DORAeCHECKLISTEN
FOR THE
Iinternal Revision

DORA tests efficiently, structured
and carry out revisions securely.

The requirements of the DORA Regulation (EU) 2022/2554 present financial companies with new challenges. Internal audits must demonstrate that the regulatory requirements are being appropriately implemented and effectively monitored. Our DORA audit checklists support the targeted, comprehensible, and supervised execution of examinations.

Your challenges

New regulatory requirements through DORA (Digital Operational Resilience Act)

High expectations from supervision, auditors, and management

Limited resources in Internal Audit

Need for standardised and traceable examination approaches

Complex requirements for ICT risk management and ICT third-party risk management

What the eChecklists cover

IT risk management

Chapter II of Regulation (EU) 2022/2554

RTS Art. 15, 16(3) DORA

Treatment, Classification and Reporting of ICT-related Incidents

Chapter III of Regulation (EU) 2022/2554

RTS Art. 18(3) DORA

RTS Art. 20 sub-para. a DORA

ITS Art. 20 lit. b DORA

Testing of digital operational resilience, including. Threat-led Penetration Testing (TLPT)

Chapter IV of Regulation (EU) 2022/2554

RTS Art. 26 Para. 11 DORA

Information and Communication Technology (ICT) Third-Party Risk Management

Chapter V of Regulation (EU) 2022/2554

RTS Art. 28 para. 10 DORA

RTS Art. 30 para. 5 DORA

DORA Article 28(9)

Your added value

Save time Reduce the effort for audit planning and execution.

Increase exam security: Employ a structured and regulatorily compliant audit approach.

Detecting vulnerabilities early: Identify action requirements before supervisors or auditors find them.

Uniform examination quality Standardise your DORA assessments across all audit teams.

Convinced? Then simply order directly via our order button or download our Order form down.

Our cooperation partners

Regulartech-IT-Audit-Consult GmbH is a consulting firm specialising in IT regulation, banking supervisory law, IT audit, and compliance for financial institutions.