Package 5 · Services

IT audit, DORA and ICT risk management

For financial entities and regulated organisations that must be audit-ready.

Become audit-ready: ICT risk management under Article 6 DORA, evidenced and traceable.

How you know you need this

DORA has applied since 17 January 2025. Supervisors do not ask whether you have a documented framework, but whether it works – and whether you can evidence that.

The register of information is incomplete or does not match the contract register. That is exactly where special audits start.

The IT audit function is thinly staffed, or independence is not cleanly separated: whoever operates the systems cannot audit them independently.

An audit is coming and you want to know where you stand beforehand – rather than finding out during the audit.

What you get

  • Audit planning with scoping: what is audited, against which standard, with which statement.
  • Review of the ICT risk management framework under Article 6 DORA: governance, risk assessment, measures, monitoring, reporting.
  • Review of the register of information under Article 28(3) DORA and reconciliation with contract register and procurement data.
  • Review of contractual requirements for ICT third-party providers and exit strategies.
  • Review of incident management and recovery: are objectives defined, and has recovery been tested?
  • Findings with risk rating, recommendation and priority – each traceably evidenced.
  • Remediation plan with owners and dates, plus tracking to completion.
  • Report to IIA and DIIR standards; IDW PS 330, IDW PS 860, IDW PS 951, ISAE 3402 and SOC 2 are taken into account where relevant.

How long it takes

Initial audit usually eight to twelve weeks. Annual audits afterwards in a shorter scope.

What you contribute

Access to policies, register, contracts and audit reports, one contact per domain, a kick-off with management.

What is not included

Implementing the remediation. Whoever audits must not implement – otherwise the report loses its independence before the supervisor. Advice on methodology, audit planning and evidence is possible.

Common questions

Can you support our audit function instead of taking it over?

Yes, as co-sourcing: you keep responsibility and the reports, I bring methodology, audit procedures and capacity. That is the most common route with thin staffing.

What is the most common finding?

Backups run, but a restore was never tested. Then permissions that were never recertified, and a register of information that does not match the contract register.

Is a gap analysis enough or do we need the audit?

A gap analysis shows gaps against the regulation; an audit assesses whether the framework works. In the end the supervisor counts the audit with defensible evidence.

Do you work with our audit function or independently?

Both are possible. Independently means: own report, own findings. With your function means: joint audit procedures, the report stays yours.

Initial call

In the first call we clarify whether the package fits your situation. Then you get two proposed dates and a clear statement on effort.

Request an initial call

Other packages

All services

Contact

Request an initial call

Describe your situation in three sentences. I usually reply within one business day with an assessment and two time slots.

Required

Required. Used only to answer you.

Required. 20 to 4000 characters.

Required fields are marked with *.