Skip to main content
DORA

Operational Resilience
for Financial Entities under DORA

The Digital Operational Resilience Act sets a single EU framework for ICT risk, incident reporting, resilience testing and third-party risk management across banks, insurers, investment firms, crypto-asset service providers and their critical ICT providers.

Basenorm centralises all five DORA pillars in one governance model, so you can demonstrate resilience to supervisors, boards and auditors with the same controls, evidence and metrics.

ICT Risk Management and Governance

Build a DORA-aligned ICT risk management framework with clear board accountability, documented strategy, and controls mapped to the Unified Control Library.

  • Board-level ICT risk governance and accountability
  • ICT risk management framework aligned with Articles 5 to 15
  • Asset, process and dependency inventory in the Governance Graph
  • Protection, detection, response and recovery controls
  • Continuous documentation and evidence for supervisors
Explore the Unified Control Library →

ICT Risk Framework

Art. 5-13
Core Banking SystemCritical
High
Payment GatewayCritical
High
Customer Portal
Medium
Reporting Engine
Low

2 High-Risk Assets

Require enhanced monitoring

Management Body Accountability

Art. 4-6

Board Oversight

Direct accountability for ICT risk

4

Policies

12

Reviews

Q1

Next Review

ICT Risk Policy
Board
Resilience Strategy
CRO
Third-Party Policy
CISO

Incident Management, Reporting and Resilience Testing

Detect, classify and report major ICT-related incidents within DORA timelines, and run advanced resilience tests including threat-led penetration testing where required.

  • Major incident classification and reporting workflows
  • Initial, intermediate and final report templates
  • Digital operational resilience testing programmes
  • Threat-led penetration testing for significant entities
  • Lessons learned and remediation tracking

ICT Third-Party Risk and Information Sharing

Manage concentration risk, contractual requirements and ongoing oversight of ICT service providers, including critical third parties designated by European Supervisory Authorities.

  • Register of information for all ICT third-party arrangements
  • DORA-compliant contractual clauses and exit strategies
  • Concentration and substitutability risk assessments
  • Oversight integration for critical ICT third-party providers
  • Secure information sharing on cyber threats and intelligence
Explore AskNorman AI →

Third-Party ICT Oversight

Art. 28
AWS Cloud ServicesCritical
14 dependencies
Risk:82
Azure InfrastructureCritical
8 dependencies
Risk:78
Salesforce CRM
3 dependencies
Risk:45

2 Critical Providers

Enhanced oversight required

Ready to prove digital operational resilience?

Join financial entities using Basenorm to operationalise DORA across ICT risk, incident reporting, resilience testing, third-party oversight and information sharing.

Frequently Asked Questions

Explore frequently asked questions about DORA and related compliance topics.