The customer-facing system your DORA testing forgot
DORA has applied to European financial entities since January 2025. Strip away the acronyms and it asks three plain things: manage the risk of your ICT systems, test how they hold up, and report it when they break. Most banks and insurers read that and think of core banking, payment rails, trading platforms. They rarely think of the chatbot on their homepage.
They should. A customer-facing assistant is an ICT system that serves your clients. It quotes, confirms, explains, and sometimes commits — in your name. DORA doesn't name chatbots specifically; it doesn't need to. If a system talks to your customers and something going wrong with it would hurt them or you, it's in scope for the resilience testing DORA expects.
So what would a resilience test of an assistant even look like? Not a load test. The question isn't whether it stays up under traffic — it's whether it stays trustworthy under pressure. Can it be talked into a rate or a waiver it shouldn't offer? Can its internal instructions be extracted? Can it be made to surface another client's data? Those are the failure modes that create real exposure for a regulated firm, and they're exactly the ones a standard infrastructure pentest walks straight past.
Here's the honest part, because you'll hear the opposite from plenty of vendors. No audit makes you DORA-compliant. Compliance is a program, signed off by your own risk and legal functions, not a badge you buy. What a good audit gives you is evidence — reproducible proof of how your assistant behaves under attack, scored by severity, in a form your risk committee and your auditors can actually use. It's an input to your resilience testing, not a substitute for it. And any sentence that maps a finding to a specific DORA article should be read by your own lawyer before it goes anywhere.
That framing isn't a hedge — it's the difference between a document that helps you and one that gets picked apart the first time it's challenged. Evidence you can stand behind beats a certificate nobody believes.
If your chatbot has been in production for a year and has never been part of a resilience test, that's not unusual. It's just the gap most financial firms haven't closed yet. Closing it starts with finding out what your assistant actually does when someone tries to break it.
See what your banking assistant does under attack — a 3-day audit, fixed fee, evidence your risk team can use.