Policy Register

DORA (Regulation (EU) 2022/2554)

The register cites 12 of its 26 clauses, on 24 policy types. Rendered when the buyer ticks "DORA".

Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. Open the standard on the compliance platform. What it expects of a policy set: the DORA regime page.

Clauses cited

12 of 26
DORA Art. 5 Governance and organisation

The management body of the financial entity shall define, approve, oversee and be responsible for the implementation of the ICT risk management framework, bear ultimate responsibility for managing ICT risk, set roles and responsibilities, approve the digital operational resilience strategy, and allocate appropriate budget and training.

Evidence an auditor accepts: Board-approved ICT risk management framework and digital operational resilience strategy; records of management-body oversight and ICT training
Common gap: No management-body ownership of ICT risk
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 6 ICT risk management framework

Financial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system, enabling them to address ICT risk quickly, efficiently and comprehensively, reviewed at least annually and audited periodically by ICT-audit staff.

Evidence an auditor accepts: Documented ICT risk management framework reviewed at least annually; iCT audit plan and reports
Common gap: No documented ICT risk framework
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 9 Protection and prevention

Financial entities shall continuously monitor and control the security and functioning of ICT systems and tools, and minimise ICT risk through appropriate ICT security policies, procedures, protocols and tools ensuring resilience, continuity and availability, and preserving confidentiality, integrity and authenticity of data (incl access management, encryption, secure configuration, network security).

Evidence an auditor accepts: ICT security policies and protective controls (access, encryption, configuration, network); evidence preserving CIA of data
Common gap: Weak or absent protective controls
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 10 Detection

Financial entities shall have mechanisms to promptly detect anomalous activities, ICT network performance issues and ICT-related incidents, with multiple layers of control, defined alert thresholds and detection processes that enable timely incident response.

Evidence an auditor accepts: Anomaly/incident detection mechanisms with defined alert thresholds; monitoring coverage records
Common gap: No anomaly detection or alerting
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 11 Response and recovery

Financial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.

Evidence an auditor accepts: ICT business continuity policy + response/recovery plans; records of plan testing
Common gap: No ICT continuity/response/recovery plans
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 12 Backup policies and procedures, restoration and recovery

Financial entities shall develop and document backup policies and procedures, and restoration and recovery procedures and methods, ensuring backups can be restored with minimal disruption, with backup systems physically and logically segregated from the source system.

Evidence an auditor accepts: Backup and restoration policies/procedures; evidence of segregated backups and restoration tests
Common gap: No tested backups
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 14 Communication

Financial entities shall have crisis communication plans enabling responsible disclosure of major ICT-related incidents or vulnerabilities to clients, counterparts and the public as appropriate, and designate communication policies for internal staff and external stakeholders.

Evidence an auditor accepts: Crisis communication plan for major ICT incidents
Common gap: No crisis communication plan
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 17 ICT-related incident management process

Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents, including early warning indicators, procedures to identify/track/log/categorise incidents by priority and severity, roles and responsibilities, and communication plans.

Evidence an auditor accepts: Documented ICT incident management process with logging, categorisation and roles
Common gap: No structured incident management process
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 24 General requirements for the performance of digital operational resilience testing

Financial entities shall establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the ICT risk management framework, following a risk-based approach.

Evidence an auditor accepts: A documented digital operational resilience testing programme
Common gap: No resilience testing programme
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 25 Testing of ICT tools and systems

The testing programme shall include a range of assessments and tests (e.g. vulnerability assessments and scans, open-source analyses, network security assessments, gap analyses, physical security reviews, questionnaires, source-code reviews, scenario-based tests, compatibility/performance tests, end-to-end and penetration testing), with critical ICT systems tested at least yearly.

Evidence an auditor accepts: Test plans and results across the required assessment types; at least-yearly testing of critical ICT systems
Common gap: Critical systems not tested annually
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 28 ICT third-party risk: general principles

Financial entities shall manage ICT third-party risk as an integral component of ICT risk, maintain a Register of Information on all contractual arrangements for the use of ICT services, report it to competent authorities, assess risk before entering arrangements (including concentration and subcontracting), and adopt an ICT third-party risk strategy.

Evidence an auditor accepts: A Register of Information of ICT third-party arrangements reported to the competent authority; pre-contract risk assessment records
Common gap: No Register of Information
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 30 Key contractual provisions

Contractual arrangements for the use of ICT services shall include the mandatory key contractual provisions (e.g. clear service descriptions, locations of data processing, data protection, accessibility/availability/integrity/security, assistance on incidents, audit and access rights, termination rights and exit strategies), with enhanced provisions for services supporting critical or important functions.

Evidence an auditor accepts: ICT contracts containing the mandatory key provisions (audit/access, termination, exit, security); enhanced provisions for critical/important-function services
Common gap: Contracts missing audit/access, termination or exit provisions
Source: DORA (Regulation (EU) 2022/2554)

See which clauses your list answers

Paste the list and every document names the clauses behind it, filtered to the regimes that apply to you. Eight documents free, no account.

Build a register