• November 3, 2025 |
  • |

ERM Maturity, Cost of Capital, and Investment Efficiency: Pre- and Post-DORA Evidence

By:
SHARE
ABSTRACT
The European Union’s Digital Operational Resilience Act (DORA) represents a paradigm shift in the regulation of information and communication technology (ICT) risk within the financial sector. This paper examines the anticipated effects of DORA on the Enterprise Risk Management (ERM) maturity of financial institutions, and the subsequent impact on their cost of capital and investment efficiency. The study outlines a methodology to empirically test these relationships by defining pre- and post-DORA event windows, centered on the regulation's proposal in September 2020 and its full application in January 2025. We propose a composite measure for ERM maturity, incorporating disclosure analysis and governance characteristics, and utilize established models supported by the literature to assess investment efficiency. Drawing on existing research, we hypothesize that DORA’s stringent and prescriptive requirements will lead to an increase in ERM maturity, particularly in relation to ICT and third-party risk management. This enhancement in risk management and transparency is expected to reduce the cost of capital for compliant firms. Furthermore, by improving the quality of risk-related information, DORA should foster greater investment efficiency, mitigating both over- and under-investment. The paper also provides a comparative analysis with the operational resilience frameworks in the United Kingdom and the United States, highlighting DORA's unique extra-territorial scope and direct oversight of critical third-party providers.

Introduction

The global financial system’s increasing dependence on digital infrastructure and third-party information and communication technology (ICT) providers has introduced new sources of systemic risk. Recognizing ICT risk as a significant threat to financial stability, regulators worldwide have intensified their focus on operational resilience.1 In the European Union, this has culminated in the Digital Operational Resilience Act (DORA), a landmark regulation establishing a harmonized and comprehensive framework for managing digital risks across the financial sector.1 DORA, which becomes fully applicable on January 17, 2025, extends its reach to over 22,000 financial entities and their critical ICT service providers.2

While extensive research has demonstrated that mature Enterprise Risk Management (ERM) frameworks can reduce a firm’s cost of capital and enhance firm value,3 the specific impact of a mandatory, domain-specific regulatory intervention like DORA remains underexplored. This paper addresses this research gap by proposing a framework to analyze the effects of DORA on ERM maturity, cost of capital, and investment efficiency within EU financial institutions. The study’s objectives are threefold: first, to assess how DORA’s requirements are likely to influence the ERM maturity of regulated entities; second, to investigate the consequential effects on their cost of capital and capital allocation decisions; and third, to contextualize these impacts through a comparative analysis of the operational resilience regimes in the UK and the US.

By examining the anticipation and compliance effects of DORA, this research aims to provide crucial insights for financial institutions, regulators, and investors into how regulatory-driven enhancements in digital operational resilience can translate into tangible economic benefits and contribute to broader financial stability.

Literature review

This study is grounded in three distinct but interconnected streams of literature: the economic benefits of ERM, the relationship between information quality and investment efficiency, and the evolving landscape of operational resilience regulation.

A foundational concept of this paper is that mature ERM practices create economic value. A significant empirical study of the U.S. insurance industry by Berry-Stölzle and Xu found that the adoption of ERM is associated with a 1.999% lower cost of equity capital.3 This reduction in the cost of capital was identified as a primary driver of the increase in firm value observed in ERM-adopting firms, demonstrating a clear financial incentive for robust risk management beyond mere compliance.3

The second stream of literature connects the quality of a firm’s information environment to its capital allocation decisions. Biddle, Hilary, and Verdi established that higher financial reporting quality improves investment efficiency by reducing both over-investment and under-investment.4 For firms prone to over-investing, better reporting imposes discipline, whereas for firms prone to under-investing, it reduces information asymmetry and improves access to external capital.4 This relationship has been corroborated across various markets, including private firms in emerging economies and publicly listed firms globally, confirming that a transparent information environment is critical for efficient capital allocation.5,6,7 DORA, by mandating detailed ICT risk management frameworks and disclosures, effectively enhances the quality of risk reporting, thereby providing a theoretical channel through which it can influence investment efficiency.

Finally, the regulatory landscape for operational resilience has fragmented globally, creating complexity for international firms.8 The UK’s regime, effective March 2022, is principles-based, requiring firms to identify “important business services” and set “impact tolerances” for disruption.9 The US employs a sector-specific approach focused on mitigating systemic risk to financial stability, rather than harm to individual clients.9

DORA distinguishes itself through its specific focus on digital and ICT risk, its prescriptive nature, and, most notably, its creation of a Union-level oversight framework for designated critical ICT third-party providers (CTPPs), regardless of their headquarters.1,10 This direct supervision of non-financial firms is a significant departure from the UK and US models, which manage third-party risk primarily through guidance for the regulated financial entities themselves.10 These differing approaches—from the UK’s broad, principles-based framework to the US’s systemic-risk focus and the EU’s prescriptive, ICT-centric model—provide a crucial context for analyzing the unique potential impacts of DORA.11

Methodology

This paper outlines an analytical framework to investigate the impact of DORA on ERM maturity, cost of capital, and investment efficiency. The research design is centered on an event study methodology, utilizing two distinct event windows to capture both market anticipation and observable compliance effects.

Research design and sample

To analyze market anticipation effects, the primary event is the publication of the DORA proposal on September 24, 2020.1 The ‘pre’ period is defined as January 1, 2019, to September 23, 2020, providing a baseline before the regulation’s details were public. The ‘post’ period spans from September 24, 2020, to January 16, 2025, covering the phase when firms actively prepared for compliance. To analyze observable compliance and operational effects, the key event is the full application date of January 17, 2025.1 The ‘post’ period for this analysis will commence from this date, allowing for the examination of empirical data on compliance costs, incident reporting, and supervisory actions.

The primary sample comprises the wide range of EU financial entities covered by DORA, including credit institutions, investment firms, insurance undertakings, crypto-asset service providers, and critical ICT third-party service providers.2 For comparative purposes, corresponding samples of financial institutions from the UK and the US will be analyzed to isolate the effects of their respective regulatory regimes.

Measurement of key variables

This section outlines the core variables that will be analyzed to assess the impact of DORA on financial institutions. It details the metrics for ERM maturity, cost of capital, and investment efficiency, and explains how these will be operationalized for empirical testing.

Erm maturity

A composite measure will be employed to capture ERM maturity robustly. This measure will consist of two components: 1) A disclosure score developed through content analysis of annual reports to quantify the depth and breadth of risk management discussions. 2) Binary indicators for key governance characteristics, specifically the presence of a dedicated Chief Risk Officer (CRO) and a board-level risk committee, signifying a structural commitment to risk oversight.

Investment efficiency

Investment efficiency will be assessed using the model developed by Biddle, Hilary, and Verdi (2009), which is supported by the provided research.4 This model serves as a standard for evaluating how efficiently firms allocate capital by measuring deviations from expected investment levels based on growth opportunities. This framework allows for the crucial distinction between over-investment and under-investment, which is directly linked to the quality of a firm’s financial reporting environment.4

Cost of capital

The cost of capital will be estimated using standard asset pricing models. The analysis will test for a statistically significant reduction in the cost of capital for firms in the post-DORA periods, consistent with the findings of prior research on the value of ERM adoption.3

Findings and analysis

Based on the outlined methodology and existing literature, this section presents an analysis of the anticipated effects of DORA on financial institutions.

Impact on ERM maturity

DORA’s prescriptive nature is expected to directly and significantly increase the ERM maturity of EU financial entities, particularly in the domain of digital resilience. The regulation mandates that the management body is personally and ultimately responsible for the firm’s ICT risk management framework, including the allocation of sufficient investment and training budgets.12,13 This top-down accountability is likely to drive the formalization of governance structures, such as dedicated risk committees. Furthermore, DORA requires firms to implement a comprehensive ICT risk management framework, perform resilience testing, and conduct detailed ICT concentration risk assessments.14 A key innovation of DORA is the establishment of a Union Oversight Framework, which grants European Supervisory Authorities (ESAs) direct supervisory power over CTPPs, including the ability to conduct investigations and impose penalties.10,15 This stringent approach to third-party risk forces a maturation of risk management practices that extends beyond the firm’s own boundaries.

Anticipated effect on cost of capital

The forced maturation of ERM driven by DORA is hypothesized to lower the cost of capital for compliant firms. By standardizing and enhancing digital risk management and disclosure, DORA reduces information asymmetry and lowers the perceived risk profile of financial institutions. Investors, having greater visibility into a firm’s operational resilience and ICT risk posture, are likely to demand a lower risk premium. This effect aligns with established findings that link voluntary ERM adoption to a reduced cost of equity capital.3 The mandatory nature of DORA is expected to broaden this effect across the entire EU financial sector.

Anticipated effect on investment efficiency

DORA’s requirements are expected to improve investment efficiency by enhancing the quality of risk-related information available to decision-makers. The regulation’s emphasis on identifying critical functions, assessing concentration risk, and analyzing the cost-benefit of alternative ICT solutions provides a structured framework for capital allocation.14 This improved information environment, analogous to higher financial reporting quality, should help mitigate capital misallocation.4 It can reduce over-investment in redundant or non-critical technologies while preventing under-investment in essential cybersecurity and resilience capabilities, which could otherwise be neglected due to a lack of clear accountability or risk visibility.

Discussion

The implementation of DORA represents a significant regulatory intervention designed to fortify the digital backbone of the EU financial system. Our analysis suggests that while the primary goal is enhancing resilience, the regulation will likely trigger secondary economic benefits through improved ERM, a lower cost of capital, and more efficient investment. DORA acts as an external catalyst, compelling a level of digital risk management maturity that may not have been achieved through voluntary, market-driven initiatives alone.

Theoretical and practical implications

Theoretically, this study extends the literature by examining the impact of a mandatory, domain-specific regulatory shock on the established relationships between ERM, cost of capital, and investment efficiency. It shifts the focus from the effects of voluntary ERM adoption to the consequences of regulatory compulsion in the critical area of ICT risk.

Practically, the implications are profound. Financial institutions face significant implementation costs and challenges, particularly smaller entities and non-EU service providers who may struggle with the regulation’s complexity and resource demands.2,16 For critical ICT providers, DORA introduces a new layer of direct supervision, with non-compliance carrying the risk of substantial financial penalties, including up to 1% of average daily global turnover.13 However, the long-term benefits may justify these costs. A lower cost of capital and more efficient deployment of resources can enhance competitiveness and profitability, while the entire financial system benefits from greater stability.

Limitations and counter-findings

This analysis is primarily anticipatory, as empirical data on DORA’s full impact will only become available after January 2025. A key limitation is the potential for high compliance costs to erode or even outweigh the financial benefits, especially in the short term. The ambiguity of certain requirements could lead to inefficient spending as firms navigate the new regulatory terrain.16 Furthermore, while firms may seek to mitigate concentration risk through strategies like multi-cloud, these approaches introduce their own challenges, including increased operational complexity and costs, which may explain a recent trend of firms reducing their number of cloud providers.17 These factors represent important counterarguments to a purely optimistic view of DORA’s economic consequences and warrant careful empirical investigation in future research.

Conclusion

The Digital Operational Resilience Act represents a transformative milestone in the regulation of information and communication technology risk within the European Union’s financial sector. By mandating a higher standard of enterprise risk management, particularly in the areas of ICT resilience and third-party oversight, DORA is expected to deliver more than regulatory compliance. It is likely to strengthen governance structures, enhance transparency, and reduce information asymmetries, which in turn can lower the cost of capital and improve investment efficiency across financial institutions.

While the immediate costs of implementation may weigh heavily on smaller entities and non-EU service providers, the long-term benefits of improved resilience, more efficient capital allocation, and greater systemic stability outweigh these challenges. Importantly, DORA shifts ERM maturity from being largely voluntary to becoming a regulated necessity, ensuring consistency across the sector. This regulatory shock not only raises the bar for operational resilience but also sets a precedent for how financial regulation can generate broader economic value.

Future research should empirically test these hypotheses in the post-implementation period, providing evidence on the trade-offs between compliance costs and efficiency gains. Such findings will be crucial for regulators, policymakers, and financial institutions seeking to strike the right balance between resilience and competitiveness in an increasingly digital financial ecosystem.

RELEVANT TAGS:

REFERENCES AND NOTES

  1. ExtraHop. (2024, October 29). DORA regulation: Digital Operational Resilience Act. ExtraHop. https://www.extrahop.com/blog/dora-regulation-digital-operational-resilience-act
  2. Tanguy, C. (2025, March 3). Understanding the DORA regulation: Europe’s strategy for a more digitally resilient financial sector. Deepki. https://www.deepki.com/blog/dora-regulation-resilient-financial-sector/
  3. Berry-Stölzle, T. R., & Xu, J. (2016). Enterprise risk management and the cost of capital. Journal of Risk and Insurance, 85(3), 579–616. https://doi.org/10.1111/jori.12152
  4. Biddle, G. C., Hilary, G., & Verdi, R. S. (2009). How does financial reporting quality relate to investment efficiency? Journal of Accounting and Economics, 48(2–3), 112–131. https://doi.org/10.1016/j.jacceco.2009.09.001
  5. Chen, F., Hope, O.-K., Li, Q., & Wang, X. (2011). Financial reporting quality and investment efficiency of private firms in emerging markets. The Accounting Review, 86(4), 1255–1288. https://doi.org/10.2308/accr-10040
  6. Khan, M. A., Safdar, N., & Manzoor, W. (2024). Financial reporting quality and investment efficiency: A transnational evidence. Pakistan Journal of Commerce and Social Sciences, 18(2), 285–305. https://doi.org/10.64534/Commer.2024.041
  7. Le, H. T. M., Lai, C.-P., Phan, V. H., & Pham, V. T. (2024). Financial reporting quality and investment efficiency in manufacturing firms: The role of firm characteristics in an emerging market. Journal of Competitiveness, 16(2), 95–112. https://www.cjournal.cz/files/518.pdf
  8. Boer, M., & Rismanchi, K. (2024, December). Operational resilience: A brief history and the road ahead (IIF Staff Paper). Institute of International Finance. https://www.iif.com/portals/0/Files/content/Regulatory/32370132_iif_staff_paper_operational_resilience_december_2024_final.pdf
  9. Rogers, J., Zappasodi, A., & Cook, R. (2022, December 1). Operational resilience in the UK, EU and US: A comparison. White & Case LLP. https://www.whitecase.com/insight-our-thinking/financial-regulatory-observer-2022-operational-resilience-uk-eu-and-us
  10. PricewaterhouseCoopers. (2021, April). Comparing international expectations on operational resilience. https://www.pwc.co.uk/financial-services/assets/pdf/comparing-international-expectations-on-operational-resilience.pdf
  11. Barling, S. J., Kumayama, K. D., Simon, D. A., Kerr-Shaw, N., & Werry, S. (2024, July 18). The EU’s Digital Operational Resilience Act (DORA) – 2024 update. Skadden, Arps, Slate, Meagher & Flom LLP. https://www.skadden.com/insights/publications/2024/07/the-eus-digital-operational-resilience-act
  12. Reimer, R., & Doser, A. (2024, February 8). DORA – New digital operational resilience rules for the EU’s financial sector. Hogan Lovells. https://www.hoganlovells.com/en/publications/dora-new-digital-operational-resilience-rules-for-the-eus-financial-sector
  13. Bouaissi, K. (2023, March 15). How will DORA impact the financial sector? https://www.ey.com/en_lu/insights/wealth-asset-management/how-will-dora-impact-the-financial-sector
  14. Zergenyi, R., Bachmann, M., Tikhonov, T., Marigo, S., Benigni, S., Vidal, G. M., & Schreihans, G. (2024, September). Impact of the Digital Operational Resilience Act on the internal audit function. European Confederation of Institutes of Internal Auditing (ECIIA) & Institut Français de l’Audit et du Contrôle Internes (IFACI). https://www.ifaci.com/wp-content/uploads/2024/11/DORA-2024-Paper.pdf
  15. European Supervisory Authorities. (2025, July 15). JC 2025 29: Guide on DORA oversight activities. European Securities and Markets Authority. https://www.esma.europa.eu/sites/default/files/2025-07/JC_2025_29__DORA_Guide_on_oversight_activities.pdf
  16. McKinsey & Company. (2024, June 28). Europe’s new resilience regime: The race to get ready for DORA. https://www.mckinsey.com/capabilities/risk-and-resilience/our-insights/europes-new-resilience-regime-the-race-to-get-ready-for-dora
  17. Koh, T. Y., & Prenio, J. (2023, November). Managing cloud risk: Some considerations for the oversight of third-party providers. Bank for International Settlements. https://www.bis.org/fsi/publ/insights53.pdf

Latest Research

Home » ERM Maturity, Cost of Capital, and Investment Efficiency: Pre- and Post-DORA Evidence
© Hampton Global 2026.
Join our newsletter
Stay up to date on latest stories