Audnexa module · DORA

DORA audit tool — gap analysis and compliance report

Audnexa is an auditable AI workspace that supports your DORA compliance audit (Regulation (EU) 2022/2554, applicable since 17 January 2025): gap analysis of the five pillars, ICT third-party risk documentation and a board-ready report — offline, with human sign-off.

DORA audit tool

The scope of a DORA audit that Audnexa covers

Five pillars to cover in the audit

DORA organises the financial sector’s digital operational resilience requirements into five pillars — an audit should cover them together:

  • ICT risk management
  • ICT-related incident handling, classification and reporting
  • Digital operational resilience testing
  • ICT third-party risk management (Art. 28–30)
  • Information sharing on cyber threats

Register of information and ICT providers

A complete register of contracts with ICT providers is one of the first things checked in an audit and the most common source of gaps. Our knowledge base covers the requirements in full — this module focuses on producing the report faster and repeatably.

audnexa

How Audnexa supports a DORA audit

DORA gap analysis

Maps evidence to the requirements of the five pillars and produces a gap report ready for your team to review.

ICT third-party risk

Supports documenting third-party risk and the data for the register of information under Art. 28–30.

Board-ready report

An auditable report with references to evidence — an artefact for the management body’s accountability.

Offline mode (Bank Mode)

Audit material and data never leave the entity’s infrastructure — no outbound traffic to the cloud.

faq

Frequently asked questions — DORA audit

When does DORA apply?
Regulation (EU) 2022/2554 has applied since 17 January 2025; the detailed requirements are specified by technical standards (RTS/ITS). Financial entities should be compliant from that date.
How does DORA differ from NIS2?
DORA is a sector-specific regulation for financial markets and takes precedence (lex specialis) over NIS2 for ICT risk. NIS2 covers a broader range of sectors. Some entities report under both regimes.
Does Audnexa run the DORA audit for us?
No. Audnexa speeds up preparing an auditable draft with references to evidence; the assessment and sign-off stay with your team. The tool does not replace an auditor’s opinion or a compliance decision.
Does our data have to leave our infrastructure?
No. In offline mode (Bank Mode) Audnexa processes audit material locally — data is not sent to the cloud or used to train models.
What is the DORA register of information?
A structured inventory of contracts with ICT service providers (including critical ones), reported to the supervisor — with service scope, critical functions and data-processing locations.

Book a security presentation

We cover technical details, deployment modes and licence terms in a security presentation (30 min, online).

+48 12 200 27 10 Book a security presentation

Contact

Audnexa is an auditable AI workspace that supports your DORA compliance audit (Regulation (EU) 2022/2554, applicable since 17 January 2025): gap analysis of the five pillars, ICT third-party risk documentation and a board-ready report — offline, with human sign-off.

Virtline Sp. z o.o. · biuro@virtline.com · +48 12 200 27 10