Skip to main content
Image coming soon

Become the Go-To Person for DORA Inside Northern Trust

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Become the Go-To Person for DORA Inside the firm

Position yourself as the internal expert on Digital Operational Resilience Act compliance

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Most compliance practitioners react to DORA mandates. The few who lead are the ones others consult before decisions are made.

The situation this course is for

Without a clear internal voice, teams default to external consultants or delayed decisions. The person who owns DORA interpretation gains influence across risk, tech, and executive planning cycles.

Who this is for

Mid-senior compliance, risk, or governance practitioner in a regulated financial institution leading teams and shaping internal practice on operational resilience topics, especially DORA.

Who this is not for

This is not for entry-level analysts, external auditors, or consultants selling DORA services. It’s for internal practitioners building authority on how DORA lands in their own organization.

What you walk away with

  • Recognized as the first internal point of contact for DORA-related decisions
  • Equipped with a documented interpretation framework for DORA articles
  • Confident in leading internal responses to regulator inquiries on resilience
  • Credible across tech, risk, and legal teams when coordinating DORA actions
  • Positioned to influence how DORA requirements are translated into policy

The 12 modules (with all 144 chapters)

Module 1. DORA Scope Mapping
Define exactly which systems and services fall under DORA’s mandate at the firm. Use real firm structure to isolate in-scope entities.
12 chapters in this module
  1. Identify critical ICT third-party dependencies
  2. Map services to DORA's seven categories
  3. Classify internal systems by risk tier
  4. Document justification for scope boundaries
  5. Align with EBA ITS taxonomy
  6. Flag borderline services for review
  7. Integrate with existing inventory systems
  8. Update mapping quarterly by design
  9. Link to governance charter
  10. Assign ownership for updates
  11. Track changes over time
  12. Visualize scope for leadership
Module 2. Framework Alignment
Connect DORA to existing internal controls. Show how ISO 27001, NIST CSF, and SOC 2 already cover parts of the rule.
12 chapters in this module
  1. Crosswalk DORA articles to ISO 27001 controls
  2. Map threat scenarios to NIST CSF functions
  3. Identify gaps using SOC 2 Type II reports
  4. Leverage existing GRC platforms
  5. Document compliance overlap
  6. Avoid redundant controls
  7. Prioritize new control development
  8. Use control owners as validators
  9. Align reporting cadence
  10. Integrate with audit plans
  11. Update mapping with rule changes
  12. Maintain version control
Module 3. Internal Interpretation Guide
Build your own firm-specific playbook for how DORA applies. Turn vague articles into operational decisions.
12 chapters in this module
  1. Define 'critical' for the firm context
  2. Interpret 'resilience testing' frequency
  3. Set thresholds for incident reporting
  4. Determine documentation standards
  5. Clarify vendor management expectations
  6. Standardize internal communication
  7. Create precedent for edge cases
  8. Link to legal team guidance
  9. Document rationale for decisions
  10. Archive version history
  11. Train new hires on guide
  12. Update after regulator feedback
Module 4. Incident Response Planning
Design a DORA-specific incident workflow that meets EBA timelines and internal escalation paths.
12 chapters in this module
  1. Classify severity levels by impact
  2. Define internal notification chain
  3. Set clock start for 24-hour rule
  4. Prepare regulator-facing summary
  5. Identify evidence retention needs
  6. Integrate with SOC shift patterns
  7. Automate alert routing
  8. Build runbook for Level 1 triage
  9. Assign decision authority
  10. Test quarterly by design
  11. Document after-action reviews
  12. Update playbook from tests
Module 5. Third-Party Oversight
Structure vendor assessments and ongoing monitoring to meet DORA’s strict outsourcing rules.
12 chapters in this module
  1. Identify all ICT third parties
  2. Classify by criticality and risk
  3. Map contract clauses to DORA
  4. Assess right to audit
  5. Review subcontracting chains
  6. Plan on-site validation
  7. Score resilience plans
  8. Conduct due diligence interviews
  9. Document oversight frequency
  10. Integrate with procurement
  11. Report findings quarterly
  12. Escalate recurring gaps
Module 6. Resilience Testing Program
Launch a rolling cycle of threat-led penetration tests and scenario drills that satisfy DORA and internal risk appetite.
12 chapters in this module
  1. Define test scope by criticality
  2. Select external testing firms
  3. Schedule annual deep dives
  4. Conduct semi-annual drills
  5. Design scenario realism
  6. Involve legal and comms
  7. Measure detection speed
  8. Track response effectiveness
  9. Report to senior management
  10. Archive findings
  11. Share lessons across teams
  12. Update plans post-test
Module 7. Regulator Engagement
Anticipate and shape how DORA inquiries are answered, before they land on someone else’s desk.
12 chapters in this module
  1. Monitor EBA interpretation updates
  2. Log prior regulator questions
  3. Prepare response templates
  4. Assign primary reviewer
  5. Review draft answers early
  6. Coordinate with legal
  7. Flag emerging themes
  8. Build case library
  9. Track open items
  10. Summarize for executives
  11. Archive submissions
  12. Update playbook quarterly
Module 8. Cross-Team Coordination
Run DORA as a shared practice, not a top-down mandate. Earn buy-in from tech, legal, and ops teams.
12 chapters in this module
  1. Map stakeholders by influence
  2. Host monthly alignment calls
  3. Define shared success metrics
  4. Document handoffs
  5. Create RACI for key tasks
  6. Integrate with sprint planning
  7. Share progress transparently
  8. Celebrate milestones
  9. Resolve conflicts early
  10. Rotate facilitation roles
  11. Gather feedback quarterly
  12. Adjust rhythm as needed
Module 9. Policy Drafting
Write internal policies that reflect DORA requirements without copying regulatory language.
12 chapters in this module
  1. Define ownership for each policy
  2. Use plain language for compliance
  3. Embed review cycles
  4. Link to control evidence
  5. Set approval authority
  6. Publish versioned history
  7. Train teams on updates
  8. Track attestation
  9. Align with global standards
  10. Integrate with onboarding
  11. Audit policy adherence
  12. Improve from feedback
Module 10. Audit Evidence Curation
Keep evidence ready and credible for both internal audits and EBA spot checks.
12 chapters in this module
  1. Define evidence types by article
  2. Set retention period per rule
  3. Organize digital repository
  4. Label files clearly
  5. Verify accessibility
  6. Assign custodians
  7. Update after changes
  8. Prep quarterly snapshots
  9. Run mock inspections
  10. Address findings fast
  11. Log exceptions
  12. Close loop with teams
Module 11. Executive Communication
Translate DORA progress and risk into executive-level summaries that inform decisions.
12 chapters in this module
  1. Define what leadership needs
  2. Summarize exposure in business terms
  3. Visualize testing results
  4. Report vendor risk heatmaps
  5. Highlight incident trends
  6. Track milestone progress
  7. Explain trade-offs
  8. Use precedent to justify
  9. Limit jargon
  10. Time updates with cycles
  11. Solicit feedback
  12. Adjust format as needed
Module 12. Continuous Improvement
Make DORA part of normal operations, self-correcting, not a one-time project.
12 chapters in this module
  1. Measure maturity annually
  2. Benchmark against peers
  3. Review regulatory updates
  4. Update internal guide
  5. Refresh training
  6. Optimize workflows
  7. Reduce manual effort
  8. Leverage automation
  9. Share best practices
  10. Mentor emerging leaders
  11. Propose process changes
  12. Celebrate self-sufficiency

How this maps to your situation

  • When a new vendor contract comes in for review
  • Before the annual resilience testing cycle begins
  • After a regulator asks about DORA readiness
  • During the Q3 compliance planning session

Before vs. after

Before
DORA compliance is managed reactively, relying on external guidance and fragmented internal efforts.
After
You lead with a clear, internal playbook, others consult you first, and your advice shapes firm-wide resilience.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 90 minutes per module, designed to fit around core responsibilities. Most practitioners complete the course in 6-8 weeks.

If nothing changes
Without a clear internal voice on DORA, teams default to consultants, delays, or inconsistent application, all of which increase regulatory exposure and dilute your strategic influence.

How this compares to the alternatives

Generic DORA training teaches compliance checklists. This course builds your authority to interpret, lead, and decide, so you’re not just following the rule, you’re shaping how it lands.

Frequently asked

Is this course specific to financial services?
Yes. Every example, template, and decision framework is built for regulated financial institutions like the firm.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Will this help me lead cross-functional teams?
Yes. Modules on coordination, communication, and policy include playbooks for earning buy-in and resolving conflicts across tech, legal, and risk teams.
$199 one-time. Approximately 90 minutes per module, designed to fit around core responsibilities. Most practitioners complete the course in 6-8 weeks..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours