Regulatory Change Impact Assessment Template (With a Worked DORA Example)

In short

A regulatory change impact assessment is the six-section, firm-side document that decides whether a new rule applies, what it changes and who owns each resulting obligation, and the template below is completed end to end for Commission Delegated Regulation (EU) 2025/532, the DORA subcontracting RTS. CUBE's 2025 Cost of Compliance Report found that 74% of firms take more than a year to implement new regulations, so the assessment should start at final-report stage, not at the application date.

Download the Excel template

Free, no email needed. Sheets: READ ME, Section 0 Document control, Section 1 Change identification, Section 2 Applicability screen, Section 3 Impact analysis, Section 4 Obligation breakdown, Section 5 Implementation plan, Section 6 Sign-off & changelog. All templates

A regulatory change impact assessment is the document a compliance team produces when a specific new rule lands: what the instrument is, whether it applies to you (with written reasoning either way), which functions and contracts it touches, and which owned, deadlined obligations fall out of it. Below is the full six-section template, ungated and in the page body, followed by the same template filled in end to end for Commission Delegated Regulation (EU) 2025/532, the DORA subcontracting RTS that entered into force on 22 July 2025. The discipline matters because implementation is slow: CUBE's Cost of Compliance Report 2025 (2,000+ senior compliance, risk and legal leaders, published 4 November 2025) found that 74% of firms take more than a year to implement new regulations.

The most valuable field in an impact assessment is the one templates rarely ship, the documented "no material impact" decision with written reasoning. When a supervisor asks "did you consider this instrument?", a dated out-of-scope decision with two sentences of reasoning is a defensible answer. A blank row is not.

This template lives in our trackers and templates library alongside the regulatory change tracker spreadsheet, which is the register this assessment feeds.

A regulatory impact assessment is what the regulator writes; this template is what you write when the rule lands

If you searched "how to write a regulatory impact assessment" and landed on OMB and OECD documents, you found sound guidance for a different document. A regulatory impact assessment (RIA) is a systematic appraisal a rule-maker performs before regulating: the costs and benefits of a proposed rule, per the OECD's RIA guidance and OMB Circular A-4 (the 2003 version, reinstated in February 2025 when OMB revoked the 2023 revision; OIRA summarizes its method in a primer). The European Commission's impact assessment guidance asks the same kind of questions: who is affected, how, at what cost and benefit, and whether the response is proportionate. Governments write RIAs so they regulate carefully.

A regulatory change impact assessment is the mirror-image document written by the regulated firm after a change is detected. The question is not "should this rule exist?" but "this rule exists, so what do we do about it, by when, and who owns it?" It sits between two disciplines it is often confused with: monitoring (detecting the change, covered in how compliance teams track regulatory changes) and regulatory change management, the end-to-end process this assessment is one stage of.

A complete assessment answers five questions:

  1. What changed, and what is the legal status of the source?
  2. Which entities, jurisdictions, products, services and activities are in scope?
  3. What changes for policies, controls, systems, people and third parties?
  4. Which actions are required, who owns them, and by when?
  5. What evidence supports the conclusion, and what will prove the implementation was completed?

The depth should match the organization's size, complexity and risk profile. The OCC's Comptroller's Handbook on compliance management systems makes the same point about change management: its formality should be commensurate with those factors, and changes should be evaluated across every affected line of business.

Everything below is the firm-side document.

The template has six sections, and every field carries a one-line instruction

Copy the tables below into a document or spreadsheet and start filling them in this afternoon, or use the free Excel workbook (one tab per section, each holding the blank fields alongside the completed 2025/532 example). Each field carries a one-line instruction; that is the field-by-field annotation, so the worked example that follows can stand on its own.

Section 0: Document control

Field How to fill it
Assessment ID Sequential, for example RCIA-2025-041, referenced from your change tracker and obligations register
Assessor Named person, not a team. One person stays accountable for the final assessment even when many contribute
Date of assessment The date of this version. Re-assessments get new dates, logged in Section 6
Status Draft / In review / Approved / Closed
Next-review trigger A date or an event. "On publication in the Official Journal" is a better trigger than an arbitrary date for an instrument still moving
Approver and sign-off date Whoever owns the risk acceptance, typically the Head of Compliance or CCO

Section 1: Change identification

This is the section gated templates tend to skip, and it is where assessments go wrong before they start.

Field How to fill it
Instrument name and official citation Full title plus a stable identifier (CELEX number, OJ reference, Federal Register citation), never just a nickname
Issuing authority and tier Who made the rule and how authoritative it is (a regulation outranks a speech)
Instrument level or type Level 1 legislation / Level 2 delegated or implementing act (RTS, ITS) / guidance / consultation / enforcement signal
Lifecycle status Consultation, final report, adopted, published in OJ, in force, applies, with dates for each known stage, "as of" dated
Key dates Publication, entry into force, application, first reporting or submission deadline. These are four different dates, and conflating them is the classic failure
Provisions changed and baseline Which articles changed, and which earlier version you compared against
How detected Source and date detected. This is the audit-trail field; the lag between publication and detection is a KPI worth tracking
Change statement One sentence: the source changes [requirement] for [regulated population or activity] in [jurisdiction] from [date], subject to [conditions or open dependencies]

If the change statement cannot be completed yet, the development needs more legal research before it can be assessed.

The level and type field earns its row. Under DORA, the Level 1 obligation to manage subcontracting risk applied from 17 January 2025, while the Level 2 detail specifying how landed in July 2025 and was rejected by the Commission once in between. A template without a level field cannot represent that reality, and most of DORA's operational substance lives in Level 2. The incident-reporting clocks are one example: the initial report within four hours of classifying an incident as major and no later than 24 hours from awareness, the intermediate report within 72 hours of the initial notification, and the final report no later than one month after the latest intermediate report sit in Delegated Regulation (EU) 2025/301 of 23 October 2024, not in DORA itself. (The Commission's November 2025 Digital Omnibus proposes routing DORA incident reports through a single entry point; as of 30 September 2026 that is still a proposal in a Parliament committee.)

Section 2: Applicability screen

Field How to fill it
Entity types in scope As defined in the instrument, cited by article
Our legal entities affected By jurisdiction. A group answer is not an answer
Jurisdictional nexus What ties us to the rule: establishment, licensing, customer location, employee location, data subjects, product distribution
Activities and products touched Specific lines of business, not "operations"
Population Consumers, employees, counterparties or another defined group the rule protects
Exemptions and proportionality For example DORA's Article 4 proportionality principle and microenterprise carve-outs, with the provision cited
Third parties Whether the duty extends to outsourced services, agents, distributors or processors
Timing Transition periods, grandfathering, phased application
Applicability decision In scope / Out of scope / Partially in scope / Unknown, with written reasoning even when out of scope
Supporting business facts The facts the decision rests on: an entity register, a licensing record, a product inventory, a threshold calculation

That last pair of fields is the defensibility artifact. Write the reasoning at the moment of decision, date it, and never delete it; dismissed changes with documented reasoning are what distinguish a triage process from a guess. "Not applicable" is not self-proving, so cite the business fact that makes it true. Use "Unknown" when a material fact is missing, and assign an owner and a date to resolve it rather than forcing a premature yes or no.

Applicability and materiality are separate decisions. A rule can legally apply and need little work because existing controls already satisfy it. Another development can impose no direct obligation and still change supervisory expectations, enforcement exposure or contract terms.

Section 3: Impact analysis

Run a functions-affected matrix, with a row for each function and columns for affected? / what changes / current-state reference:

Function Affected? What changes Current-state reference (policy, control or contract)
Compliance
Legal
Procurement and third-party risk
IT and security
Operations
Finance
Front office

Then check the change against eight domains, so nothing is missed: obligations and controls (created, amended, clarified or removed), products and customers, processes and operations, data and technology, policies and governance, people and training, contracts and third parties, and financial or strategic effects. Then rate the whole change:

Field Rubric
Materiality High = new obligation requiring a new control or contract change. Medium = existing control needs amendment. Low = documentation or awareness only
Urgency Application date minus today: a mechanical calculation, not a feeling
Estimated cost and effort band A = documentation only. B = process or contract changes. C = new systems or controls
Confidence How sure you are of the interpretation and of the business facts behind it

Materiality is judged on consistent dimensions: severity if the requirement is not met, reach across entities and markets, harm to customers or the market, time available, complexity and reversibility, and the strength of existing controls. Do not let a single score replace the analysis. A High, Medium or Low label is only useful when its rationale is visible.

Section 4: Obligation breakdown

One row per discrete obligation. This is the section that turns analysis into work, and it feeds your obligations register directly (the template for that is the regulatory obligations register template).

Obligation Provision Owner Deadline Required action Evidence that will prove compliance Validation

The evidence column is the field templates most often omit. Decide at assessment time what artifact will prove each obligation is met (a revised policy, an amended contract, a filed report), or the obligation will be "done" in a status column and unprovable in an audit. The validation column names how someone other than the owner will test that the change worked, whether by sample, walk-through or control test.

Section 5: Implementation plan

Field How to fill it
Actions, owners, dates The project plan distilled from Section 4
Dependencies Contract renewal calendars, system release windows, budget cycles
Interim-risk acceptance Where full compliance by the deadline is not achievable, record the interim control, its limits, who accepted the risk, when, the review cadence and the date the interim control retires
Post-implementation review The date someone checks that the change achieved its intended outcome

The OCC handbook expects examiners to ask whether an organization reviews a change after it is implemented and whether project records, committee minutes, adopted procedures and monitoring show that the process worked as intended. The last row of that table is how you have an answer.

Section 6: Sign-off and changelog

A visible change log (date, change, source) for the assessment itself. Instruments move; the January 2025 rejection in the worked example below invalidated part of an assessment written in August 2024, and the changelog is how that shows. Keep three more things with it. Separate facts, assumptions and professional judgments, and record contrary views that shaped the decision. Add a review trigger whenever a conclusion depends on guidance that may change. And list the events that reopen the assessment: an amendment, a correction, a final text, an interpretation by a regulator or court, local implementation, a new product, a new jurisdiction, a supplier change, an acquisition, or an assumption that turns out to be wrong.

Date Change Source

Before approval, ask eight questions. Is the source authoritative and current? Is its legal status described correctly? Have all relevant entities, jurisdictions, products and third parties been considered? Are the business facts confirmed by the people who own the activity? Does every significant conclusion have evidence? Are actions specific, owned and timed against the compliance date? Is validation defined? Are uncertainties and escalations visible?

The worked example assesses Delegated Regulation (EU) 2025/532 from an EU payment institution's compliance seat

Now the same template, completed. The scenario is hypothetical but the regulation is real: a mid-size EU payment institution (one of the 20 categories of financial entity listed in DORA Article 2(1); see EIOPA's DORA overview) whose card acquiring and processing run on ICT providers that subcontract. All regulatory facts below are as of 30 September 2026 and cite the final text on EUR-Lex: Commission Delegated Regulation (EU) 2025/532.

First, the lifecycle that makes this instrument such a good test of the template (documented on the EBA's Single Rulebook page for the RTS and, for the rejection episode, in PwC Legal's analysis):

Date Event
26 July 2024 ESAs publish the joint Final Report on the draft RTS (JC 2024 53)
21 January 2025 Commission rejects the draft by letter: draft Article 5, on conditions across the ICT subcontracting chain, went beyond the empowerment in DORA Article 30(5)
7 March 2025 ESAs issue their Opinion on the amended draft
24 March 2025 Commission adopts the delegated regulation
2 July 2025 Published in the Official Journal
22 July 2025 In force, with no transitional provision for existing contracts

Section 0: Document control (completed)

Field Entry
Assessment ID RCIA-2025-041
Assessor Head of Compliance
Date of assessment 7 July 2025 (v3; prior versions 12 August 2024 and 3 February 2025, see Section 6)
Status Approved
Next-review trigger Event: any ESAs guidance or Q&A on the RTS. Date backstop: first annual third-party risk review after in-force
Approver and sign-off date CCO, 15 July 2025

Section 1: Change identification (completed)

Field Entry
Instrument Commission Delegated Regulation (EU) 2025/532 of 24 March 2025, an RTS specifying the elements to determine and assess when subcontracting ICT services supporting critical or important functions. CELEX 32025R0532; OJ L, 2.7.2025
Issuing authority and tier European Commission, on the ESAs' (EBA, EIOPA, ESMA) draft. Tier A
Instrument level or type Level 2: RTS under DORA Art. 30(5), supplementing Regulation (EU) 2022/2554 (Level 1, applies from 17 January 2025)
Lifecycle status In force (22 July 2025). Full history: final report 26 Jul 2024, Commission rejection 21 Jan 2025, ESAs Opinion 7 Mar 2025, adopted 24 Mar 2025, OJ 2 Jul 2025, in force 22 Jul 2025. As of 7 Jul 2025
Key dates Publication 2 Jul 2025; entry into force and application 22 Jul 2025; no separate application date; no transitional period
Provisions changed and baseline New instrument; baseline is DORA Art. 30(5) and our v2 assessment of the amended draft
How detected Daily OJ sweep, detected 2 July 2025, same day. Instrument tracked since the ESAs final report through EBA source monitoring, 26 July 2024
Change statement The RTS requires DORA financial entities to assess defined elements of ICT subcontracting chains, secure specified contract content and handle provider notifications of material changes, from 22 July 2025, with no transitional provision for existing contracts, although changes to them must be made in a timely manner on a documented timeline

Section 2: Applicability screen (completed)

Field Entry
Entity types in scope Financial entities under DORA Art. 2 that use ICT services supporting critical or important functions under contracts permitting subcontracting; includes payment institutions
Our legal entities affected EU payment institution entity (home-state license). Non-EU group entities are out of DORA scope
Jurisdictional nexus Establishment and license in the EU member state
Activities and products touched Card acquiring and payment processing, both run on ICT arrangements classified as supporting critical or important functions in our DORA register of information
Population Not applicable: a supervisory duty on the entity, not a customer-facing rule
Exemptions and proportionality DORA Art. 4 proportionality applies to how we implement; we are not a microenterprise, so no carve-out
Third parties Yes: ICT providers and their subcontractors
Timing No transition period
Applicability decision In scope. Reasoning: we are a DORA financial entity, and at least four ICT arrangements supporting critical or important functions permit subcontracting (cloud hosting, acquiring processing, fraud scoring, card personalization). Recorded 12 Aug 2024, reconfirmed against the final text 7 Jul 2025
Supporting business facts Entity register, license record, and the four register-of-information entries flagged as supporting critical or important functions

Section 3: Impact analysis (completed)

Function Affected? What changes Current-state reference
Compliance Yes Owns re-assessment, register updates and the evidence trail Third-party risk policy v2.3; DORA register of information
Legal Yes Contract addenda for the mandatory content in Art. 4 across in-scope ICT contracts Master services agreements; outsourcing addenda
Procurement and third-party risk Yes Pre-contract due diligence extended to the Art. 1 risk-profile elements and the Art. 3 risk assessment, including whether the provider can monitor its own subcontractors Vendor due-diligence questionnaire v4
IT and security Yes Monitoring of subcontracting chains for critical functions; data-location tracking Cloud governance standard; CMDB
Operations Partially Exit and termination playbooks extended for subcontracting failures (Art. 6) Business continuity and exit plans
Finance Low Budget line for external counsel on contract remediation Outsourcing budget FY2025
Front office No No customer-facing change None
Field Entry
Materiality High: new obligations requiring contract changes and new due-diligence steps (rubric: new obligation plus contract change)
Urgency Assessed 7 Jul 2025 against in-force 22 Jul 2025: 15 days for new-contract readiness; legacy-contract exposure handled in Section 5
Cost and effort band B: process and contract changes; external counsel for addenda; no new systems
Confidence High on scope and dates (final text on EUR-Lex); medium on how supervisors will read "well in time" in Art. 5

Section 4: Obligation breakdown (completed)

Obligation Provision Owner Deadline Required action Evidence Validation
Take the elements that shape the overall risk profile and complexity of an ICT service into account when assessing subcontracting Art. 1 Head of TPRM 22 Jul 2025 (new contracts) Extend the due-diligence questionnaire with the Art. 1 elements Revised questionnaire and completed assessments on file Second-line sample of three new onboardings
Complete the due diligence and risk assessment before agreeing that a critical or important service may be subcontracted, including whether the provider can monitor its own subcontractors Art. 3 Head of TPRM 22 Jul 2025 (new contracts) Add the Art. 3 conditions, including a provider-oversight capability check, to onboarding due diligence Due-diligence report section per provider Second-line sample of three new onboardings
Ensure contracts contain the mandatory content: monitoring, data location, security standards, authority access, change notification Art. 4 General Counsel New contracts 22 Jul 2025; legacy per Section 5 Clause-gap review of in-scope ICT contracts; issue addenda Signed addenda; clause-gap tracker Legal spot-check of executed addenda
Handle provider notifications of material subcontracting changes ("well in time") Art. 5 (final text) Head of Compliance 22 Jul 2025 Stand up a notification-intake and response protocol with a defined assessment SLA Notification-handling SOP; response log Tabletop test with a mock notification
Maintain termination rights for subcontracting breaches Art. 6 General Counsel and Operations 22 Jul 2025 Extend exit plans and the termination playbook to subcontracting-triggered exits Updated exit plans Exit-plan walkthrough with Operations
Update the DORA register of information for subcontracting detail DORA Art. 28(3); CIR (EU) 2024/2956 templates Head of Compliance Next annual register submission Refresh subcontractor entries across the 15 register templates Register export; submission receipt Reconcile the register against contract records

That last row is the knock-on most assessments miss. The register of information is already a live supervisory artifact, and your subcontracting data feeds it: the ESAs collected the first registers via competent authorities by 30 April 2025 and used them to designate the first 19 critical ICT third-party providers on 18 November 2025, including AWS, Microsoft and Google Cloud.

Section 5: Implementation plan (completed)

Field Entry
Actions, owners, dates Per Section 4; weekly stand-up owned by the Head of Compliance until all rows are green
Dependencies Contract renewal calendar (two of four in-scope contracts renew in Q4 2025); external counsel capacity
Interim-risk acceptance The regulation has no transitional provision for existing contracts. Decision: remediate legacy contracts at renewal or within 12 months, whichever is earlier; interim exposure accepted by the board risk committee on 15 July 2025, reviewed quarterly, retired when the last addendum is signed. This is a deliberate, documented risk decision, not a grace period the regulation grants, and it matches Article 4(2), which asks for changes to existing contracts "in a timely manner and as soon as it is possible" and for the planned timeline to be documented
Post-implementation review 15 January 2026: sample of new contracts and addenda checked against Art. 4, results to the risk committee

Section 6: Sign-off and changelog (completed)

Date Change Source
12 Aug 2024 v1 assessed against the ESAs final report; obligations drafted including draft Art. 5 chain-monitoring conditions ESAs Final Report JC 2024 53
3 Feb 2025 v2: Commission rejection noted (letter of 21 Jan 2025); draft-Art. 5 chain-condition workstream paused, all other workstreams continued Commission rejection letter via EBA
10 Mar 2025 ESAs Opinion on the amended draft noted; scope of the final text now stable ESAs Opinion, 7 Mar 2025
7 Jul 2025 v3 against the final OJ text: draft chain-monitoring conditions absent from the final text; "Art. 5" now denotes material-change notification. Obligations re-based; approved EUR-Lex CELEX 32025R0532

The changelog shows that the rejected draft's Article 5 and the final regulation's Article 5 are different provisions that happen to share a number. A team working from a July 2024 summary would build a chain-monitoring program the final text does not require in that form, and might miss the notification protocol it does require, which is why the template always cites the final EUR-Lex text.

Start the assessment at final-report stage, because teams that waited for the Official Journal got 20 days

The timeline above settles the "when do we assess?" argument with arithmetic. A team that opened this assessment at the ESAs' final report (26 July 2024) had roughly twelve months of runway to the 22 July 2025 in-force date. A team that waited for OJ publication (2 July 2025) had 20 days, against a regulation with no transitional provision that requires contract changes. Set against the CUBE finding that 74% of firms take more than a year to implement a new regulation, twenty days is little more than notice.

The counterargument is "drafts change, so why assess early?" The same instrument answers it: the draft did change, materially, and the assessment survived because it carried lifecycle status and re-assessment triggers instead of pretending the rule was static. Early assessment plus a changelog beats late assessment every time; the January 2025 rejection cost the early team one paused workstream, while late teams lost the entire runway. The same logic applies to proposed rules generally. Assess a proposal when its likely effect or implementation effort justifies preparation, label it as proposed, record the uncertainty, separate preparatory actions from mandatory ones, and reassess when the final text is issued.

Catching instruments at final-report stage is a monitoring-design question. That is horizon scanning feeding change management, and the horizon scanning template covers the upstream half. For changes that span several jurisdictions, start from one common source record, then assess applicability, local implementation, deadlines and actions by jurisdiction and legal entity; one regional conclusion rarely carries over unchanged.

Five mistakes make an impact assessment worthless in front of a supervisor

  1. No record of out-of-scope decisions. If your process only documents rules you act on, you cannot prove you considered the ones you dismissed. The Section 2 reasoning field is two sentences per instrument; write them.
  2. Citing drafts, summaries or vendor blogs instead of the final text. The Article 5 renumbering above is the cautionary tale. Cite the CELEX number, link EUR-Lex (or the equivalent primary source), and re-base obligations when the final text lands.
  3. Conflating publication, entry into force and application. DORA entered into force in January 2023 and applies from 17 January 2025; 2025/532 was published on 2 July 2025 and came into force on 22 July 2025, so each of the four date types needs its own field.
  4. Inventing grace periods. 2025/532 has no transitional provision for existing contracts. The honest move is Section 5's documented interim-risk acceptance, a real decision with an owner and a review date, not an assumed one, and consistent with Article 4(2), which expects timely changes and a documented timeline.
  5. Writing penalty folklore into the impact box. "DORA fines firms 1% of turnover" is wrong. DORA sets no EU-level fine tariff for financial entities, because sanctions are set at Member State level, and the periodic penalty payments in Article 35, of up to 1% of average daily worldwide turnover (Article 35(8)) for no more than six months (Article 35(7)), apply only to designated critical ICT third-party providers (as of 30 September 2026, per the DORA text).

A sixth mistake is structural: running assessments as unconnected documents. Each assessment should feed a register, the change tracker for status and the obligations register for the Section 4 rows, and your regulatory change management policy should name the assessment as a mandatory stage with the trigger defined.

The template works in a spreadsheet until volume outruns diligence

Everything above works in a spreadsheet, and if you run five assessments a year, a spreadsheet is the right tool. The template breaks down on volume: the detection lag in Section 1, the re-assessment triggers in Section 0 and the changelog discipline in Section 6 all depend on someone noticing every status change across every instrument you track, and that work does not scale by diligence.

RegWatch (my company) automates this part of the workflow, and its records line up with the template's sections. Section 1 starts from a Finding: the source URL, dates and a verbatim excerpt captured by a scheduled monitoring run. Section 2's applicability call maps to triage: each finding is scored against your company profile, accepted ones get a plain-language "Why this matters," and suppressed ones remain on the record, marked as suppressed. Each Section 4 row becomes an Obligation with an owner, an effective date and an evidence area, and the obligation's history and the audit log carry Section 6. The judgment stays human: whether a rule applies, how hard it hits, and whether the written reasoning holds.

Tooling or not, start by copying the template, picking the most recent instrument that landed on your desk, and filling in all six sections against the primary text. If Section 2's reasoning field or Section 4's evidence and validation columns feel unfamiliar, practice those first, because an examiner asks for them by name.

This article is general information, not legal advice.

Download the Excel template

Free, no email needed. Sheets: READ ME, Section 0 Document control, Section 1 Change identification, Section 2 Applicability screen, Section 3 Impact analysis, Section 4 Obligation breakdown, Section 5 Implementation plan, Section 6 Sign-off & changelog. All templates

Questions

What is a regulatory change impact assessment?

A structured document a regulated firm produces when a specific new or amended regulation is detected. It identifies the instrument, decides applicability with written reasoning, maps the impact across functions and existing controls, and breaks the rule into owned, deadlined obligations with defined evidence. It sits between monitoring, which detects the change, and implementation, which executes the plan.

What is the difference between a regulatory impact assessment (RIA) and a regulatory change impact assessment?

A regulatory impact assessment is written by the regulator before rulemaking, as a cost-benefit appraisal of a proposed rule under OECD guidance and OMB Circular A-4. A regulatory change impact assessment is written by the regulated firm after a change is detected, to work out what it must do.

What should a regulatory change impact assessment include?

Six sections: document control, change identification including the instrument's level and lifecycle status, an applicability screen with a written in-scope or out-of-scope decision, impact analysis across functions and existing controls, an obligation breakdown with owner, deadline, evidence and validation for each row, and an implementation plan with sign-off and changelog. Most templates omit lifecycle status, documented out-of-scope reasoning and evidence per obligation.

When should you run the assessment: at consultation, adoption or entry into force?

At the final-report or adoption stage, with a re-assessment trigger at every later status change. For the DORA subcontracting RTS, teams that assessed at the ESAs' final report (26 July 2024) had about twelve months before the 22 July 2025 in-force date, while teams that waited for Official Journal publication (2 July 2025) had 20 days. The draft also changed in between, which is why triggers matter.

How long does it take to implement a regulatory change?

CUBE's Cost of Compliance Report 2025, a survey of more than 2,000 senior compliance, risk and legal leaders published on 4 November 2025, found that 74% of firms take more than a year to implement new regulations. That is why the assessment has to start at final-report stage rather than at the application date.

When is an impact assessment complete?

When the conclusion is approved, every required action has an owner and a deadline, completion evidence is retained, and material changes have been validated by someone other than the owner. Closing the analysis before implementation is finished opens a gap between interpretation and control. Give a closed assessment both a decision date and defined reopening triggers, such as an amendment, a regulator's interpretation or a new product.

Terms in this guide

Sources

  1. CUBE, The Cost of Compliance Report 2025 accessed 30 Sep 2026
  2. Commission Delegated Regulation (EU) 2025/532, EUR-Lex accessed 30 Sep 2026
  3. EBA Single Rulebook: joint RTS on subcontracting ICT services supporting critical or important functions accessed 30 Sep 2026
  4. PwC Legal: European Commission rejects the DORA subcontracting RTS accessed 30 Sep 2026
  5. EBA: The ESAs acknowledge the European Commission's amendments to the technical standard on subcontracting under DORA (7 March 2025) accessed 1 Oct 2026
  6. Regulation (EU) 2022/2554 (DORA), EUR-Lex accessed 30 Sep 2026
  7. Commission Delegated Regulation (EU) 2025/301 on ICT-related incident reporting accessed 30 Sep 2026
  8. Commission Implementing Regulation (EU) 2024/2956, register of information templates accessed 30 Sep 2026
  9. ESAs announce timeline to collect registers of information and designate critical ICT third-party providers accessed 30 Sep 2026
  10. EIOPA: ESAs designate the first critical ICT third-party providers under DORA (18 November 2025) accessed 30 Sep 2026
  11. EIOPA: Digital Operational Resilience Act (DORA) overview accessed 30 Sep 2026
  12. OECD, Regulatory Impact Assessment accessed 30 Sep 2026
  13. Office of Information and Regulatory Affairs, Regulatory Impact Analysis: A Primer (on OMB Circular A-4) accessed 30 Sep 2026
  14. OMB Memorandum M-25-15, Rescission and Reinstatement of Circular A-4 (12 February 2025) accessed 30 Sep 2026
  15. European Parliament Legislative Observatory, Digital Omnibus (2025/0360(COD)) accessed 30 Sep 2026
  16. European Commission, Impact assessments accessed 30 Sep 2026
  17. OCC Comptroller's Handbook, Compliance Management Systems accessed 30 Sep 2026

See which of this month’s changes apply to you.

Book a session on the regulators and markets you name.

Book a demo