Package 5 · Services
IT audit, DORA and ICT risk management
For financial entities and regulated organisations that must be audit-ready.
Become audit-ready: ICT risk management under Article 6 DORA, evidenced and traceable.
How you know you need this
DORA has applied since 17 January 2025. Supervisors do not ask whether you have a documented framework, but whether it works – and whether you can evidence that.
The register of information is incomplete or does not match the contract register. That is exactly where special audits start.
The IT audit function is thinly staffed, or independence is not cleanly separated: whoever operates the systems cannot audit them independently.
An audit is coming and you want to know where you stand beforehand – rather than finding out during the audit.
What you get
- Audit planning with scoping: what is audited, against which standard, with which statement.
- Review of the ICT risk management framework under Article 6 DORA: governance, risk assessment, measures, monitoring, reporting.
- Review of the register of information under Article 28(3) DORA and reconciliation with contract register and procurement data.
- Review of contractual requirements for ICT third-party providers and exit strategies.
- Review of incident management and recovery: are objectives defined, and has recovery been tested?
- Findings with risk rating, recommendation and priority – each traceably evidenced.
- Remediation plan with owners and dates, plus tracking to completion.
- Report to IIA and DIIR standards; IDW PS 330, IDW PS 860, IDW PS 951, ISAE 3402 and SOC 2 are taken into account where relevant.
How long it takes
Initial audit usually eight to twelve weeks. Annual audits afterwards in a shorter scope.
What you contribute
Access to policies, register, contracts and audit reports, one contact per domain, a kick-off with management.
What is not included
Implementing the remediation. Whoever audits must not implement – otherwise the report loses its independence before the supervisor. Advice on methodology, audit planning and evidence is possible.
Common questions
Can you support our audit function instead of taking it over?
Yes, as co-sourcing: you keep responsibility and the reports, I bring methodology, audit procedures and capacity. That is the most common route with thin staffing.
What is the most common finding?
Backups run, but a restore was never tested. Then permissions that were never recertified, and a register of information that does not match the contract register.
Is a gap analysis enough or do we need the audit?
A gap analysis shows gaps against the regulation; an audit assesses whether the framework works. In the end the supervisor counts the audit with defensible evidence.
Do you work with our audit function or independently?
Both are possible. Independently means: own report, own findings. With your function means: joint audit procedures, the report stays yours.
Initial call
In the first call we clarify whether the package fits your situation. Then you get two proposed dates and a clear statement on effort.
Other packages
- Architecture review – For organisations whose IT grew over years and where nobody has the full picture any more.
- Project and sub-project management – For undertakings that need one accountable person – not another supplier.
- Interim: lead architect / platform operations lead – For vacancies that operations cannot wait for.
- AI architectures and automation – For organisations that must run AI in their own network – without cloud and without outside access.
- Training and seminars – For teams that should be able to do it themselves afterwards.
Contact
Request an initial call
Describe your situation in three sentences. I usually reply within one business day with an assessment and two time slots.