Compliance and regulation

DORA

Digital operational resilience for financial entities and their ICT providers.

What it involves

What we do

The DORA Regulation requires financial entities to have an ICT risk management framework, incident management and reporting, resilience testing and control over providers. We implement it end to end.

What's included

  • ICT risk management framework and governance
  • Management, classification and reporting of ICT incidents
  • Resilience testing programme (including TLPT)
  • Register of information and management of ICT providers
  • Information-sharing arrangements
  • Reporting to authorities and the management body

Who it's for

  • Banks, insurers, asset managers and payment institutions
  • Fintechs and ICT providers to the financial sector
  • Critical providers subject to oversight

Deliverables

  • DORA gap assessment
  • ICT risk framework
  • Provider register
  • Resilience testing plan

Reference frameworks and standards

DORA (EU Reg. 2022/2554)ESAs RTS/ITSISO 27001ISO 22301

Reference frameworks used to design, implement, review and evidence. They are not presented as our own certifications unless contractually applicable.

How we approach it

  1. DiscoverWe get to know your business, environment, risks and priorities.
  2. AnalyseWe assess maturity, exposure, compliance and real capabilities.
  3. DesignWe define strategy, roadmap, architecture and action plan.
  4. ImplementWe deliver controls, processes, technology and evidence.
  5. OperateWe monitor, respond and support continuous improvement.
  6. OptimiseWe measure results, reduce risk and evolve capabilities.

Let's talk

Does DORA fit your situation?

Tell us about your challenges and let's design together the best strategy to protect and strengthen your business.