EUEuropean UnionIn forceDORA

How to cover AI systems in your DORA compliance

DORA, Digital Operational Resilience Act (EU) 2022/2554

Status
In force
Binding
Yes
Object analysed
Organisation
Requirements
6
Next milestone
—

In short

For the financial sector an AI system is an ICT asset: ICT risk management, major incidents, resilience testing and third-party provider risk (model and cloud vendors).

Steps to compliance

  1. Qualify each AI systemAxes to decide: Supports a critical or important function.
  2. Determine your roleDuties vary by role: Financial entity and ICT provider.
  3. Apply the 6 requirementsThey focus on: Incidents & corrective action, Cybersecurity, Risk management and Governance & accountability.
  4. Prove it with checks11 checks to document, 9 of which also serve NIST AI RMF, ISO 42001 and NIS2.
  5. Keep compliance up to dateEvery known milestone has passed: the obligations apply.

Scope and penalties

Kind
Regulation
Scope
Financial entities and critical ICT third-party providers.
Territorial reach
European Union.
Penalties
Set by member states; up to 1% of average daily worldwide turnover as periodic penalty for critical providers.
Jurisdiction
European Union

Timeline

Jan 16, 2023Entry into force
Jan 17, 2025Application date
Apr 30, 2025First register of information submitted
Nov 18, 2025First critical ICT providers designated
Release
PastSet in the textPotentialTo verify

Qualifying a system

Classification axes and possible verdicts

Supports a critical or important function

Critical or important functionOther function

Requirements

6 requirements

CodeArticleRequirementApplies toChecks
DORA-05Art. 5, 6ICT risk framework under the management body's responsibility
Financial entity
DORA-08Art. 8Identification and inventory of ICT assets and functions
Financial entity
DORA-17Art. 17-19Classification and reporting of major incidents (4h / 72h / 1 month)
Financial entity
DORA-24Art. 24-27Operational resilience testing, TLPT for significant entities
Financial entityCritical or important function
DORA-28Art. 28-30ICT third-party risk: register of information, clauses, exit strategy
Financial entity
DORA-11Art. 11Continuity, response and recovery
Financial entityCritical or important function

Checks to document

Evidence collected for a check counts for every regulation that uses it.

CodeCheckScopeThemesAlso used by
CHK-POL-RISKAn AI risk-management policy and process are established through transparent, documented controlsOrganisation
CHK-EXEC-ACCOUNTExecutive leadership is accountable for AI risk decisions (board committee, risk appetite)Organisation
CHK-INVENTORYA mechanism to inventory AI systems is in place and resourcedOrganisation
VER-022-F-01Risk and incident response procedureOrganisation
NEW-DORA-01DORA major incident reporting procedure proposedSystem
—
VER-009-F-04Resilience to adversarial attacks testedModel
CHK-SECURITYSecurity and resilience are evaluated and documentedSystem
CHK-THIRDPARTY-POLPolicies address third-party AI/data risks, incl. IP, transparency and testingOrganisation
CHK-THIRDPARTY-CONTINGENCYContingency/redundancy for high-risk third-party failures and ongoing third-party monitoringModel
NEW-DORA-02AI vendor listed in the DORA register of information proposedSystem
—
VER-AUTO-01Suspension procedure in the event of riskOrganisation

Themes covered

Frequently asked questions

Who is in scope of DORA?

Financial entities and critical ICT third-party providers. European Union.

What penalties does DORA carry?

Set by member states; up to 1% of average daily worldwide turnover as periodic penalty for critical providers.

When do the DORA obligations apply?

Apr 30, 2025: First register of information submitted; Nov 18, 2025: First critical ICT providers designated.

Is DORA binding?

Yes. Kind: regulation. Status: in force.

How does DORA relate to other regulations?

The same checks serve several texts. Shared checks: NIST AI RMF (7), ISO 42001 (4) and NIS2 (3).

Related regulations

Official sources

Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo