The question at hand
Your compliance team monitors DORA, the EU AI Act, NIS2, and UK-specific guidance from the FCA and PRA. Each framework generates technical standards, supervisory Q&As, and enforcement notices at different intervals. You're tracking obligations across all of them, currently using spreadsheets, shared inboxes, and email threads.
The question: Do you invest in compliance automation now, or continue managing regulatory obligations manually until the workload becomes unmanageable?
This isn't theoretical. On 17 January 2025, DORA entered into application. High-risk AI system obligations under Annex III of the EU AI Act apply from 2 December 2027. Between now and then, your team will handle overlapping deadlines, conflicting guidance updates, and obligations that span multiple frameworks. The argument for automation centers on whether your current process can scale to meet that volume without dropping obligations. The argument against it questions whether the cost and disruption of implementation outweigh the risk of staying manual.
The case for automating now
Compliance teams that waited until DORA's application date to build their tracking infrastructure spent the first quarter of 2025 catching up. Those who managed it well had already mapped obligations to specific articles, assigned named owners, and built audit trails before the deadline.
Manual processes break at predictable points: horizon scanning, obligation mapping, and evidence collection. Regulatory updates land in a shared inbox. Someone reads them, decides which obligations they affect, and emails the relevant owners. Evidence of completion ends up in a folder. When an EBA Q&A clarifies Article 30 of DORA after your initial assessment, nobody updates the spreadsheet automatically. You rely on someone noticing the clarification, determining which provider assessments it affects, and manually cascading the change.
That process holds at low volume. It fails when one quarter brings DORA technical standards, revised AI Act guidance, an FCA operational resilience consultation, and updated NIS2 transposition from multiple member states. Obligations sit without owners. Evidence gaps surface weeks before a supervisory review.
Automation addresses this by treating regulatory updates as structured data, not inbox items. When the EBA publishes guidance affecting Article 30, an automated workflow flags every obligation record tied to that provision, assigns tasks to the relevant owners, and updates the audit trail when they close the task. The record stays current without manual handling.
The financial risk supports the case. The EU AI Act allows penalties of up to €15 million or 3% of global annual turnover for failing to meet high-risk system requirements. If your AI-driven credit decisioning system qualifies as both a high-risk AI system under the AI Act and an ICT third-party service under DORA, you're managing overlapping obligations across two frameworks. Missing one because it wasn't logged correctly isn't a process failure your regulator will excuse.
The case for staying manual
Automation vendors promise efficiency, but implementation is disruptive. You're asking your compliance team to change how they work while managing existing obligations. The transition period introduces its own risks: dual-running systems, incomplete data migration, and staff reverting to spreadsheets because the new platform doesn't match their workflow.
The judgment involved in compliance work doesn't automate easily. Whether an ICO enforcement notice changes your risk position under UK GDPR, whether an updated AI use case shifts its classification under Annex III, whether an EBA Q&A affects your existing DORA assessment: these are analytical questions requiring domain expertise, not workflow automation. Automation handles routing, tracking, and audit trails. That's valuable, but it's not the hard part.
Manual processes also have advantages that get overlooked in the automation pitch. Your team knows exactly where everything is. The spreadsheet might not update automatically, but it also doesn't break when a vendor pushes a software update. You're not dependent on a third-party platform's interpretation of regulatory frameworks, and you're not paying annual license fees that scale with user count.
For smaller compliance teams, the cost-benefit calculation often doesn't close. If you're managing 15 ICT providers under DORA and monitoring three regulatory regimes, the manual overhead is real but manageable. The break-even point for automation comes when the volume of obligations exceeds what your team can track reliably without dropping items. Until you hit that threshold, you're paying for capacity you don't need.
Where practitioners actually land
Most compliance teams don't choose between full automation and pure manual processes. They automate the parts that break first and keep manual control over the parts that require judgment.
The pattern that works: automate horizon scanning and obligation assignment, keep manual control over evidence assessment and risk classification. Let the platform flag when the EBA publishes new guidance, route it to the right owner, and track the response. But don't let it decide whether that guidance changes your risk position or how you document your assessment. That stays with your compliance team.
Teams that handled DORA well typically started with obligation mapping six to nine months before the application date. They built a granular record of every requirement, assigned owners, and established clear accountability. Some did this in spreadsheets, some used purpose-built platforms. What mattered wasn't the tool, it was the discipline of mapping obligations to specific provisions and tracking them to closure.
The teams struggling now are the ones that treated DORA as a reading exercise rather than an implementation project. They read the regulation, understood the requirements, and assumed tracking would follow naturally. It didn't.
Our take
If your compliance program is managing DORA, the EU AI Act, NIS2, and UK-specific requirements with spreadsheets and shared inboxes, you're running a process that will fail under load. The question isn't whether to automate, it's when.
Automate now if you're already dropping obligations, if evidence collection takes longer than the work it documents, or if your team spends more time searching for records than analyzing regulatory updates. Don't automate if your current volume is manageable, if your team lacks the capacity to implement a new platform while managing existing obligations, or if you haven't yet mapped your obligations at a granular level.
The worst outcome is buying automation as a substitute for process discipline. Platforms don't fix unclear accountability or poorly defined obligations. They make those problems faster and more expensive.
Start with a process diagnosis. Identify where your manual workflow breaks: Is it horizon scanning? Obligation assignment? Evidence collection? Map your obligations to specific regulatory provisions, assign named owners, and build audit trails that connect evidence to requirements. If you can't do that manually, you can't do it with automation either.
The deadline for high-risk AI systems under Annex III is 2 December 2027. If your current tracking method can't tell you which obligations apply to which systems, or if finding that answer requires searching through folders and email threads, you won't catch the failure before your regulator does.


