DORA audit — ICT requirements, third-party risk and how to prepare
What DORA is and who it covers
DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) is directly applicable EU law harmonizing digital operational resilience for the financial sector. It applies since 17 January 2025.
It covers a broad range of financial entities (banks, insurers, investment firms, payment institutions and others) and — indirectly — critical ICT third-party providers.
The five DORA pillars
- ICT risk management (framework, roles, policies),
- major ICT incident reporting,
- digital operational resilience testing (including advanced / TLPT),
- ICT third-party risk management (register of information, contractual clauses),
- cyber-threat information sharing.
Register of information (ICT third parties)
A concrete obligation is maintaining a register of information about ICT third-party contracts, with criticality classification — a key element of third-party-risk audits.
How to prepare for a DORA audit
- inventory the ICT risk-management framework and evidence,
- build the register of information and criticality classification,
- document incident reporting and resilience testing,
- review vendor contractual clauses (audit rights, exit plan),
- prepare a review-ready gap report for the risk committee.
How Audnexa supports DORA audits
Audnexa supports preparing auditable report and gap-analysis drafts for DORA — with references to evidence and a full audit trail. In offline mode (Bank Mode), material stays in the customer’s infrastructure and a human approves every report.
A mature tool, battle-tested over years in Virtline’s audit practice (ISO/IEC 27001). It does not replace an auditor’s or lawyer’s opinion.
Frequently asked questions
When does DORA apply?
DORA applies since 17 January 2025 as a directly applicable EU regulation — no national transposition is required.
How does DORA differ from NIS2?
DORA is a regulation focused on the financial sector’s digital operational resilience (lex specialis). NIS2 is a broader-scope directive. For financial entities, DORA generally takes precedence on ICT matters.
Which tool should you choose for a DORA audit?
Assess data control (offline/on-premise), audit trail, human approval, ICT vendor register support and maturity. Audnexa meets these criteria (Bank Mode, ISO/IEC 27001, years of Virtline practice).
Sources
This content is informational and does not constitute a legal opinion, an auditor’s opinion or a formal compliance decision.