Skip to content
13 items · Free checklist

EU Digital Operational Resilience Act (DORA) Compliance Checklist 2026

EU DORA (Regulation 2022/2554, in application January 17, 2025) applies to 20 categories of EU-regulated financial entities and their ICT service providers. It mandates a harmonized ICT risk managemen

Maximum penalty: No single EU-wide penalty amount for financial entities — DORA Art. 50 delegates administrative-penalty amounts to each Member State's own national law, with wide divergence (e.g., Finland caps individual penalties at €100,000; Germany at €5,000,000). For DESIGNATED CRITICAL ICT third-party providers only, the EU-level Lead Overseer may impose a periodic penalty payment under Art. 35 of up to 1% of average daily worldwide turnover, charged daily for a maximum of 6 months, until compliance.

Complete each item below to achieve compliance. Use Aegis Firma to generate all required documentation automatically.

Regulatory Requirements

1. ICT Risk Management Framework

Implement a documented ICT risk management framework covering all ICT assets including AI tools and services. Must include risk identification, protection measures, detection capabilities, response protocols, and recovery procedures. Board-level oversight of ICT risk is required.

Due: January 17, 2025

2. Third-Party ICT Risk Assessment (AI Vendors)

Assess and document ICT risks from all third-party ICT service providers, including AI tool vendors (OpenAI, Microsoft Copilot, etc.). Contracts with ICT service providers must include mandatory clauses: security requirements, audit rights, exit strategies, and incident notification obligations.

Due: January 17, 2025

3. Major ICT Incident Reporting

Establish incident management processes to detect, classify, and report major ICT-related incidents to the relevant national competent authority. Includes incidents caused by or involving AI systems. Initial report within 4 hours of classification; intermediate report within 72 hours; final report within one month.

Due: January 17, 2025

4. Digital Operational Resilience Testing

Conduct annual resilience testing of ICT systems including AI tools (vulnerability assessments, penetration testing). Significant institutions must conduct Threat-Led Penetration Testing (TLPT) every 3 years.

Due: January 17, 2026

5. Mandatory Contract Clauses for AI Vendors

Any AI software vendor contracted by an EU financial institution must ensure their contracts include DORA-mandatory clauses: (1) security SLAs aligned with client's ICT risk management standards; (2) audit rights for the financial entity and regulatory authorities; (3) incident notification obligations (within defined timelines); (4) exit planning and data portability; (5) subcontracting disclosure and controls.

Due: January 17, 2025

Implementation Steps

6. Classify all AI-driven credit scoring, fraud detection, and trading systems

7. Apply EU AI Act high-risk classification to AI in credit scoring (Annex III)

8. Comply with DORA requirements for ICT resilience of AI-driven systems

9. Implement explainability for AI credit decisions (ECOA/Reg B adverse action notices in US)

10. Review CFPB guidance on AI in consumer credit decisions

11. Ensure Fair Credit Reporting Act (FCRA) compliance for AI that uses consumer reports

12. Conduct model risk management (SR 11-7 guidance for US banks)

13. Test AI models for disparate impact on protected classes quarterly