Skip to main content
Image coming soon

CMP1868 Mastering DORA for Financial Services Compliance Leaders

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering DORA for Financial Services Compliance Leaders

Build unshakable reasoning for resilience decisions that stand up to peer review

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Peers question your control choices and you lack concrete, sourced reasoning to defend them

The situation this course is for

Even solid compliance work gets challenged when reviewers don’t see the logic behind thresholds, testing cycles, or vendor classifications. Without documented rationale tied to DORA's intent and EBA guidelines, decisions appear arbitrary, even when they’re sound.

Who this is for

Senior compliance or risk practitioner at a U.S.-based financial institution, embedded in DORA implementation or audit coordination, who must defend design choices to technical peers, internal audit, or control owners outside their function.

Who this is not for

Entry-level analysts, consultants selling generic frameworks, or anyone not actively shaping DORA evidence or control narratives for their firm.

What you walk away with

  • Explain DORA control thresholds using EBA guidelines and peer-reviewed implementation examples
  • Deflect peer challenges with sourced reasoning, not policy repetition
  • Map incident reporting requirements to actual operations timelines
  • Justify third-party risk classifications with documented precedents
  • Produce audit-ready narratives that anticipate follow-up questions

The 12 modules (with all 144 chapters)

Module 1. DORA’s Strategic Intent in U.S. Financial Markets
Understand the regulatory drivers behind DORA, including EBA RTS timelines and how U.S. firms are interpreting cross-border reporting obligations. This module grounds your work in the policy context that shapes review expectations.
12 chapters in this module
  1. Origins of DORA within post-crisis EU financial oversight
  2. Key differences between DORA and existing FFIEC guidance
  3. How U.S. broker-dealers are classifying 'critical ICT providers'
  4. Mapping DORA’s incident reporting to SEC Form 8-K cycles
  5. EBA finalisation status and expected U.S. ripple effects
  6. Defining 'digital operational resilience' in practice
  7. Why legacy SOX controls don’t cover DORA scope
  8. The role of the primary regulator in escalation paths
  9. Timeline for first full compliance cycle reporting
  10. How tiered thresholds apply to third-party contracts
  11. Common misinterpretations in vendor classification
  12. Sources to cite when defending your scope decisions
Module 2. Building Defensible Control Thresholds
Move beyond copying peer thresholds. Learn how to derive and justify your own using EBA guidance, incident data, and operational capacity.
12 chapters in this module
  1. Why 48 hours isn't always the right incident window
  2. Linking incident severity to client impact metrics
  3. Using historical outages to justify recovery targets
  4. Balancing regulator expectations with technical feasibility
  5. Documenting rationale for internal audit review
  6. How to adjust thresholds by business line
  7. Examples of accepted deviations from EBA templates
  8. Peer benchmarking without copying flawed logic
  9. When to escalate threshold decisions upstream
  10. Using change advisory board data to justify timelines
  11. Avoiding over-engineering in non-critical systems
  12. Sources to cite in control design documentation
Module 3. Third-Party Risk Classification Frameworks
Classify vendors with confidence using a repeatable method rooted in DORA Article 5 and EBA Q&A.
12 chapters in this module
  1. Defining materiality for non-banking ICT providers
  2. Mapping vendor services to potential firm-wide impact
  3. Scoring dependencies using network topology data
  4. Documenting rationale for 'critical' versus 'important'
  5. Examples from peer institutions under audit
  6. How to handle multi-vendor service chains
  7. Using contract renewal cycles to phase controls
  8. Aligning with internal procurement classification
  9. Incorporating vendor audit rights into sourcing
  10. Managing shadow ICT through discovery workflows
  11. When self-classification isn’t enough
  12. Sources to defend your classification framework
Module 4. Incident Reporting Workflows and Triggers
Design reporting workflows that meet DORA timelines without over-reporting.
12 chapters in this module
  1. Defining 'significant ICT incident' by impact type
  2. Setting detection thresholds using monitoring data
  3. Integrating with SIEM and service desk systems
  4. Roles and handoffs in escalation chains
  5. Documenting initial versus final assessment windows
  6. How much detail regulators expect in initial reports
  7. Aligning with existing SOX and SEC disclosure cycles
  8. Examples of accepted reporting templates
  9. Avoiding false positives in automated alerts
  10. Using tabletop exercise outcomes to refine triggers
  11. When to involve legal and comms teams early
  12. Sources to cite in reporting policy design
Module 5. Resilience Testing and Audit Readiness
Structure resilience testing that satisfies DORA without creating unsustainable overhead.
12 chapters in this module
  1. Differentiating resilience testing from disaster recovery
  2. Frequency requirements by system criticality tier
  3. Using tabletop exercises to meet minimum standards
  4. Documenting test scope and assumptions clearly
  5. Integrating findings into ongoing control improvements
  6. How much evidence auditors expect to see
  7. Examples of sufficient test summary reports
  8. Managing internal versus external test execution
  9. Timing tests to avoid fiscal close conflicts
  10. Using past findings to justify current posture
  11. Aligning with ISO 22301 where applicable
  12. Sources to defend your testing schedule
Module 6. ICT Provider Subsidiary and Outsourcing Compliance
Ensure outsourced functions meet DORA standards even when outside direct control.
12 chapters in this module
  1. Defining 'subsidiary' under DORA context
  2. Applying controls to offshore development teams
  3. Monitoring compliance through contractual KPIs
  4. Audit rights and access requirements for vendors
  5. Evidence collection from third-party providers
  6. Handling delays in vendor response timelines
  7. Examples of acceptable SLAs for incident reporting
  8. Managing multi-tiered vendor relationships
  9. Using SIG questionnaires effectively
  10. Documenting oversight process for internal audit
  11. How often to review third-party attestations
  12. Sources to cite in oversight framework
Module 7. Internal Governance and Escalation Protocols
Establish clear ownership and escalation paths that reflect DORA’s governance expectations.
12 chapters in this module
  1. Defining roles: CRO versus CISO versus CTO
  2. Creating a DORA-specific steering committee
  3. Integrating with existing risk governance forums
  4. Setting escalation thresholds by incident type
  5. Documenting decision logs for audit review
  6. Managing dual reporting lines in hybrid structures
  7. Using risk appetite statements to guide choices
  8. Examples of effective escalation playbooks
  9. Timing of executive updates
  10. Aligning with board-level reporting cadence
  11. Recording rationale for deferred actions
  12. Sources to justify governance model
Module 8. Data Integrity and Logging Requirements
Meet DORA’s audit logging expectations without overloading existing systems.
12 chapters in this module
  1. Minimum logging requirements by system tier
  2. Retention periods for incident versus audit logs
  3. Securing log access against tampering
  4. Integrating with existing logging infrastructure
  5. Sampling strategies for high-volume systems
  6. Documenting rationale for logging scope
  7. Examples of sufficient log retention policies
  8. Handling cross-border data storage issues
  9. Using logs for post-incident reconstruction
  10. Aligning with SEC Rule 17a-4 where applicable
  11. Managing cost versus compliance trade-offs
  12. Sources to defend your logging design
Module 9. Cyber Threat Intelligence Sharing
Participate in threat sharing without exposing sensitive information.
12 chapters in this module
  1. Understanding DORA’s threat intel exchange mandate
  2. Joining qualified information sharing forums
  3. Classifying threat data for internal dissemination
  4. Protecting client data in shared reports
  5. Using automated feeds without overloading teams
  6. Examples of compliant threat sharing templates
  7. Integrating with FS-ISAC and other bodies
  8. Timing of threat notifications
  9. Documenting participation for auditors
  10. Aligning with existing CISO workflows
  11. Managing vendor participation in sharing
  12. Sources to cite in threat intel program
Module 10. Training and Awareness for DORA Roles
Ensure staff in critical roles understand their DORA responsibilities.
12 chapters in this module
  1. Defining 'relevant personnel' under DORA
  2. Frequency and content of required training
  3. Documenting completion for audit purposes
  4. Tailoring content by role and system access
  5. Examples of effective training modules
  6. Using phishing simulations to reinforce concepts
  7. Integrating with existing compliance training
  8. Managing contractors and temporary staff
  9. Tracking refresh cycles automatically
  10. Avoiding check-the-box training culture
  11. Measuring effectiveness beyond completion
  12. Sources to justify training approach
Module 11. Documentation and Audit Evidence Management
Structure evidence to pass review without last-minute scrambling.
12 chapters in this module
  1. List of mandatory documentation under DORA
  2. Organizing files for quick retrieval
  3. Version control for evolving policies
  4. Using evidence matrices effectively
  5. Examples of sufficient policy statements
  6. Documenting exceptions and compensating controls
  7. Maintaining evidence between audit cycles
  8. Integrating with GRC platforms
  9. Reducing duplication across frameworks
  10. Preparing for EBA or SEC targeted reviews
  11. Handling document retention schedules
  12. Sources to cite in audit preparation
Module 12. Continuous Improvement and Change Management
Build feedback loops that keep your DORA implementation adaptive and credible.
12 chapters in this module
  1. Using audit findings to prioritize updates
  2. Integrating lessons from incident reviews
  3. Updating controls after system changes
  4. Managing change in hybrid cloud environments
  5. Examples of effective post-mortem templates
  6. Aligning with SDLC and change advisory boards
  7. Documenting rationale for control changes
  8. Communicating updates to stakeholders
  9. Tracking improvement metrics over time
  10. Using maturity assessments constructively
  11. Avoiding stagnation in control design
  12. Sources to cite in continuous improvement

How this maps to your situation

  • DORA implementation phase
  • Pre-audit evidence preparation
  • Cross-functional control alignment
  • Peer challenge defense preparation

Before vs. after

Before
You rely on policy documents and general guidance when explaining control choices.
After
You respond to peer questions with specific, sourced examples and documented precedents that align with DORA’s intent and EBA expectations.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: 90 minutes per week over six weeks, or binge in one weekend. Total course time: approximately 18 hours.

If nothing changes
Without defensible reasoning, your control decisions may be overridden or second-guessed, jeopardizing both compliance and credibility.

How this compares to the alternatives

Generic DORA overviews give high-level summaries. This course gives you specific, defensible justifications tied to EBA guidance, peer implementations, and operational reality, so you can stand by your decisions when challenged.

Frequently asked

Will this help me if I’m not in Europe?
Yes. DORA affects all firms with EU exposure, and U.S. regulators are monitoring implementation closely. The course includes specific guidance for U.S.-based financial institutions like Schwab.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Is this relevant to SOX or FFIEC?
Yes. The course shows how DORA complements existing frameworks and where it diverges, so you can avoid redundant work and focus on what’s new.
$199 one-time. 90 minutes per week over six weeks, or binge in one weekend. Total course time: approximately 18 hours..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours