Audit & Supervision

DORA Audit: Requirements, Checklist & How to Prepare

Everything financial entities need on DORA audits: supervisory inspections, the mandatory internal audit of the ICT risk framework, audit scope by pillar, the evidence supervisors demand and how to be ready before they knock.

3 audit types: Supervisory · Internal · Readiness Art. 6(6) internal audit mandate Penalties set by national law (Art. 50) Updated August 2026

What Is a DORA Audit?

A DORA audit is any structured review of a financial entity's compliance with the Digital Operational Resilience Act — Regulation (EU) 2022/2554 — and its 13 supplementing Regulatory and Implementing Technical Standards. The word "audit" is used loosely across the industry, and the first step to preparing properly is to recognise that it refers to three quite different exercises with different owners, triggers and consequences.

What they share is the reference standard: every DORA audit measures the entity against the same body of binding rules — the 64 articles of DORA plus the RTS/ITS. What differs is who runs the review, whether participation is mandatory, and what happens when a gap is found. A gap discovered by your own internal audit becomes a remediation action. The same gap discovered by a competent authority during a supervisory inspection becomes a formal finding — with potential capital, enforcement and reputational consequences attached.

That asymmetry is the single most important idea on this page. It is why mature institutions invest in audit readiness: the cheapest place to find a DORA gap is in a review you commissioned yourself.

The Three Types of DORA Audit

1. Supervisory inspection

Run by the competent authority (ECB, BaFin, ACPR, DNB, Banca d'Italia, CSSF and others). Mandatory, scheduled by the supervisor, often part of the SREP cycle for banks. Produces formal findings and can drive enforcement.

2. Internal audit

Required by Art. 6(6). The ICT risk management framework must be independently reviewed by auditors with ICT expertise, following the entity's audit plan. Findings go to the management body for formal follow-up.

3. Readiness assessment

Voluntary. Commissioned by the entity — internally or via a specialist firm — to find and fix gaps before a supervisor does. Mirrors the supervisory scope but produces a remediation plan, not an enforcement notice.

External financial audit note: DORA does not create a separate statutory "DORA opinion" within the annual financial-statement audit. However, statutory auditors increasingly consider ICT and operational resilience risk as part of going-concern and operational risk assessment, and audit committees now routinely add DORA to the internal audit universe.

Internal Audit Requirements Under DORA Art. 6(6)

Article 6(6) is the explicit DORA mandate for internal audit. It states that the ICT risk management framework must be subject to internal audit by auditors "on a regular basis in line with the financial entity's audit plan", and that those auditors must possess "sufficient knowledge, skills and expertise in ICT risk, as well as appropriate independence".

Three obligations flow from this short sentence, and supervisors test each of them:

Competence

The auditors must genuinely understand ICT risk — not just financial or process auditing. A generalist internal audit function that ticks "ICT framework reviewed" without the technical depth to challenge encryption design, network segmentation, recovery testing or sub-outsourcing chains will itself become a finding. Many institutions co-source the technical depth: internal audit owns the plan and the opinion, a specialist firm supplies the ICT expertise.

Independence

The auditor cannot review a function they help operate or design. Internal audit sits in the third line of defence; the ICT risk function and the CISO sit in the second and first. The reporting line of internal audit must run to the audit committee / management body, not to the CIO. Supervisors check the organisational chart and the reporting lines, not just the policy.

Follow-up by the management body

Article 6(6) is not satisfied by producing a report. The management body must formally receive audit findings, decide on remediation, allocate resources and track closure. Board minutes must evidence this loop. An audit finding that sits open for three cycles with no documented management response is, in supervisory eyes, worse than the original gap — it signals a governance failure under Article 5 accountability.

Frequency

DORA sets no fixed interval — it is risk-based, governed by the audit plan. In practice: significant institutions and critical or important functions are reviewed at least annually; lower-risk areas on a 2-3 year rotation so that the whole ICT risk framework is covered within a defined cycle. The audit plan itself, and its risk-based rationale, is something supervisors will ask to see.

Supervisory Inspections: How They Work

Supervisory review under DORA is exercised by national competent authorities and, for SSM-significant banks, by the ECB Joint Supervisory Teams. It takes two forms: off-site review (analysis of submitted documentation — the Register of Information, incident reports, the resilience testing programme) and on-site inspection (a supervisory team physically reviewing controls, interviewing staff, sampling evidence).

Triggers

Powers

Under Articles 50 and related provisions, supervisors can require information, conduct on-site inspections, demand remediation within deadlines, impose administrative penalties (amounts set by national law under Art. 50 — no EU-wide cap), issue public censure, and apply qualitative measures. For designated Critical ICT Third-Party Providers, the Lead Overseer regime adds direct ESA oversight (see third-party risk).

DORA Audit Scope by Pillar

Whether internal or supervisory, a DORA audit walks the five pillars. Use the table below as the backbone of an audit programme — each row is a testable control area with its article anchor.

PillarWhat the audit testsAnchor
ICT risk managementBoard-approved framework, ICT risk appetite, three-lines-of-defence model, asset classification, protection & detection controls, ICT business continuity policy, validated RTO/RPOArt. 5-16
Incident managementDetection, classification governance against RTS criteria, 4h/72h/1-month reporting, root-cause discipline, NCA portal readinessArt. 17-23
Resilience testingAnnual testing programme, independence of testers, coverage of critical functions, TLPT lifecycle and attestation where designatedArt. 24-27
Third-party riskRegister of Information completeness, Article 30 mandatory clauses, concentration risk, sub-outsourcing visibility, tested exit strategiesArt. 28-44
Information sharingParticipation arrangements, threat-intelligence handling, GDPR-compliant exchangeArt. 45

Run the free 45-point DORA compliance checklist to get a fast structured read across all five pillars before you scope a formal audit.

The Evidence a DORA Audit Demands

DORA audits are evidence-driven. A control that exists but is not documented is, in audit terms, a control that does not exist. Assemble and keep current the following audit file:

Audit tip: keep this file continuously, not at audit time. Supervisors increasingly run short-notice "dip checks" — if the Register of Information or incident log only reflects reality at the 30 April submission date, a mid-year check will surface the gap.

How to Prepare: DORA Audit Readiness

Audit readiness is a deliberate programme, not a scramble before the supervisor arrives. A proven sequence:

1. Scope and self-assess

Map your entity against all five pillars and the 13 RTS. The free DORA compliance checklist gives a fast structured baseline; a formal gap analysis turns it into a prioritised backlog with ownership and effort estimates.

2. Close the evidence gaps

For every control, ask "could I hand a supervisor the evidence today?" Where the answer is no, the gap is documentation, not control design — and that is the fastest category to fix.

3. Run a mock inspection

A readiness assessment that mirrors the supervisory scope, ideally run by people who have seen real inspections. It surfaces the findings a supervisor would raise — while they still cost only remediation effort.

4. Validate the recovery claims

The most common evidence failure is RTO/RPO that look fine on paper but were never tested end-to-end. Schedule and document the test before the audit, not during it.

5. Brief the management body

Article 5 accountability means the board must be able to speak to the ICT risk position. A pre-audit board briefing is a standard part of readiness work.

The 7 Most Common DORA Audit Findings

  1. Incomplete Register of InformationMissing LEIs, inconsistent service taxonomy, and almost universally weak sub-outsourcing data below Tier 2. The single most frequent finding in 2025 inspections.
  2. Incident classification governanceOutdated internal thresholds causing under-reporting of major incidents; no clear, empowered classification decision owner.
  3. Recovery objectives not validatedRTO/RPO documented but never tested end-to-end, or tested only in isolated components rather than full failover.
  4. Article 30 clauses missing from contractsLegacy vendor master agreements never re-papered with audit rights, exit, sub-outsourcing and data-location clauses.
  5. Superficial board oversightICT risk reaching the board as a status colour rather than quantitative KRIs; minutes that do not evidence real challenge or follow-up.
  6. Internal audit lacks ICT depthA generalist internal audit function reviewing the ICT framework without the competence to challenge it — a finding under Article 6(6) itself.
  7. Open findings left unremediatedPrior audit or inspection findings carried for multiple cycles with no documented management response — read by supervisors as a governance failure.
DORA Audit Support

Get Audit-Ready With Regulation DORA

We are a specialist team focused exclusively on DORA, operational resilience and GRC for EU financial institutions. We help banks, insurers, investment firms and ICT providers walk into a supervisory inspection with a defensible, evidence-complete audit file — and we have run readiness work across institutions in more than 20 EU countries.

Free DORA Gap Analysis

An interactive self-assessment across the five pillars that returns a compliance score and your top audit-risk priorities in minutes. The fastest way to know where you stand — no call, no signup.

Audit Readiness Review

A mock inspection across the five pillars and 13 RTS — run by people who have seen real supervisory reviews. You receive a prioritised remediation backlog, not an enforcement notice.

from €990

Resiplan — continuous evidence

Our specialised SaaS keeps your Register of Information, incident log and audit evidence current and export-ready year-round — so a dip check or inspection is never a scramble.

14-day free trial

Independent of software vendors and testing firms. NDA on every engagement. ISO 27001-aligned handling of client material.

DORA Audit FAQ

What is a DORA audit?

A DORA audit is any structured review of a financial entity's compliance with Regulation (EU) 2022/2554. The term covers three distinct things: (1) supervisory inspections and the off-site review carried out by competent authorities (ECB, BaFin, ACPR, etc.), (2) the mandatory internal audit of the ICT risk management framework required by Article 6(6), and (3) external readiness assessments commissioned voluntarily by the entity to test its compliance before a supervisor does. They share the same reference standard — DORA plus the 13 RTS/ITS — but differ in who runs them and the consequences.

Does DORA require an internal audit of ICT risk?

Yes. Article 6(6) requires that the ICT risk management framework be subject to internal audit by auditors with sufficient knowledge, skills and expertise in ICT risk, on a regular basis and in line with the entity's audit plan. Auditors must be independent of the function being reviewed. The frequency is risk-based — annually for significant institutions and critical functions, less often for lower-risk areas — and the management body must follow up formally on every audit finding.

How often does a DORA audit have to take place?

There is no single fixed interval. The internal audit of the ICT risk framework follows the entity's risk-based audit plan — typically a full cycle every 1 to 3 years with critical areas reviewed annually. Supervisory inspections are scheduled by the competent authority and can happen any time, often as part of the SREP cycle for banks. Resilience testing (vulnerability assessments, scenario tests) is an annual programme, and designated entities run Threat-Led Penetration Testing at least every 3 years.

Who can perform a DORA internal audit?

Article 6(6) requires auditors with sufficient ICT risk knowledge and full independence from the ICT function being audited. This can be the entity's own internal audit department (third line of defence), provided it has the technical competence, or a co-sourced/outsourced specialist firm. Many institutions combine both: internal audit owns the audit plan and an external specialist provides the deep technical capability. The management body remains accountable for acting on the findings regardless of who performs the work.

What do supervisors check during a DORA inspection?

Supervisors focus on evidence, not policy documents. The most scrutinised areas in 2025-2026 inspections are: the completeness and data quality of the Register of Information, the governance behind incident classification, validated recovery objectives (RTO/RPO tested end-to-end), Article 30 contractual clauses in third-party contracts, board-level ICT risk oversight with concrete minutes, and the resilience testing programme. Roughly 60-70% of inspected entities receive material findings on at least one of these themes.

What is a DORA audit readiness assessment?

A readiness assessment is a voluntary, pre-emptive audit run by the entity itself or a specialist firm to find and fix gaps before a supervisor does. It mirrors the supervisory scope — all 5 pillars and the 13 RTS — and produces a prioritised remediation backlog rather than an enforcement notice. It is the lowest-cost way to manage audit risk: a gap found in a readiness assessment costs remediation effort; the same gap found in a supervisory inspection costs a finding, possible capital add-ons and reputational exposure.

What documents are needed for a DORA audit?

Core audit evidence includes: the board-approved ICT risk management framework and ICT business continuity policy, the Register of Information, incident logs with classification rationale, the resilience testing programme and reports (including TLPT attestation where applicable), third-party contracts showing Article 30 clauses, board and committee minutes evidencing ICT risk oversight, RTO/RPO test results, and the prior internal audit reports with management follow-up. DORA audits are evidence-driven — undocumented controls are treated as absent.

What are the consequences of a poor DORA audit?

A weak internal audit result is itself a governance finding. A poor supervisory inspection can trigger qualitative supervisory measures, Pillar 2 capital add-ons for SSM banks (typically 25-100 basis points depending on severity), public censure, and in serious cases activity restrictions. Administrative fines under Article 50 are set by each Member State — DORA fixes no EU-wide cap for entities or for accountable natural persons. The economic impact frequently exceeds the headline fine once capital and reputational effects are included.

How much does a DORA audit or readiness assessment cost?

Cost scales with entity size and scope. A focused readiness review of a single pillar can be a half-day engagement; a full 5-pillar gap assessment for a mid-size institution is typically a multi-day engagement. Specialist fixed-fee formats start at a low-cost entry assessment and scale to full multi-day programmes. The cost of a readiness assessment is a fraction of the cost of a supervisory finding — which is why audit-readiness work has the strongest ROI of any DORA spend.

Does ISO 27001 certification satisfy a DORA audit?

No, but it helps. ISO 27001 controls overlap significantly with the RTS on ICT risk management framework — a certified entity typically meets 60-75% of the control design requirements. But DORA audits also test DORA-specific items that ISO does not cover: incident classification against the RTS thresholds, the Register of Information format, Article 30 contractual clauses, TLPT, and the specific board accountability model. Auditors accept ISO 27001 as evidence of control design but require separate verification of the DORA-specific delta.

Related DORA Resources

What is DORA?

The complete plain-language guide to the regulation, its 5 pillars and scope.

DORA Compliance Checklist

Free interactive 45-point self-assessment across all 5 pillars.

RTS & ITS Standards

All 13 technical standards — the reference your audit is measured against.

Incident Reporting

Classification criteria and the 4h/72h/1-month reporting workflow.

Third-Party Risk

Register of Information and Article 30 clauses — a top audit finding area.

TLPT Guide

Threat-Led Penetration Testing — scope, phases and supervisory attestation.

Gap Analysis Tool

Identify compliance gaps against DORA requirements in under 15 minutes.

DORA Consulting Services

Expert audit-readiness and gap-assessment engagements.

🚀
Next Step · Automate It

Now You Know the Gaps — Close Them With Resiplan

Resiplan runs all five DORA pillars in one platform — no more dozens of spreadsheets and a dedicated team to keep them in sync. Turn your one-off assessment into continuous compliance — automated register of information, incident tracking, vendor risk monitoring, real-time dashboards. Advising several institutions? Each client gets its own separate tenant.

Automated RoI submission
Incident reporting workflow
Vendor risk scoring
Real-time compliance dashboard
Try Resiplan — Free Demo See Pricing →

7-day free trial · No credit card · Cancel anytime

Practitioner tools for DORA compliance teams

Workbooks, playbooks and certifications built for EU financial entities. Add several to your cart: volume discounts apply automatically.

academy-bundle

DORA Certifications Bundle

399 € excl. VAT
academy

DORA for IT & Security Teams

199 € excl. VAT
academy

DORA for ICT Providers & Vendors

199 € excl. VAT
90
certificates issued
60
certified professionals
14
programmes awarded

Browse the full library · Excel toolkits · Certifications

How Compliant Is Your Institution?

Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.

Get Your Free DORA Score Join Free Monthly Webinar