Operationalize DORA
From ICT risk management to incident management to third-party risks: transform requirements into actionable control and evidence logic.
Mehr erfahrenPractical Guides for Financial Institutions
Not a GRC tool. But a structured workspace with practical guides, document templates and methodology — to convert regulatory changes in the financial sector into target states, test programmes, evidence packs and maturity assessments, and stay auditable.
From ICT risk management to incident management to third-party risks: transform requirements into actionable control and evidence logic.
Mehr erfahrenInterlock governance, outsourcing management, risk control and internal audit with DORA and information security requirements.
Mehr erfahrenLeverage ISO/IEC 27001:2022 as international reference for management system, controls, evidence and continuous improvement.
Mehr erfahren12 control objectives for systematic cyber security — from identification through protection and detection to response and recovery. Fully aligned with DORA and ISO 27001.
Mehr erfahrenImplementation Logic
The platform is not a news site, but a structured workspace for target states, measures, evidence and review status.
Clear target images for processes, controls, roles and evidence.
Practical implementation steps instead of abstract standard reproduction.
Examples of documentation, reports, audit trails and committee documents.
Keep drafts, review needs, approvals and publication status separately manageable.
Regulatory Radar
Current regulatory signals of the current calendar week with impact on DORA, MaRisk, EBA, BaFin, Third-Party Risk, Information Register and Evidence.
Current Regulatory Signals
Die EIOPA hat am 26. Mai 2026 die technische Dokumentation zum Risk-Free Rate (RFR) veröffentlicht, die ab dem 30. Januar 2027 anwendbar ist. Die Dokumentation legt die Methode zur Bestimmung der risikofreien Zinsstrukturkurven für die Solvency-II-Berechnung der versicherungstechnischen Rückstellungen fest. Für Institute mit Versicherungstochter oder gemischter Tätigkeit sind Änderungen der Zinskurvenmethodik relevant für die Eigenkapitalplanung.
EIOPA
2026 Priority Modules
These modules address the specific requirements and challenges facing financial institutions in 2026.
Operationalization of the risk-based testing programme according to Art. 24/25 DORA with 12 test types, protection needs model and 36-month cycle.
Go to Test ProgrammePreparation for the annual DORA information register submission with data quality checks, error logs and management approval.
Check ReadinessManagement of ICT third-party relationships including due diligence, contractual requirements, monitoring and concentration risks.
Go to Third-Party RiskExtension of Third-Party Risk Management to non-ICT services according to EBA consultation with Single Register concept.
Go to Third-Party RiskAnalysis of the impact of the 9th MaRisk amendment on institution-specific risk management and integration with DORA requirements.
Go to MaRiskLinking evidence and maturity with test programme, information register and regulatory radar for comprehensive management reporting.
Go to Evidence & MaturityRole Paths
Each role receives specific entry points, relevant modules and recommended working methods for their specific responsibilities.
Key question: How do we ensure our ICT resilience meets regulatory requirements and protects our business?
Key question: How do we ensure the timely and complete submission of all regulatory reports?
Key question: How do we ensure our ICT systems are adequately protected?
Key question: How do we effectively identify, assess and manage ICT risks?
Key question: How do we manage the risks from our ICT third-party relationships?
Key question: How do we evaluate the effectiveness of our ICT resilience measures?
Key question: How do we ensure our information register data is correct and complete?
Key question: How do we identify our critical or important functions?