Perspectives · Sep 7, 2026 · 3 min read
Banking Compliance in 2026: The Regulations Costing the Most, and Where Automation Actually Helps
Financial sector compliance costs average $181 billion a year. Here's what's driving that spend under DORA, and where automation is actually cutting it.

Compliance costs across the financial sector average $181 billion annually, with the average cost per employee to maintain compliance reaching around $10,000, according to Forbes-reported industry estimates. With the Digital Operational Resilience Act's additional requirements now in force, those costs are only expected to climb. For banks and financial institutions, the question in 2026 isn't whether compliance spend will keep rising, it's whether that spend goes toward headcount or toward infrastructure that actually reduces the manual load.
The Regulations Driving the Cost
DORA has been directly applicable across the EU since January 17, 2025, and 2026 has marked a clear shift from regulatory guidance toward active supervision and enforcement. National Competent Authorities and the European Supervisory Authorities are no longer just reviewing paperwork, they're demanding real-time evidence of resilience, automated reporting, and demonstrable control over ICT risk. The penalties reflect that shift: Italy has set ceilings up to €20 million or 10% of annual turnover, and Ireland allows fines up to €10 million or 10% of turnover. Even a mid-sized company, defined under DORA as having fewer than 250 employees and turnover below €50 million, can face fines of €500,000 for poor third-party risk management alone.
DORA isn't the only pressure point. EU financial institutions absorbed updated EBA AML guidelines and revised PSD2 technical standards in the same period, and MiCA continues to bring licensing and disclosure obligations for crypto-asset activity. Each addition adds its own workflow steps, documentation requirements, and audit trail, on top of the ones already in place, and none of them are designed to share infrastructure with the others by default.
Legacy Systems Are the Real Bottleneck
Much of the rising cost traces back to infrastructure rather than the regulations themselves. Many financial institutions still rely on legacy systems that are difficult to integrate with modern, automated compliance tools, which makes every new requirement a technically complex, costly upgrade rather than a configuration change. Mid-market banks with $10 billion to $30 billion in assets typically spend $15 million to $60 million annually on compliance once personnel, tooling, external audit fees, and regulatory change management are counted, and a meaningful share of that spend goes toward maintaining systems that weren't built to produce the kind of real-time evidence DORA now expects.
Where Automation Is Actually Moving the Needle
The institutions seeing real ROI aren't necessarily cutting headcount, they're changing what compliance staff spend their time on. AI automation is reported to be cutting compliance spend by up to 40% at some mid-market banks, largely by acting as a triage layer: scoring alerts by risk probability, clustering related cases, and surfacing only the highest-confidence anomalies for human review, rather than asking analysts to work through every alert manually.
What DORA-Ready Infrastructure Looks Like in Practice
In 2026, "major" ICT incidents require a strict three-stage reporting cadence: initial notification within four hours of classification, an intermediate report within 72 hours, and a final report within one month. Meeting that timeline manually, under pressure, is where most institutions run into trouble. A DORA-ready setup automates incident classification against the regulation's RTS criteria, triggers escalation to legal and compliance teams the moment a "major" threshold is hit, and keeps a centralized, auditable log of every incident, including the minor ones, for year-end trend analysis and examiner review.
This is the specific gap casepal's LGRC infrastructure is built to close for institutions operating under DORA, MiCA, the AI Act, and NIS2: keeping evidence current as a byproduct of daily operations, so it's ready before the examiner asks, not assembled after.
Where This Leaves Compliance Teams
As NCAs and ESAs continue moving from reviewing policy documents to demanding proof, the institutions most exposed in the next enforcement cycle won't be the ones with the least mature risk programs on paper. They'll be the ones still running DORA compliance through spreadsheets and email, and finding out how far behind that leaves them the moment an examiner asks for real-time evidence.
Written by Anna Balabina
Back to all posts


