How to cover AI systems in your DORA compliance
DORA, Digital Operational Resilience Act (EU) 2022/2554
- Status
- In force
- Binding
- Yes
- Object analysed
- Organisation
- Requirements
- 6
- Next milestone
- —
In short
For the financial sector an AI system is an ICT asset: ICT risk management, major incidents, resilience testing and third-party provider risk (model and cloud vendors).
Steps to compliance
- Qualify each AI systemAxes to decide: Supports a critical or important function.
- Determine your roleDuties vary by role: Financial entity and ICT provider.
- Apply the 6 requirementsThey focus on: Incidents & corrective action, Cybersecurity, Risk management and Governance & accountability.
- Prove it with checks11 checks to document, 9 of which also serve NIST AI RMF, ISO 42001 and NIS2.
- Keep compliance up to dateEvery known milestone has passed: the obligations apply.
Scope and penalties
- Kind
- Regulation
- Scope
- Financial entities and critical ICT third-party providers.
- Territorial reach
- European Union.
- Penalties
- Set by member states; up to 1% of average daily worldwide turnover as periodic penalty for critical providers.
- Jurisdiction
- European Union
Timeline
Qualifying a system
Classification axes and possible verdicts
Supports a critical or important function
Requirements
6 requirements
| Code | Article | Requirement | Applies to | Checks |
|---|---|---|---|---|
| DORA-05 | Art. 5, 6 | ICT risk framework under the management body's responsibility | ||
| DORA-08 | Art. 8 | Identification and inventory of ICT assets and functions | ||
| DORA-17 | Art. 17-19 | Classification and reporting of major incidents (4h / 72h / 1 month) | ||
| DORA-24 | Art. 24-27 | Operational resilience testing, TLPT for significant entities | ||
| DORA-28 | Art. 28-30 | ICT third-party risk: register of information, clauses, exit strategy | ||
| DORA-11 | Art. 11 | Continuity, response and recovery |
Checks to document
Evidence collected for a check counts for every regulation that uses it.
| Code | Check | Scope | Themes | Also used by |
|---|---|---|---|---|
| CHK-POL-RISK | An AI risk-management policy and process are established through transparent, documented controls | Organisation | ||
| CHK-EXEC-ACCOUNT | Executive leadership is accountable for AI risk decisions (board committee, risk appetite) | Organisation | ||
| CHK-INVENTORY | A mechanism to inventory AI systems is in place and resourced | Organisation | ||
| VER-022-F-01 | Risk and incident response procedure | Organisation | ||
| NEW-DORA-01 | DORA major incident reporting procedure proposed | System | ||
| VER-009-F-04 | Resilience to adversarial attacks tested | Model | ||
| CHK-SECURITY | Security and resilience are evaluated and documented | System | ||
| CHK-THIRDPARTY-POL | Policies address third-party AI/data risks, incl. IP, transparency and testing | Organisation | ||
| CHK-THIRDPARTY-CONTINGENCY | Contingency/redundancy for high-risk third-party failures and ongoing third-party monitoring | Model | ||
| NEW-DORA-02 | AI vendor listed in the DORA register of information proposed | System | ||
| VER-AUTO-01 | Suspension procedure in the event of risk | Organisation |
Themes covered
Frequently asked questions
Who is in scope of DORA?
Financial entities and critical ICT third-party providers. European Union.
What penalties does DORA carry?
Set by member states; up to 1% of average daily worldwide turnover as periodic penalty for critical providers.
When do the DORA obligations apply?
Apr 30, 2025: First register of information submitted; Nov 18, 2025: First critical ICT providers designated.
Is DORA binding?
Yes. Kind: regulation. Status: in force.
How does DORA relate to other regulations?
The same checks serve several texts. Shared checks: NIST AI RMF (7), ISO 42001 (4) and NIS2 (3).
Related regulations
Official sources
Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.