DORA

DORA in practice: RPO, RTO and the end of the generic DR plan

Since January 2025, operational resilience is a regulatory outcome, not a document. What that demands of every capture pipeline.

DORA in practice: RPO, RTO and the end of the generic DR plan

For years, the disaster recovery plan lived inside a document. It was updated once a year, validated with a signature and filed in a repository few people opened. DORA, Regulation (EU) 2022/2554 on Digital Operational Resilience, applicable since 17 January 2025, made that model obsolete. Resilience stopped being a document and became a demonstrable outcome, measured in concrete numbers and tested regularly. For an archive of recordings, that changes everything upstream: resilience has to exist in every capture pipeline, not at the end of the chain.

What changes when resilience becomes a measurable outcome?

The essential difference DORA introduces is one of nature. A classic DR plan described an intention: «in the event of an incident, we will restore critical systems». DORA requires that intention to be converted into quantified objectives, assigned to specific functions and validated in practice. The question the supervisor asks is no longer «do you have a plan?», but «what is your RPO and RTO for this function, and when did you last test it?».

What are RPO and RTO in practice?

Two indicators structure the entire resilience conversation:

  • RPO (Recovery Point Objective): how much data can be lost, measured in time. An RPO of five minutes means that, in the worst case, you lose the interactions from the five minutes before the incident.
  • RTO (Recovery Time Objective): how long before the function is operational again. An RTO of one hour means the archive has to be accessible, and capturing, within sixty minutes.

For compliance recordings, the RPO carries particular weight. An interaction that was not captured cannot be recovered, there is no alternative copy of a call that was never recorded. The loss is permanent and, if that call was subject to a retention obligation, it is also a regulatory failure. That is why the RPO of a capture pipeline is not a number chosen for operational convenience: it is a limit on legal exposure.

A generic DR plan answers the question «what do we do when something fails?». Resilience by design answers an earlier and more demanding question: «what keeps working even while something is failing?».

Why is resilience measured per pipeline rather than per system?

The most common mistake is to define a single RPO and RTO for «the recording system». In reality, a modern archive brings together several capture pipelines, trading voice, corporate telephony, Microsoft Teams, messaging channels, email, and each has a different risk profile. Trading voice may justify an RPO close to zero, with redundant capture; a low-risk internal channel tolerates more relaxed objectives. DORA rewards that granularity, because it shows the organisation understands its own critical dependencies.

Is testing mandatory or optional?

DORA requires a regular digital operational resilience testing programme, and for the most significant entities it provides for advanced threat-led testing. For an archive, this translates into concrete exercises: simulate the failure of a capture node and measure whether failover respects the declared RPO; restore the archive from a copy and time the real RTO; verify that no interaction was silently lost during recovery. An RPO that has never been tested is a hypothesis, not a control.

Where do third-party providers fit in?

DORA devotes an entire chapter to ICT third-party risk. If the recordings archive depends on an external provider, for hosting, capture or storage, that provider’s resilience objectives become part of the institution’s own. The management body is directly responsible for ensuring that contracts reflect RPO and RTO compatible with critical functions, and that a testable exit strategy exists. Resilience is not outsourced: it is inherited.

It is also worth separating resilience from a simple backup. A copy protects against permanent loss, but says nothing about recovery time or about continuity of capture during the incident. DORA asks for more than the ability to restore: it asks that critical functions hold, or return within a known time, even under failure. For an archive of recordings, that means redundancy in capture itself, because data that was not captured at the moment exists in no copy at all, and not only in downstream storage.

The end of the generic DR plan is not the end of planning. It is planning maturing: from an annual document into a continuous, measured property of every capture pipeline. Anyone who can say, for each stream of recordings, what the RPO is, what the RTO is and when they were last tested, is answering DORA in the language it demands.

Published by the uPlayback team, a Grupês product. Three decades of experience in compliance recording.

Continue reading

More from our blog.

MiFID II: the seven questions an auditor asks first MiFID II

MiFID II: the seven questions an auditor asks first

Before asking for recordings, the regulator tests whether you can find them, evidence them and retain them. A guide to the questions that decide…

Read article →
Digital sovereignty: why the Cloud Act changes your architecture Sovereignty

Digital sovereignty: why the Cloud Act changes your architecture

Where your recordings live has stopped being a technical decision. It is a decision about legal exposure, and it belongs to the board.

Read article →
Voice, chat and email: why three systems are a risk Platform

Voice, chat and email: why three systems are a risk

Compliance fails at the seams. A single governed archive is what makes a compliance project achievable.

Read article →

Ready when you are.

Compliance, integrations and deployment answered live, with your questions on the table and no generic pitch.

Book a Demo Take the assessment