EU Digital Operational Resilience Act (DORA) Compliance Checklist 2026
EU DORA (Regulation 2022/2554, in application January 17, 2025) applies to 20 categories of EU-regulated financial entities and their ICT service providers. It mandates a harmonized ICT risk managemen…
Maximum penalty: No single EU-wide penalty amount for financial entities — DORA Art. 50 delegates administrative-penalty amounts to each Member State's own national law, with wide divergence (e.g., Finland caps individual penalties at €100,000; Germany at €5,000,000). For DESIGNATED CRITICAL ICT third-party providers only, the EU-level Lead Overseer may impose a periodic penalty payment under Art. 35 of up to 1% of average daily worldwide turnover, charged daily for a maximum of 6 months, until compliance.
Complete each item below to achieve compliance. Use Aegis Firma to generate all required documentation automatically.
Regulatory Requirements
1. ICT Risk Management Framework
Implement a documented ICT risk management framework covering all ICT assets including AI tools and services. Must include risk identification, protection measures, detection capabilities, response protocols, and recovery procedures. Board-level oversight of ICT risk is required.
Due: January 17, 2025
2. Third-Party ICT Risk Assessment (AI Vendors)
Assess and document ICT risks from all third-party ICT service providers, including AI tool vendors (OpenAI, Microsoft Copilot, etc.). Contracts with ICT service providers must include mandatory clauses: security requirements, audit rights, exit strategies, and incident notification obligations.
Due: January 17, 2025
3. Major ICT Incident Reporting
Establish incident management processes to detect, classify, and report major ICT-related incidents to the relevant national competent authority. Includes incidents caused by or involving AI systems. Initial report within 4 hours of classification; intermediate report within 72 hours; final report within one month.
Due: January 17, 2025
4. Digital Operational Resilience Testing
Conduct annual resilience testing of ICT systems including AI tools (vulnerability assessments, penetration testing). Significant institutions must conduct Threat-Led Penetration Testing (TLPT) every 3 years.
Due: January 17, 2026
5. Mandatory Contract Clauses for AI Vendors
Any AI software vendor contracted by an EU financial institution must ensure their contracts include DORA-mandatory clauses: (1) security SLAs aligned with client's ICT risk management standards; (2) audit rights for the financial entity and regulatory authorities; (3) incident notification obligations (within defined timelines); (4) exit planning and data portability; (5) subcontracting disclosure and controls.
Due: January 17, 2025
Implementation Steps
6. Identify all AI/ML systems used in ICT-dependent financial functions
7. Include AI systems in your ICT risk management framework
8. Conduct resilience testing of AI-driven systems (at least annually)
9. Map AI third-party dependencies — classify as Critical ICT Third-Party Providers if applicable
10. Register Critical ICT Third-Party Providers with the relevant ESA
11. Establish exit strategies for AI vendor concentration risk
12. Include AI incidents in your incident classification and reporting procedures