Zum Inhalt springen

DORA Exit Workspace

Board Approval Pack

Structured decision template for the management body. Each exit run requires defined decision points with documented resolutions, risk assessments, and evidence.

Note: This decision matrix structures the governance process but does not replace legal review of the specific exit situation.

Decision Flow Across the Exit Lifecycle

1

Phase 1: Sourcing & Due Diligence

Activation Decision → Sourcing Decision → Budget Approval

2

Phase 2: Implementation

Scenario Decision → Technical Specification → Security Concept

3

Phase 3: Integration & Data Migration

Reconciliation Proof → Integrity Confirmation → Data Release

4

Phase 4: Test & Dry-Run

Security Clearance → Penetration Test → Cutover Approval → Point of No Return

5

Phase 5: Transition & Cutover

Go-Live Approval → Fallback Decision → Residual Risk Decision → Operational Proof

Activation Decision

Formal determination that an exit trigger has occurred and the exit process is activated. Resolution to enter the review phase.

Required: Trigger Proof, Initial Assessment

Sourcing Decision

Determination of the selected sourcing scenario: insourcing, switch to another provider, cloud migration or hybrid model. Resolution with economic analysis.

Required: Scenario Comparison, Cost Estimate

Budget Approval

Release of the exit budget including penalties, parallel operating costs, personnel expenses and risk buffer. Milestone-based partial releases possible.

Required: Cost Model, Budget Plan

Scenario Decision

Confirmation of the detailed exit scenario including migration sequence, schedule and risk assessment. Basis for operational planning.

Required: Detailed Migration Plan

Point of No Return

Formal decision after which a return to the old service provider is no longer economically or technically feasible. Highest escalation level.

Required: Risk Analysis, Legal Opinion

Cutover Approval

Final release before production switch. Confirmation that all security, portability and integrity proofs are available and the cutover plan is ready.

Required: Pre-Cutover Checklist, Security Clearance

Fallback Decision

Determination of fallback criteria and scenarios in case the cutover fails or is unstable. Defined in advance, not ad-hoc.

Required: Fallback Scenarios, Rollback Plan

Residual Risk Decision

Conscious acceptance of remaining risks after the exit. Documented residual risks, mitigation measures and acceptance by the management body.

Required: Risk Inventory, Action Plan

Customer Impact Analysis

Assessment of the exit impact on customers: service continuity, data access, communication obligations. Proof that no disproportionate disadvantages arise.

Required: Customer Impact Assessment, Communication Plan

License-to-Operate Impact

Review of whether the exit affects the institution's operating license or regulatory classification. Reporting obligations per DORA Art. 28 and MaRisk AT 9.

Required: Regulatory Assessment, Draft Report

Residual Risk Register

Continuously maintained register of all risks remaining after the exit — including responsible parties, deadlines and monitoring intervals.

Required: Risk Register, Monitoring Plan

Decision Log

Complete documentation of all board decisions in the exit process. Evidence for audit and supervisory authority that every decision was made informed and documented.

Required: Minutes, Decision Templates

Request a Pilot Meeting

We will guide you through the entire board approval process — from the first activation decision to the documented exit completion.

Request Pilot Meeting