← back to overview
DORA-AI · regulation pack · preview

DORA — Digital Operational Resilience Act (AI overlay)

Regulation (EU) 2022/2554 — Digital Operational Resilience Act, with the AI-specific overlay applied to ICT third-party risk management. In force since 17 January 2025. Targets EU financial entities (banks, insurers, investment firms, payment institutions) and the AI systems they consume from ICT third-party providers. The EU's first joint Critical Third-Party Providers (CTPPs) list was published in November 2025 — DORA's CTPP oversight directly reaches the hyperscalers that ship foundation-model AI to EU FS customers.

jurisdiction · EU version · 2025.01 effective · Jan. 17, 2025 requirements · 9
EU Joint Oversight Forum · CTPP designation

Direct ESA oversight reaches your AI suppliers — not just your bank.

DORA's Article 31 creates the EU's first cross-border oversight regime for Critical Third-Party Providers (CTPPs). The first CTPP list was published in November 2025 and reaches the hyperscalers that ship foundation-model AI to EU financial entities. This pack maps your AI vendor inventory to the CTPP register and produces the concentration-risk documentation your competent authority will expect at the next examination.

  • Register of Information with AI-vendor sub-processor disclosure (Art. 28)
  • Concentration-risk map across CTPP dependencies (Art. 31)
  • Exit-strategy templates for AI-as-a-service contracts (Art. 30)
  • TLPT-aligned testing programme covering AI use cases (Art. 24)
requirements — preview
Art. 5 · Article high-risk gate

ICT risk management framework

Establish a sound, comprehensive, and well-documented ICT risk management framework covering AI systems used in critical or important functions.

artifact: ict_risk_frameworkartifact: ai_policy evidence: risk_registerevidence: board_signoff
Art. 8 · Article high-risk gate

Identification of ICT-related risks

Identify, classify, and document all ICT-supported business functions (including AI-driven ones), assets, and the information assets they handle. Maintain an inventory updated at least annually.

artifact: vendor_register_entryartifact: third_party_ai_register evidence: asset_inventoryevidence: model_inventory
Art. 17 · Article high-risk gate

ICT-related incident management process

Establish and implement an ICT-related incident management process to detect, manage, and notify ICT-related incidents — including AI hallucination / bias incidents that disrupt critical functions.

artifact: incident_response_runbook evidence: incident_logevidence: tabletop_exercise
remaining 6 requirements — locked
Art. 19 · Article

Reporting of major ICT-related incidents

Report major incidents to competent authorities. Initial, intermediate, and final reports per the technical RTS. AI-system outages that breach the materiality thresholds are in scope.

Art. 24 · Article

Digital operational resilience testing

Test ICT systems regularly. For significant entities, threat-led penetration testing (TLPT) every three years. AI systems used in critical functions are scoped into the testing programme.

Art. 28 · Article

General principles — ICT third-party risk

Manage ICT third-party risk as an integral component of ICT risk. Maintain a Register of Information for all contractual arrangements, including AI-as-a-service vendors and foundation-model providers.

Art. 30 · Article

Key contractual provisions

Contracts with ICT third-party service providers must contain rights to audit, monitor, terminate, and ensure exit strategies. AI vendor contracts must include model versioning, data lineage attestations, and sub-processor disclosure.

Art. 31 · Article

Critical Third-Party Providers (CTPPs)

ICT services from designated CTPPs (the EU Joint Oversight Forum published the first list in November 2025) are subject to direct oversight by ESAs. Financial entities consuming AI from CTPPs must document those dependencies and implement concentration-risk controls.

Art. 45 · Article

Information-sharing arrangements

Financial entities may exchange information and intelligence on cyber threats, including AI-specific attack patterns (prompt-injection campaigns, jailbreak repositories, model poisoning).

Unlock the full DORA-AI pack

Get all 6 remaining requirements, generated reports, evidence-mapping templates, and the audit-chain export. Cancel anytime.

Unlock the pack → or full platform

Not ready to buy? Run the free EU AI Act gap report.

12-question intake mapped to Articles 9-15. Branded PDF in your inbox in minutes. No card required.

Free gap report →