Skip to content

Evidence request lists

DORA

Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

DORA Chapter II: ICT Risk Management

DORA-Art.10
Detection

Financial entities shall have mechanisms to promptly detect anomalous activities, ICT network performance issues and ICT-related incidents, with multiple layers of control, defined alert thresholds and detection processes that enable timely incident response.

Artefacts an auditor will ask for
  • Anomaly/incident detection mechanisms with defined alert thresholds
  • Monitoring coverage records
Where this commonly fails
  • No anomaly detection or alerting
DORA-Art.11
Response and recovery

Financial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.

Artefacts an auditor will ask for
  • ICT business continuity policy + response/recovery plans
  • Records of plan testing
Where this commonly fails
  • No ICT continuity/response/recovery plans
  • Plans untested
DORA-Art.12
Backup policies and procedures, restoration and recovery

Financial entities shall develop and document backup policies and procedures, and restoration and recovery procedures and methods, ensuring backups can be restored with minimal disruption, with backup systems physically and logically segregated from the source system.

Artefacts an auditor will ask for
  • Backup and restoration policies/procedures
  • Evidence of segregated backups and restoration tests
Where this commonly fails
  • No tested backups
  • Backups not segregated from source
DORA-Art.13
Learning and evolving

Financial entities shall gather information on vulnerabilities, cyber threats and ICT-related incidents, conduct post-incident reviews, and continuously evolve the ICT risk management framework, ICT security awareness programmes and digital operational resilience training.

Artefacts an auditor will ask for
  • Post-incident review records and lessons-learned actions
  • ICT security awareness and resilience training
Where this commonly fails
  • No post-incident learning
  • No security awareness/training programme
DORA-Art.14
Communication

Financial entities shall have crisis communication plans enabling responsible disclosure of major ICT-related incidents or vulnerabilities to clients, counterparts and the public as appropriate, and designate communication policies for internal staff and external stakeholders.

Artefacts an auditor will ask for
  • Crisis communication plan for major ICT incidents
Where this commonly fails
  • No crisis communication plan
DORA-Art.16
Simplified ICT risk management framework

Specified smaller and non-interconnected financial entities are subject to a simplified ICT risk management framework with proportionate requirements (sound systems, monitoring, business continuity, incident handling and testing).

Artefacts an auditor will ask for
  • For eligible entities: a simplified ICT risk framework meeting the Article 16 elements
Where this commonly fails
  • Misapplying the simplified regime to ineligible entities
DORA-Art.5
Governance and organisation

The management body of the financial entity shall define, approve, oversee and be responsible for the implementation of the ICT risk management framework, bear ultimate responsibility for managing ICT risk, set roles and responsibilities, approve the digital operational resilience strategy, and allocate appropriate budget and training.

Artefacts an auditor will ask for
  • Board-approved ICT risk management framework and digital operational resilience strategy
  • Records of management-body oversight and ICT training
Where this commonly fails
  • No management-body ownership of ICT risk
  • No board-approved resilience strategy
DORA-Art.6
ICT risk management framework

Financial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system, enabling them to address ICT risk quickly, efficiently and comprehensively, reviewed at least annually and audited periodically by ICT-audit staff.

Artefacts an auditor will ask for
  • Documented ICT risk management framework reviewed at least annually
  • ICT audit plan and reports
Where this commonly fails
  • No documented ICT risk framework
  • Framework not reviewed/audited
DORA-Art.7
ICT systems, protocols and tools

Financial entities shall use and maintain ICT systems, protocols and tools that are appropriate to the scale of operations, reliable, with sufficient capacity, and technologically resilient to handle additional information-processing needs under stressed conditions.

Artefacts an auditor will ask for
  • Inventory of ICT systems/tools with capacity and resilience assessment
Where this commonly fails
  • Outdated/unsupported ICT systems without resilience assessment
DORA-Art.8
Identification

Financial entities shall identify, classify and adequately document all ICT-supported business functions, roles and responsibilities, the information assets and ICT assets supporting them, and their interdependencies, and identify all sources of ICT risk on a continuous basis.

Artefacts an auditor will ask for
  • Inventory/classification of ICT-supported functions and ICT assets + interdependencies
  • Continuous ICT risk identification records
Where this commonly fails
  • Incomplete asset/function inventory
  • No mapping of dependencies
DORA-Art.9
Protection and prevention

Financial entities shall continuously monitor and control the security and functioning of ICT systems and tools, and minimise ICT risk through appropriate ICT security policies, procedures, protocols and tools ensuring resilience, continuity and availability, and preserving confidentiality, integrity and authenticity of data (incl access management, encryption, secure configuration, network security).

Artefacts an auditor will ask for
  • ICT security policies and protective controls (access, encryption, configuration, network)
  • Evidence preserving CIA of data
Where this commonly fails
  • Weak or absent protective controls
  • No encryption/access management

DORA Chapter III: ICT-Related Incident Management

DORA-Art.17
ICT-related incident management process

Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents, including early warning indicators, procedures to identify/track/log/categorise incidents by priority and severity, roles and responsibilities, and communication plans.

Artefacts an auditor will ask for
  • Documented ICT incident management process with logging, categorisation and roles
Where this commonly fails
  • No structured incident management process
DORA-Art.18
Classification of ICT-related incidents and cyber threats

Financial entities shall classify ICT-related incidents and determine their impact based on criteria including the number/relevance of clients and transactions affected, geographical spread, data losses, criticality of services affected, and economic impact; and classify significant cyber threats.

Artefacts an auditor will ask for
  • Incident classification methodology aligned to the DORA criteria/RTS thresholds
Where this commonly fails
  • No incident classification against the prescribed criteria
DORA-Art.19
Reporting of major ICT-related incidents

Financial entities shall report major ICT-related incidents to the relevant competent authority within the prescribed timelines using initial, intermediate and final notifications, and may notify significant cyber threats on a voluntary basis.

Artefacts an auditor will ask for
  • Major-incident reports (initial/intermediate/final) submitted to the competent authority within the deadlines
Where this commonly fails
  • Late or missing major-incident reporting
DORA-Art.23
Operational or security payment-related incidents

The incident management and reporting requirements also apply to operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers and electronic money institutions.

Artefacts an auditor will ask for
  • Payment-incident handling and reporting consistent with the ICT incident process
Where this commonly fails
  • Payment-related incidents excluded from the incident process

DORA Chapter IV: Digital Operational Resilience Testing

DORA-Art.24
General requirements for the performance of digital operational resilience testing

Financial entities shall establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the ICT risk management framework, following a risk-based approach.

Artefacts an auditor will ask for
  • A documented digital operational resilience testing programme
Where this commonly fails
  • No resilience testing programme
DORA-Art.25
Testing of ICT tools and systems

The testing programme shall include a range of assessments and tests (e.g. vulnerability assessments and scans, open-source analyses, network security assessments, gap analyses, physical security reviews, questionnaires, source-code reviews, scenario-based tests, compatibility/performance tests, end-to-end and penetration testing), with critical ICT systems tested at least yearly.

Artefacts an auditor will ask for
  • Test plans and results across the required assessment types
  • At least-yearly testing of critical ICT systems
Where this commonly fails
  • Critical systems not tested annually
  • Narrow test coverage
DORA-Art.26
Advanced testing of ICT tools, systems and processes based on TLPT

Financial entities identified as significant shall carry out, at least every three years, threat-led penetration testing (TLPT) on live production systems covering critical or important functions, performed by qualified internal or external testers.

Artefacts an auditor will ask for
  • TLPT scope, threat intelligence, and test reports (at least three-yearly for in-scope entities)
  • TLPT attestation
Where this commonly fails
  • In-scope entity not performing TLPT
  • TLPT not covering critical functions
DORA-Art.27
Requirements for testers for the carrying out of TLPT

Financial entities shall use only testers for TLPT that meet requirements on suitability, reputation, technical and organisational capabilities, and (for external testers) certification and professional indemnity insurance.

Artefacts an auditor will ask for
  • Evidence that TLPT testers meet the Article 27 suitability/insurance requirements
Where this commonly fails
  • Using testers not meeting the requirements

DORA Chapter V: ICT Third-Party Risk Management

DORA-Art.28
ICT third-party risk: general principles

Financial entities shall manage ICT third-party risk as an integral component of ICT risk, maintain a Register of Information on all contractual arrangements for the use of ICT services, report it to competent authorities, assess risk before entering arrangements (including concentration and subcontracting), and adopt an ICT third-party risk strategy.

Artefacts an auditor will ask for
  • A Register of Information of ICT third-party arrangements reported to the competent authority
  • Pre-contract risk assessment records
Where this commonly fails
  • No Register of Information
  • No pre-contract third-party risk assessment
DORA-Art.29
Preliminary assessment of ICT concentration risk at entity level

When assessing ICT third-party arrangements supporting critical or important functions, financial entities shall assess ICT concentration risk, including the risks of contracting providers that are not easily substitutable or of multiple arrangements with the same or closely connected providers, and the implications of subcontracting.

Artefacts an auditor will ask for
  • ICT concentration-risk assessment for critical/important-function arrangements
Where this commonly fails
  • Concentration risk not assessed
DORA-Art.30
Key contractual provisions

Contractual arrangements for the use of ICT services shall include the mandatory key contractual provisions (e.g. clear service descriptions, locations of data processing, data protection, accessibility/availability/integrity/security, assistance on incidents, audit and access rights, termination rights and exit strategies), with enhanced provisions for services supporting critical or important functions.

Artefacts an auditor will ask for
  • ICT contracts containing the mandatory key provisions (audit/access, termination, exit, security)
  • Enhanced provisions for critical/important-function services
Where this commonly fails
  • Contracts missing audit/access, termination or exit provisions
DORA-Art.31
Designation of critical ICT third-party service providers

The European Supervisory Authorities designate critical ICT third-party service providers, which become subject to the Union Oversight Framework led by a Lead Overseer; financial entities shall account for the use of such providers in their third-party risk management.

Artefacts an auditor will ask for
  • Identification of any critical ICT third-party providers used and their oversight status
Where this commonly fails
  • No awareness of critical-TPP designations affecting the entity

DORA Chapters VI-VII: Information Sharing, Penalties and Data Protection

DORA-Art.45
Information-sharing arrangements on cyber threat information and intelligence

Financial entities may exchange amongst themselves cyber threat information and intelligence (indicators of compromise, tactics, techniques and procedures, alerts and tools) within trusted communities, under arrangements that protect the sensitivity of the information and comply with data protection law.

Artefacts an auditor will ask for
  • Participation in threat-information-sharing arrangements (where adopted) with protective and data-protection safeguards
Where this commonly fails
  • Sharing threat information without appropriate safeguards
DORA-Art.50
Administrative penalties and remedial measures

Competent authorities shall have the power to impose effective, proportionate and dissuasive administrative penalties and remedial measures for breaches of the Regulation; financial entities should be prepared to evidence compliance and remediate findings.

Artefacts an auditor will ask for
  • Readiness to evidence DORA compliance and to remediate supervisory findings
Where this commonly fails
  • No process to respond to supervisory findings/penalties
DORA-Art.56
Data protection

The processing of personal data under the Regulation shall be carried out in accordance with Regulation (EU) 2016/679 and other applicable Union data protection law, with processing limited to what is necessary to comply with the obligations under DORA.

Artefacts an auditor will ask for
  • GDPR-compliant handling of personal data processed for DORA purposes
Where this commonly fails
  • Processing personal data beyond what DORA compliance requires
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the DORA framework page.