DORA
Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
DORA Chapter II: ICT Risk Management
Financial entities shall have mechanisms to promptly detect anomalous activities, ICT network performance issues and ICT-related incidents, with multiple layers of control, defined alert thresholds and detection processes that enable timely incident response.
- Anomaly/incident detection mechanisms with defined alert thresholds
- Monitoring coverage records
- No anomaly detection or alerting
Financial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.
- ICT business continuity policy + response/recovery plans
- Records of plan testing
- No ICT continuity/response/recovery plans
- Plans untested
Financial entities shall develop and document backup policies and procedures, and restoration and recovery procedures and methods, ensuring backups can be restored with minimal disruption, with backup systems physically and logically segregated from the source system.
- Backup and restoration policies/procedures
- Evidence of segregated backups and restoration tests
- No tested backups
- Backups not segregated from source
Financial entities shall gather information on vulnerabilities, cyber threats and ICT-related incidents, conduct post-incident reviews, and continuously evolve the ICT risk management framework, ICT security awareness programmes and digital operational resilience training.
- Post-incident review records and lessons-learned actions
- ICT security awareness and resilience training
- No post-incident learning
- No security awareness/training programme
Financial entities shall have crisis communication plans enabling responsible disclosure of major ICT-related incidents or vulnerabilities to clients, counterparts and the public as appropriate, and designate communication policies for internal staff and external stakeholders.
- Crisis communication plan for major ICT incidents
- No crisis communication plan
Specified smaller and non-interconnected financial entities are subject to a simplified ICT risk management framework with proportionate requirements (sound systems, monitoring, business continuity, incident handling and testing).
- For eligible entities: a simplified ICT risk framework meeting the Article 16 elements
- Misapplying the simplified regime to ineligible entities
The management body of the financial entity shall define, approve, oversee and be responsible for the implementation of the ICT risk management framework, bear ultimate responsibility for managing ICT risk, set roles and responsibilities, approve the digital operational resilience strategy, and allocate appropriate budget and training.
- Board-approved ICT risk management framework and digital operational resilience strategy
- Records of management-body oversight and ICT training
- No management-body ownership of ICT risk
- No board-approved resilience strategy
Financial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system, enabling them to address ICT risk quickly, efficiently and comprehensively, reviewed at least annually and audited periodically by ICT-audit staff.
- Documented ICT risk management framework reviewed at least annually
- ICT audit plan and reports
- No documented ICT risk framework
- Framework not reviewed/audited
Financial entities shall use and maintain ICT systems, protocols and tools that are appropriate to the scale of operations, reliable, with sufficient capacity, and technologically resilient to handle additional information-processing needs under stressed conditions.
- Inventory of ICT systems/tools with capacity and resilience assessment
- Outdated/unsupported ICT systems without resilience assessment
Financial entities shall identify, classify and adequately document all ICT-supported business functions, roles and responsibilities, the information assets and ICT assets supporting them, and their interdependencies, and identify all sources of ICT risk on a continuous basis.
- Inventory/classification of ICT-supported functions and ICT assets + interdependencies
- Continuous ICT risk identification records
- Incomplete asset/function inventory
- No mapping of dependencies
Financial entities shall continuously monitor and control the security and functioning of ICT systems and tools, and minimise ICT risk through appropriate ICT security policies, procedures, protocols and tools ensuring resilience, continuity and availability, and preserving confidentiality, integrity and authenticity of data (incl access management, encryption, secure configuration, network security).
- ICT security policies and protective controls (access, encryption, configuration, network)
- Evidence preserving CIA of data
- Weak or absent protective controls
- No encryption/access management
DORA Chapter III: ICT-Related Incident Management
Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents, including early warning indicators, procedures to identify/track/log/categorise incidents by priority and severity, roles and responsibilities, and communication plans.
- Documented ICT incident management process with logging, categorisation and roles
- No structured incident management process
Financial entities shall classify ICT-related incidents and determine their impact based on criteria including the number/relevance of clients and transactions affected, geographical spread, data losses, criticality of services affected, and economic impact; and classify significant cyber threats.
- Incident classification methodology aligned to the DORA criteria/RTS thresholds
- No incident classification against the prescribed criteria
Financial entities shall report major ICT-related incidents to the relevant competent authority within the prescribed timelines using initial, intermediate and final notifications, and may notify significant cyber threats on a voluntary basis.
- Major-incident reports (initial/intermediate/final) submitted to the competent authority within the deadlines
- Late or missing major-incident reporting
The incident management and reporting requirements also apply to operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers and electronic money institutions.
- Payment-incident handling and reporting consistent with the ICT incident process
- Payment-related incidents excluded from the incident process
DORA Chapter IV: Digital Operational Resilience Testing
Financial entities shall establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the ICT risk management framework, following a risk-based approach.
- A documented digital operational resilience testing programme
- No resilience testing programme
The testing programme shall include a range of assessments and tests (e.g. vulnerability assessments and scans, open-source analyses, network security assessments, gap analyses, physical security reviews, questionnaires, source-code reviews, scenario-based tests, compatibility/performance tests, end-to-end and penetration testing), with critical ICT systems tested at least yearly.
- Test plans and results across the required assessment types
- At least-yearly testing of critical ICT systems
- Critical systems not tested annually
- Narrow test coverage
Financial entities identified as significant shall carry out, at least every three years, threat-led penetration testing (TLPT) on live production systems covering critical or important functions, performed by qualified internal or external testers.
- TLPT scope, threat intelligence, and test reports (at least three-yearly for in-scope entities)
- TLPT attestation
- In-scope entity not performing TLPT
- TLPT not covering critical functions
Financial entities shall use only testers for TLPT that meet requirements on suitability, reputation, technical and organisational capabilities, and (for external testers) certification and professional indemnity insurance.
- Evidence that TLPT testers meet the Article 27 suitability/insurance requirements
- Using testers not meeting the requirements
DORA Chapter V: ICT Third-Party Risk Management
Financial entities shall manage ICT third-party risk as an integral component of ICT risk, maintain a Register of Information on all contractual arrangements for the use of ICT services, report it to competent authorities, assess risk before entering arrangements (including concentration and subcontracting), and adopt an ICT third-party risk strategy.
- A Register of Information of ICT third-party arrangements reported to the competent authority
- Pre-contract risk assessment records
- No Register of Information
- No pre-contract third-party risk assessment
When assessing ICT third-party arrangements supporting critical or important functions, financial entities shall assess ICT concentration risk, including the risks of contracting providers that are not easily substitutable or of multiple arrangements with the same or closely connected providers, and the implications of subcontracting.
- ICT concentration-risk assessment for critical/important-function arrangements
- Concentration risk not assessed
Contractual arrangements for the use of ICT services shall include the mandatory key contractual provisions (e.g. clear service descriptions, locations of data processing, data protection, accessibility/availability/integrity/security, assistance on incidents, audit and access rights, termination rights and exit strategies), with enhanced provisions for services supporting critical or important functions.
- ICT contracts containing the mandatory key provisions (audit/access, termination, exit, security)
- Enhanced provisions for critical/important-function services
- Contracts missing audit/access, termination or exit provisions
The European Supervisory Authorities designate critical ICT third-party service providers, which become subject to the Union Oversight Framework led by a Lead Overseer; financial entities shall account for the use of such providers in their third-party risk management.
- Identification of any critical ICT third-party providers used and their oversight status
- No awareness of critical-TPP designations affecting the entity
DORA Chapters VI-VII: Information Sharing, Penalties and Data Protection
Financial entities may exchange amongst themselves cyber threat information and intelligence (indicators of compromise, tactics, techniques and procedures, alerts and tools) within trusted communities, under arrangements that protect the sensitivity of the information and comply with data protection law.
- Participation in threat-information-sharing arrangements (where adopted) with protective and data-protection safeguards
- Sharing threat information without appropriate safeguards
Competent authorities shall have the power to impose effective, proportionate and dissuasive administrative penalties and remedial measures for breaches of the Regulation; financial entities should be prepared to evidence compliance and remediate findings.
- Readiness to evidence DORA compliance and to remediate supervisory findings
- No process to respond to supervisory findings/penalties
The processing of personal data under the Regulation shall be carried out in accordance with Regulation (EU) 2016/679 and other applicable Union data protection law, with processing limited to what is necessary to comply with the obligations under DORA.
- GDPR-compliant handling of personal data processed for DORA purposes
- Processing personal data beyond what DORA compliance requires
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the DORA framework page.