow.

Three Things That Conversation Made Undeniable

**The first is that most institutions confuse documentation with readiness.** This is not laziness or incompetence. It is a rational response to how compliance has historically been evaluated. Regulators asked for evidence of frameworks. Organisations produced frameworks. The feedback loop rewarded paperwork. DORA has changed the question being asked. The Information Register is not a document, it is a live query run against your actual data architecture. You cannot write your way to a passing grade. The data either exists in a coherent, mappable form, or it does not.

**The second is that this is the same problem wearing different clothes.** The broken data layer that cannot support an Information Register submission is the same broken data layer that cannot support AI or ML initiatives. When organisations talk about data readiness for artificial intelligence, and the conversation comes up constantly now, they often frame it as a new investment required for new capabilities. In most cases, it is neither new nor optional. It is a pre-existing infrastructure deficit that AI ambitions have simply made impossible to defer. I wrote about the adjacent problem, the way third-party data creates hidden exposure, in an earlier piece on [rethinking third-party risk](https://lakshvaswani.com/when-partners-become-liabilities-rethinking-third-party-risk/). The pattern is the same: the problem is not the risk you can see. It is the one your data architecture cannot tell you about.

**The third is the one the industry least wants to hear.** Operational resilience frameworks that rest on poor data infrastructure are not frameworks. They are documents waiting to embarrass you. The scenario matters here: a genuine operational disruption, a regulatory examination, a cyber incident requiring rapid forensics. All of them require the same thing, accurate, accessible, well-governed data about your critical functions, your dependencies, and your recovery pathways. If that data does not exist in a usable form under normal conditions, it will not materialise under pressure. I have written previously about [the human side of cyber risk](https://lakshvaswani.com/when-firewalls-fail-the-human-side-of-cyber-risk/) and the way institutional confidence about resilience tends to collapse precisely when it is tested. Data readiness is the structural version of that same overconfidence.

What This Means for the Institutions Still Building

If your organisation is in the cohort that has the framework but not the data infrastructure to support it, and based on everything I am seeing, that is most of the industry, the path forward has a specific sequence.

The Information Register deadline is the forcing function, but treating it as a one-time submission exercise would be a significant mistake. The register is a symptom question. The actual question it is asking is whether your data governance, your system architecture, and your critical function mapping are coherent enough to produce a reliable, auditable output on demand. Answering yes in 2026 and reverting to fragmentation in 2027 solves nothing. Continuous readiness cannot be delegated to a project team that convenes before a regulatory deadline. It has to be owned at the top, funded accordingly, and treated as a permanent operational capability, not an event.

This also has direct implications for AI ambitions. Boards and executive committees increasingly want to understand when and how they can deploy AI and ML across risk and compliance functions. The honest answer is that those capabilities will perform in direct proportion to the quality of the data they run on. Closing the data preparedness gap is not a precondition for AI, it is the work itself.


The institutions that come out of the DORA era in the strongest position will not be the ones with the most sophisticated frameworks. They will be the ones that quietly fixed their data infrastructure while everyone else was still formatting governance documents.

A resilience framework that relies on data you cannot actually produce is not a framework. It is a liability you have not invoiced yet.