Standards / Information security, privacy and AI

DORA EU digital operational resilience

ICT risk, incident reporting, resilience testing, and third-party risk for EU financial entities.

Core documents AMS builds

  • ICT risk framework
  • Incident classification procedure
  • Resilience testing plan
  • Register of ICT providers

Drafted from your actual processes and systems, then kept under version control with review dates.

The path to DORA

Six steps from first conversation to DORA. AMS and our consultants handle each one with you.

  1. 1Scope

    Define which sites, teams, processes and systems DORA will cover.

  2. 2Gap assessment

    Compare what you do today with every DORA requirement and list what is missing.

  3. 3Documents

    Write the policies, procedures and records DORA expects, starting with the ict risk framework.

  4. 4Implement and collect evidence

    Put the processes into daily work and capture proof that they run, on a schedule.

  5. 5Internal review

    Check readiness with an internal audit or self-assessment, and close the findings.

  6. 6Ongoing compliance

    There is no single certificate. You keep records current, answer regulators and customers, and review controls as the rules change.

DORA questions

Planning DORA? Talk to our team

How long does DORA implementation take?

Most organizations need about 12–24 weeks, depending on size, number of sites and how much is already in place. A gap assessment gives a firm estimate.

What documents does DORA require?

Core documents usually include: ict risk framework, incident classification procedure, resilience testing plan, register of ict providers. AMS drafts them from your actual processes and keeps them under version control.

Can DORA be combined with other standards?

Yes. DORA is often run together with ISO/IEC 20000-1, ISO/IEC 27001, ISO/IEC 27701. AMS maps shared requirements, so one record can count toward several standards.

How does AMS help with DORA?

AMS runs the full DORA program: scoping, gap assessment, documents, evidence capture, internal audits, corrective actions and the audit pack for your reviewers.

Let's look at your operation together

A 30-minute call. Tell us how you work today and we'll show you the product that fits, configured around your process.