What is the Conducting ICT Risk Audits Under DORA course about?
Build the audit methodology that satisfies your CAE, your external auditors, and the ECB in a single workpaper trail. ICT risk control tests at regulated banks frequently document what was tested without demonstrating whether the control is effective or who owns it. The CAE sends reports back. Regulators ask questions the workpapers cannot answer without a verbal walkthrough. The audit committee receives.
Why this course?
Banking internal audit is facing a methodology gap that DORA made visible. Before DORA, ICT risk audits were often conducted by technology specialists using IT audit methodology, delegated to external parties, or bundled inside operational risk programmes. DORA made ICT risk a standalone regulatory obligation with its own testing and documentation standards. Most banking internal auditors who now carry ICT risk audits.
What do you take away from the Conducting ICT Risk Audits Under DORA course?
Design ICT risk control tests that produce evidence an ECB or ACPR examiner accepts as complete without requesting additional documentation. Build a control attribute matrix that maps each DORA RTS requirement to a testable control and a named accountable owner. Write findings that survive multiple internal review cycles and retain their substance in the audit committee pack. Construct a workpaper trail so.
What you get with this course?
12 written modules in the Art of Service learning environment, accessible on enrolment Control attribute matrix template populated for a representative banking ICT environment, ready to adapt for the first audit cycle Workpaper trail template covering index structure, cross-reference guide, and review sign-off format Three-tier ownership attestation format ready for fieldwork use DORA RTS-to-testable-control mapping workbook Downloadable templates and worked examples for.
What you will have in hand by Day 1, Week 1, Month 1?
Access to all 12 modules and downloadable templates on enrolment day. Hand-built implementation playbook delivered alongside course access within 24 hours.
What does the Conducting ICT Risk Audits Under DORA cover on before and after?
ICT risk audit workpapers document what was tested without demonstrating control effectiveness or ownership. Reports go back for internal revision. Regulators ask follow-up questions that require verbal reconstruction of the evidence trail. Each ICT risk audit cycle produces a workpaper trail that maps from DORA RTS requirement to control to evidence to finding, with ownership documented at every tier. Reports satisfy CAE.
What happens if you do not address this?
The next ACPR or ECB supervisory review of ICT risk will examine the internal audit function's methodology, not just the ICT function's controls. If the workpapers from prior cycles do not demonstrate effective testing methodology and ownership documentation at the required standard, the finding lands on the audit function itself.
Who it is for?
Internal auditors at regulated banks who now carry ICT risk in their annual audit plan. The senior auditor who can write a financial crime or credit risk finding in an hour but who sat in an ICT risk audit fieldwork session last cycle and realised the testing approach, the evidence standard, and the findings structure are different in ways that were not.
Closely related courses: The DORA ICT Risk Manager Playbook, DORA ICT Risk Classification for Banking Analysts, DORA ICT Controls for Insurance Security Officers, DORA ICT Risk Management for Bank Security Officers.
More answers: what you get with every course, refund policy, all help answers.
A focused course, tailored for you
Conducting ICT Risk Audits Under DORA for Banking
Build the audit methodology that satisfies your CAE, your external auditors, and the ECB in a single workpaper trail.
ICT risk control tests at regulated banks frequently document what was tested without demonstrating whether the control is effective or who owns it. The CAE sends reports back. Regulators ask questions the workpapers cannot answer without a verbal walkthrough. The audit committee receives assurance it cannot verify.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
Banking internal audit is facing a methodology gap that DORA made visible. Before DORA, ICT risk audits were often conducted by technology specialists using IT audit methodology, delegated to external parties, or bundled inside operational risk programmes. DORA made ICT risk a standalone regulatory obligation with its own testing and documentation standards. Most banking internal auditors who now carry ICT risk audits were trained in credit risk, financial crime, or treasury audit, and their methodology does not translate cleanly. The consequence: workpapers that describe controls rather than test them, findings without the ownership attribution DORA requires, and report structures that satisfy the audit team but not the ACPR or ECB examiner reading the same document.
What you walk away with
- Design ICT risk control tests that produce evidence an ECB or ACPR examiner accepts as complete without requesting additional documentation.
- Build a control attribute matrix that maps each DORA RTS requirement to a testable control and a named accountable owner.
- Write findings that survive multiple internal review cycles and retain their substance in the audit committee pack.
- Construct a workpaper trail so the evidence chain from control test to final report requires no reconstruction during examination.
- Conduct a DORA-compliant ICT risk audit from planning through report without importing methodology from another audit domain.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- 12 written modules in the Art of Service learning environment, accessible on enrolment
- Control attribute matrix template populated for a representative banking ICT environment, ready to adapt for the first audit cycle
- Workpaper trail template covering index structure, cross-reference guide, and review sign-off format
- Three-tier ownership attestation format ready for fieldwork use
- DORA RTS-to-testable-control mapping workbook
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
What you will have in hand by Day 1, Week 1, Month 1
Access to all 12 modules and downloadable templates on enrolment day.
Hand-built implementation playbook delivered alongside course access within 24 hours.
Before and after
ICT risk audit workpapers document what was tested without demonstrating control effectiveness or ownership. Reports go back for internal revision. Regulators ask follow-up questions that require verbal reconstruction of the evidence trail.
Each ICT risk audit cycle produces a workpaper trail that maps from DORA RTS requirement to control to evidence to finding, with ownership documented at every tier. Reports satisfy CAE review and ECB examination without additional explanation.
What happens if you do not address this
The next ACPR or ECB supervisory review of ICT risk will examine the internal audit function's methodology, not just the ICT function's controls. If the workpapers from prior cycles do not demonstrate effective testing methodology and ownership documentation at the required standard, the finding lands on the audit function itself.
Who it is for
Internal auditors at regulated banks who now carry ICT risk in their annual audit plan. The senior auditor who can write a financial crime or credit risk finding in an hour but who sat in an ICT risk audit fieldwork session last cycle and realised the testing approach, the evidence standard, and the findings structure are different in ways that were not obvious before the audit started.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Five to seven hours across the 12 modules. Templates are ready to apply in the first fieldwork cycle after completion.
Why $199 is the right number
IIA training on technology audit covers general methodology but does not address DORA's specific ICT risk requirements for EU-regulated banks. Big4 advisory on DORA implementation covers the second-line compliance function, not the testing methodology the internal audit function needs to conduct, document, and report. This course covers the intersection: how a banking internal auditor conducts, evidences, and reports an ICT risk audit that satisfies both internal quality standards and supervisory examination.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.