Skip to main content
Image coming soon

BCM2920 Mastering DORA; A Step-by-Step Guide to Financial Services Resilience

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering DORA; A Step-by-Step Guide to Financial Services Resilience

A complete implementation path for operational resilience in regulated financial institutions

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
DORA evidence packs that require last-minute sourcing across teams

The situation this course is for

Teams in regulated financial institutions are spending 70-100 hours assembling DORA compliance evidence, only to face rework due to misaligned control mapping or missing test results. The pain isn't strategy, it's the deadline-bound package that still lacks signed-off attestation two days before submission.

Who this is for

IC-level compliance, risk, or technology practitioner at a financial institution implementing DORA, responsible for producing or consolidating evidence for internal audit or regulator review

Who this is not for

C-suite executives looking for board-level summaries, consultants selling DORA frameworks, or engineers building resilience tooling without compliance context

What you walk away with

  • Produce regulator-ready DORA evidence packs in under 10 hours
  • Map technical controls directly to DORA Annex IV requirements
  • Automate evidence collection from existing IT and risk systems
  • Reduce rework from control gaps identified in final review
  • Own the narrative when EBA reviewers request follow-up data

The 12 modules (with all 144 chapters)

Module 1. Understanding DORA's Scope and Financial Sector Impact
Clarify which parts of Macquarie’s infrastructure and third-party arrangements fall under DORA’s scope, with mapping to existing ISO 27001 and MiFID II controls.
12 chapters in this module
  1. Defining ICT third-party risk under DORA Article 4
  2. How DORA interacts with existing MiFID II compliance layers
  3. Identifying critical and important functions in your domain
  4. Mapping DORA scope to internal audit reporting lines
  5. Key differences between DORA and previous resilience standards
  6. Regulator expectations for outsourcing oversight
  7. Thresholds for reporting major ICT incidents
  8. Time-bound requirements for incident notification
  9. How EBA guidelines shape national regulator behavior
  10. Preparing for on-site inspection cycles under DORA
  11. Integrating DORA scope with existing risk registers
  12. Documenting in-scope services for evidence collection
Module 2. Building the ICT Risk Register for Regulator Submission
Create a compliant, living risk register that satisfies EBA templates and internal audit requirements.
12 chapters in this module
  1. Structuring the ICT risk register per EBA specifications
  2. Linking risks to business service dependencies
  3. Classifying risk severity with regulator-aligned criteria
  4. Documenting inherent vs residual risk assessments
  5. Incorporating cyber threat intelligence feeds
  6. Updating risk ratings after control changes
  7. Versioning the register for audit trail
  8. Aligning risk language with internal audit taxonomy
  9. Integrating risk ownership into BAU workflows
  10. Automating data pulls from GRC platforms
  11. Handling peer review of risk entries
  12. Preparing the register for supervisory inspection
Module 3. Third-Party Risk Mapping for Critical Providers
Document vendor relationships with evidence that survives deep-dive reviews.
12 chapters in this module
  1. Identifying critical third-party dependencies
  2. Classifying providers under DORA Article 26
  3. Assessing concentration risk across vendors
  4. Documenting due diligence for onboarding
  5. Tracking contractual obligations for audit rights
  6. Mapping SLAs to business continuity requirements
  7. Evaluating cloud provider compliance posture
  8. Handling sub-outsourcing oversight
  9. Running annual third-party reassessments
  10. Collecting SOC 2 and ISO 27001 evidence from vendors
  11. Managing evidence expiry dates
  12. Creating escalation paths for vendor incidents
Module 4. Incident Classification and Reporting Timelines
Ensure major incidents are classified and reported within regulator-defined windows.
12 chapters in this module
  1. Defining 'major incident' under DORA Article 21
  2. Setting up detection triggers in monitoring systems
  3. Classifying incidents by business impact level
  4. Documenting initial assessment within 2 hours
  5. Escalating to internal crisis management
  6. Preparing incident summary for regulator
  7. Meeting 72-hour detailed report deadline
  8. Including root cause and remediation steps
  9. Maintaining incident log for audit
  10. Integrating with existing SOAR platforms
  11. Running tabletop exercises for incident response
  12. Avoiding common classification pitfalls
Module 5. Digital Operational Resilience Testing Plans
Design and document test plans that meet DORA's scope and frequency mandates.
12 chapters in this module
  1. Identifying systems subject to resilience testing
  2. Creating annual testing calendar
  3. Designing scenario-based penetration tests
  4. Involving internal audit in test design
  5. Documenting test scope and methodology
  6. Capturing test results for evidence pack
  7. Addressing findings from previous tests
  8. Integrating red team outputs
  9. Running crisis communication simulations
  10. Ensuring third-party participation in tests
  11. Reporting test outcomes to senior management
  12. Updating test plans based on risk changes
Module 6. Information and Communication Security Controls
Align existing security controls with DORA’s minimum requirements.
12 chapters in this module
  1. Mapping ISO 27001 controls to DORA Annex IV
  2. Documenting access control policies
  3. Verifying multi-factor authentication enforcement
  4. Logging and monitoring privileged access
  5. Encrypting data in transit and at rest
  6. Managing patching cycles for critical systems
  7. Configuring network segmentation
  8. Validating backup and restore procedures
  9. Testing control effectiveness quarterly
  10. Integrating with existing SOC operations
  11. Documenting control ownership
  12. Producing evidence for auditor requests
Module 7. Internal Audit Alignment and Evidence Packaging
Structure evidence submissions to reduce back-and-forth during review cycles.
12 chapters in this module
  1. Understanding internal audit’s DORA checklist
  2. Formatting evidence for audit trail
  3. Linking controls to specific DORA articles
  4. Versioning documents for review cycles
  5. Creating audit-ready index files
  6. Including attestations from control owners
  7. Adding cross-references to policy documents
  8. Highlighting changes from prior submissions
  9. Preparing for sample-based validation
  10. Responding to audit queries efficiently
  11. Tracking open items to closure
  12. Archiving evidence for retention
Module 8. Automating Evidence Collection from Existing Systems
Reduce manual effort by pulling data directly from GRC, ITSM, and security platforms.
12 chapters in this module
  1. Identifying systems with relevant control data
  2. Mapping DORA requirements to data fields
  3. Using APIs to extract evidence automatically
  4. Validating data accuracy from source systems
  5. Scheduling regular evidence syncs
  6. Building dashboards for evidence status
  7. Handling access permissions for data pulls
  8. Integrating with ServiceNow for ticket evidence
  9. Pulling Jira data for project controls
  10. Exporting AWS CloudTrail for audit logs
  11. Normalizing data across platforms
  12. Creating fallback processes for system outages
Module 9. Cross-Functional Coordination for DORA Readiness
Orchestrate inputs from risk, legal, IT, and compliance teams efficiently.
12 chapters in this module
  1. Identifying stakeholders per DORA domain
  2. Setting up recurring coordination meetings
  3. Defining RACI for evidence ownership
  4. Creating shared documentation repositories
  5. Standardizing terminology across teams
  6. Managing handoffs between functions
  7. Resolving conflicting interpretations
  8. Escalating blockers to management
  9. Tracking action items centrally
  10. Aligning on reporting deadlines
  11. Documenting decisions from working groups
  12. Maintaining momentum across quarters
Module 10. Regulator Engagement and Inspection Preparation
Anticipate supervisory questions and structure responses effectively.
12 chapters in this module
  1. Reviewing EBA final reports for focus areas
  2. Preparing narrative for critical functions
  3. Organizing evidence by inspection theme
  4. Anticipating follow-up on control gaps
  5. Conducting pre-inspection dry runs
  6. Training spokespeople for regulator Q&A
  7. Documenting rationale for control choices
  8. Handling document requests under deadline
  9. Maintaining composure during deep dives
  10. Capturing feedback for future cycles
  11. Reporting inspection outcomes internally
  12. Updating playbooks based on feedback
Module 11. Continuous Improvement and Change Management
Keep DORA compliance current as systems and regulations evolve.
12 chapters in this module
  1. Tracking changes in IT infrastructure
  2. Updating risk assessments after major projects
  3. Revising third-party documentation post-contract
  4. Re-testing after control changes
  5. Monitoring regulatory updates from EBA
  6. Subscribing to national competent authority alerts
  7. Incorporating lessons from incidents
  8. Updating policies after audit findings
  9. Running annual DORA compliance training
  10. Measuring maturity over time
  11. Benchmarking against peer institutions
  12. Reporting progress to senior management
Module 12. Building a Reusable DORA Implementation Playbook
Create a living document that survives team changes and audit cycles.
12 chapters in this module
  1. Structuring the playbook for usability
  2. Including step-by-step evidence workflows
  3. Adding screenshots and real examples
  4. Documenting escalation paths
  5. Embedding templates and checklists
  6. Versioning the playbook
  7. Assigning ownership for updates
  8. Onboarding new team members
  9. Integrating with knowledge management
  10. Protecting sensitive information
  11. Sharing non-sensitive parts across teams
  12. Using the playbook for new regulatory standards

How this maps to your situation

  • DORA implementation in financial institutions
  • Regulator-facing evidence preparation
  • Cross-functional compliance coordination
  • Audit and supervisory inspection readiness

Before vs. after

Before
Spending weeks compiling DORA evidence manually, chasing stale documentation, and facing rework during audit cycles.
After
Producing regulator-ready evidence packs in under 10 hours with automated sourcing and validated control mapping.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters total)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 6-8 hours of focused work, designed to be completed in 2-3 sittings, with immediate application to current evidence cycles.

If nothing changes
Without a structured approach, DORA evidence collection will continue to consume disproportionate time during audit cycles, increasing the risk of findings, delays, and reputational exposure during supervisory reviews.

How this compares to the alternatives

Unlike generic DORA overviews or consultant frameworks, this course delivers a step-by-step implementation path with templates and examples tailored to financial services practitioners like you , not theoretical models.

Frequently asked

Is this course focused on technical or policy-level content?
It’s focused on implementation , how to produce evidence, map controls, and meet deadlines using real templates and workflows.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Can I use this if my firm uses a different compliance framework?
Yes , the course teaches how to map DORA to existing controls like ISO 27001, SOC 2, or MiFID II, regardless of your baseline.
$199 one-time. Approximately 6-8 hours of focused work, designed to be completed in 2-3 sittings, with immediate application to current evidence cycles..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours