MiFID II: the seven questions an auditor asks first
Before asking for recordings, the regulator tests whether you can find them, evidence them and retain them. A guide to the questions that decide…
Read article →DORA
Since January 2025, operational resilience is a regulatory outcome, not a document. What that demands of every capture pipeline.

For years, the disaster recovery plan lived inside a document. It was updated once a year, validated with a signature and filed in a repository few people opened. DORA, Regulation (EU) 2022/2554 on Digital Operational Resilience, applicable since 17 January 2025, made that model obsolete. Resilience stopped being a document and became a demonstrable outcome, measured in concrete numbers and tested regularly. For an archive of recordings, that changes everything upstream: resilience has to exist in every capture pipeline, not at the end of the chain.
The essential difference DORA introduces is one of nature. A classic DR plan described an intention: «in the event of an incident, we will restore critical systems». DORA requires that intention to be converted into quantified objectives, assigned to specific functions and validated in practice. The question the supervisor asks is no longer «do you have a plan?», but «what is your RPO and RTO for this function, and when did you last test it?».
Two indicators structure the entire resilience conversation:
For compliance recordings, the RPO carries particular weight. An interaction that was not captured cannot be recovered, there is no alternative copy of a call that was never recorded. The loss is permanent and, if that call was subject to a retention obligation, it is also a regulatory failure. That is why the RPO of a capture pipeline is not a number chosen for operational convenience: it is a limit on legal exposure.
A generic DR plan answers the question «what do we do when something fails?». Resilience by design answers an earlier and more demanding question: «what keeps working even while something is failing?».
The most common mistake is to define a single RPO and RTO for «the recording system». In reality, a modern archive brings together several capture pipelines, trading voice, corporate telephony, Microsoft Teams, messaging channels, email, and each has a different risk profile. Trading voice may justify an RPO close to zero, with redundant capture; a low-risk internal channel tolerates more relaxed objectives. DORA rewards that granularity, because it shows the organisation understands its own critical dependencies.
DORA requires a regular digital operational resilience testing programme, and for the most significant entities it provides for advanced threat-led testing. For an archive, this translates into concrete exercises: simulate the failure of a capture node and measure whether failover respects the declared RPO; restore the archive from a copy and time the real RTO; verify that no interaction was silently lost during recovery. An RPO that has never been tested is a hypothesis, not a control.
DORA devotes an entire chapter to ICT third-party risk. If the recordings archive depends on an external provider, for hosting, capture or storage, that provider’s resilience objectives become part of the institution’s own. The management body is directly responsible for ensuring that contracts reflect RPO and RTO compatible with critical functions, and that a testable exit strategy exists. Resilience is not outsourced: it is inherited.
It is also worth separating resilience from a simple backup. A copy protects against permanent loss, but says nothing about recovery time or about continuity of capture during the incident. DORA asks for more than the ability to restore: it asks that critical functions hold, or return within a known time, even under failure. For an archive of recordings, that means redundancy in capture itself, because data that was not captured at the moment exists in no copy at all, and not only in downstream storage.
The end of the generic DR plan is not the end of planning. It is planning maturing: from an annual document into a continuous, measured property of every capture pipeline. Anyone who can say, for each stream of recordings, what the RPO is, what the RTO is and when they were last tested, is answering DORA in the language it demands.
Published by the uPlayback team, a Grupês product. Three decades of experience in compliance recording.
Continue reading
MiFID II Before asking for recordings, the regulator tests whether you can find them, evidence them and retain them. A guide to the questions that decide…
Read article →
Sovereignty Where your recordings live has stopped being a technical decision. It is a decision about legal exposure, and it belongs to the board.
Read article →
Platform Compliance fails at the seams. A single governed archive is what makes a compliance project achievable.
Read article →Compliance, integrations and deployment answered live, with your questions on the table and no generic pitch.