Third-Line Assurance over DORA
Internal audit is the third line — independent assurance that DORA controls are designed well and operating effectively. DORA explicitly expects ICT risk to fall within the audit plan (Art. 6).
What the DORA auditor provides
- An independent opinion on whether DORA obligations are met and effective.
- Assurance to the audit committee and management body.
- Findings, root causes and tracked recommendations.
Assurance, not delivery
The Digital Operational Resilience Act (Regulation (EU) 2022/2554) has applied since 17 January 2025, and Article 6 places the ICT risk-management framework squarely within the reach of internal audit: it must be subject to periodic audit by auditors with sufficient knowledge, and the audit plan and follow-up must reach the management body. The third line does not build controls or monitor them day to day — that is the first and second lines. It independently tests whether the controls the organisation claims to have are both well-designed and actually operating, and it reports that opinion to the audit committee. Its product is credible, evidenced assurance, not activity.
Design
Is the control set up to meet the DORA obligation at all?
Operation
Does it actually run — with evidence, not assertion?
Opinion
An independent verdict to the audit committee.
Worked example. A bank’s management asserts its DORA programme is “complete”. Internal audit does not take this on trust: it samples the incident process, the Register and the testing findings, tests each for design and operation, and issues an independent opinion. The board learns not what management hopes is true, but what audit has evidenced — the whole value of a third line.
That was your free preview
Enrol to unlock all 23 lessons, every knowledge check, the dedicated certification exam, the downloadable toolkit and your verifiable certificate — lifetime access.
Secure payment via Stripe · 30-day money-back guarantee.