Practical insights for Norwegian AIFMs from the Swedish implementation of DORA

The Digital Operational Resilience Act (Regulation (EU) 2022/2554), commonly known as DORA, aims to address the growing reliance on Information and Communication Technology (ICT) in the financial sector and mitigating its associated risks. As of January 17 2025, DORA is applicable in the EU. Throughout autumn of 2024, Swedish Alternative Investment Fund Managers (“AIFMs”) subject to DORA have made substantial progress in implementing and ensuring compliance with the regulation.
Effective DORA implementations have started with the formation of a cross-functional project group and conducting a gap analysis to align existing frameworks with DORA requirements. Key components include establishing an ICT risk management framework, implementing incident response procedures, and managing ICT third-party risks through updated contracts and a comprehensive register of information. Compliance systems have enabled Swedish AIFMs to optimize data handling and maintain technical accuracy. Norway’s legislative proposal for DORA was adopted on 20 May 2025, and the Dora Act expected to enter into force between summer of 2025 and January 2026. The first mandatory reports are anticipated in early 2026. Given DORA’s extensive requirements, Norwegian AIFMs should initiate preparations now to ensure timely compliance.
At Permian, we have actively advised and consulted Swedish AIFMs throughout this process, gaining valuable insights into the practical steps for successful DORA compliance. In the full article, we outline the key considerations and actions Norwegian AIFMs should take as they prepare for the upcoming implementation of DORA in Norway.
For access to the full article, please click here.
Key Contacts








