Skip to main content
Image coming soon

CMP7434 Mastering DORA for Financial Services Compliance Leaders

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering DORA for Financial Services Compliance Leaders

A structured path to full compliance and operational resilience under the Digital Operational Resilience Act

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

Compliance, risk, and governance practitioners in financial services, particularly IC-level roles at global institutions preparing for DORA compliance deadlines.

Who this is not for

Entry-level analysts, vendor auditors, or teams focused exclusively on non-financial sector regulations.

What you walk away with

  • Map DORA requirements directly to internal controls with confidence
  • Anticipate EBA supervisory expectations in audit and reporting cycles
  • Structure testing evidence that satisfies internal and external reviewers
  • Navigate ICT third-party risk management under DORA Article 25
  • Lead internal stakeholders through mapping and gap assessments

The 12 modules (with all 144 chapters)

Module 1. DORA Scope and Applicability for Global Financial Institutions
Understand which parts of Macquarie’s operations fall under DORA’s scope, including subsidiaries, outsourcing arrangements, and critical ICT functions.
12 chapters in this module
  1. Defining ICT-related services under DORA Article 4
  2. Determining materiality thresholds for reporting entities
  3. Applying DORA to non-EU branches with EU exposure
  4. Exemptions and exclusions under national transposition
  5. Mapping entity types: credit institutions vs. financial institutions
  6. Understanding ‘significant’ ICT third-party dependencies
  7. Role of national competent authorities in scope determination
  8. How DORA interacts with MiFID II and PSD2 classifications
  9. Case study: scope determination at a global investment bank
  10. Common misclassifications in pre-DORA assessments
  11. Key documentation required for initial scope submission
  12. First steps in scoping a multi-jurisdictional entity
Module 2. ICT Risk Management Framework Requirements
Build a compliant ICT risk management framework aligned with DORA Article 7 and EBA guidelines.
12 chapters in this module
  1. Core components of a DORA-compliant risk taxonomy
  2. Establishing risk ownership across business and IT units
  3. Integrating DORA with existing ISO 27001 and NIST CSF practices
  4. Documenting risk appetite statements for ICT disruptions
  5. Risk assessment frequency and trigger events
  6. Linking risk registers to incident reporting thresholds
  7. Third-party risk integration under DORA Article 25
  8. Tools for automated risk scoring and heat mapping
  9. Benchmarking against EBA’s risk tolerance expectations
  10. Common gaps in current-phase risk frameworks
  11. Role of internal audit in validating framework design
  12. How to structure evidence for supervisory review
Module 3. Incident Classification and Reporting Under DORA
Classify and escalate ICT incidents according to EBA severity thresholds and reporting timelines.
12 chapters in this module
  1. Understanding major vs. significant incident criteria
  2. Incident types: cyber, infrastructure, human error, vendor
  3. Calculating incident impact on operations and clients
  4. Time-based thresholds for initial and follow-up reports
  5. Required fields in EBA’s standardized reporting template
  6. Internal coordination between IT, legal, and compliance
  7. Handling cross-border incident implications
  8. Testing incident response workflows
  9. Documentation required for supervisory follow-up
  10. Common reporting delays and how to avoid them
  11. How regulators assess timeliness and completeness
  12. Case study: post-incident review at a European bank
Module 4. Digital Operational Resilience Testing Programs
Design and lead resilience testing programs that meet DORA Article 10 requirements.
12 chapters in this module
  1. Types of testing: IST, BCT, scenario coverage
  2. Defining severity scenarios based on business impact
  3. Engaging internal and external red teams
  4. Third-party dependency testing under DORA Article 25
  5. Test frequency and independence standards
  6. Documentation of findings and action plans
  7. How to escalate unresolved gaps to senior management
  8. Integrating findings into risk register updates
  9. Supervisory expectations for test scope completeness
  10. Tools for tracking testing maturity over time
  11. Benchmarking against peer institution test depth
  12. Case example: progress tracking over three cycles
Module 5. ICT Third-Party Risk Management
Implement DORA-compliant oversight of critical ICT third-party relationships.
12 chapters in this module
  1. Defining ‘critical’ and ‘important’ third parties
  2. Due diligence requirements before contract signing
  3. Right-to-audit provisions under DORA Article 25
  4. Ongoing monitoring of vendor performance and security
  5. Subcontractor oversight and transparency mandates
  6. Exit planning and transition readiness
  7. Joint resilience testing with vendors
  8. Escalation paths for vendor-related incidents
  9. Reporting third-party issues to competent authorities
  10. Common pitfalls in multi-vendor environments
  11. Role of procurement in pre-contract DORA screening
  12. Model clauses for DORA-aligned vendor contracts
Module 6. Information Sharing Frameworks Under DORA
Establish compliant mechanisms for sharing cyber threat information within the financial sector.
12 chapters in this module
  1. Understanding DORA’s five information sharing arrangements
  2. Eligibility criteria for joining sectoral information-sharing bodies
  3. Types of information that can be shared under safe harbor
  4. Internal approval process for submissions
  5. Handling anonymization requirements
  6. Response time expectations for shared alerts
  7. Legal protections under Article 15
  8. Coordination between internal CSIRT and external bodies
  9. Documentation of information shared and received
  10. Case study: responding to a cross-institution phishing alert
  11. How information feeds into risk and incident frameworks
  12. Building a culture of proactive sharing
Module 7. Compliance Function Roles Under DORA
Clarify the responsibilities of compliance officers in DORA implementation and oversight.
12 chapters in this module
  1. Compliance vs. CISO vs. business unit responsibilities
  2. Oversight of framework alignment and update cycles
  3. Reporting lines to senior management and boards
  4. Tracking regulatory change across EBA, ECB, and ESMA
  5. Internal assurance over DORA control effectiveness
  6. Coordination with external auditors and consultants
  7. Handling audit findings and remediation timelines
  8. Maintaining independence in review functions
  9. Escalation protocols for non-compliance issues
  10. Training plans for compliance team DORA readiness
  11. Supervisory expectations for compliance documentation
  12. How to demonstrate continuous improvement
Module 8. Supervisory Reporting and Review Process
Prepare for and respond to regulator-led DORA compliance assessments.
12 chapters in this module
  1. Understanding EBA’s timeline for supervisory convergence
  2. Common inspection focus areas by jurisdiction
  3. Document requests: what to prepare in advance
  4. Interview expectations for compliance and IT leads
  5. Evidence folder structure for efficient review
  6. Handling follow-up questions from supervisors
  7. How findings are classified and remediated
  8. Cross-border coordination between regulators
  9. Benchmarking against other institution reviews
  10. Public disclosure requirements post-review
  11. Internal preparation checklist for audit cycles
  12. Case example: resolving a major deficiency finding
Module 9. Integration with Existing Regulatory Frameworks
Align DORA requirements with existing MiFID II, GDPR, and internal governance standards.
12 chapters in this module
  1. Mapping DORA controls to MiFID II Article 38
  2. GDPR and DORA intersection on incident reporting
  3. SOX and DORA overlap on internal control documentation
  4. How ISO 27001 supports DORA evidence generation
  5. NIST CSF as a foundation for resilience testing
  6. Integrating BCBS 239 data resilience principles
  7. Avoiding duplication in audit and reporting
  8. Creating a unified compliance calendar
  9. Tooling for cross-framework control tracking
  10. Reporting efficiency gains from integrated frameworks
  11. Case study: single source of truth for compliance
  12. How to structure cross-functional alignment
Module 10. Executive Oversight and Governance Documentation
Support senior management in fulfilling their DORA-mandated governance responsibilities.
12 chapters in this module
  1. Required board-level reporting elements
  2. Minutes content expectations for DORA compliance
  3. Documentation of management oversight meetings
  4. Escalation thresholds for executive awareness
  5. Role of CEO and CRO in sign-off cycles
  6. Business continuity integration points
  7. Strategic risk appetite statements
  8. Resource allocation decisions for resilience
  9. Succession planning for key DORA roles
  10. Training records for senior management
  11. External reporting to shareholders
  12. How to structure annual compliance statements
Module 11. Internal Audit Readiness for DORA
Ensure internal audit teams are prepared to validate DORA compliance across the enterprise.
12 chapters in this module
  1. Defining audit scope in a multi-jurisdictional context
  2. Sampling strategies for control testing
  3. Evidence requirements for control effectiveness
  4. Assessing third-party testing sufficiency
  5. Reporting findings to management and audit committee
  6. Linking audit results to risk appetite breaches
  7. Coordination with external supervisory audits
  8. Using audit results to update risk frameworks
  9. Audit follow-up on remediation progress
  10. Training internal auditors on DORA specifics
  11. Benchmarking audit maturity across cycles
  12. Building long-term assurance capacity
Module 12. Sustaining Compliance Beyond Initial Implementation
Establish a continuous improvement cycle for DORA compliance.
12 chapters in this module
  1. Monitoring regulatory updates from EBA and ESAs
  2. Updating frameworks to reflect new guidance
  3. Change management for control adjustments
  4. Annual review and refresh of testing programs
  5. Maintaining staff training and awareness
  6. Tracking key compliance metrics over time
  7. Benchmarking against industry peers
  8. Preparing for future EU regulatory waves
  9. Building institutional memory
  10. Documenting lessons learned
  11. Handover protocols for key roles
  12. Creating a living compliance playbook

How this maps to your situation

  • Initial scoping and classification
  • Framework design and integration
  • Testing and incident readiness
  • Ongoing governance and audit

Before vs. after

Before
Working reactively to DORA requirements with fragmented processes and unclear ownership.
After
Leading structured, evidence-backed DORA implementation across teams with confidence and visibility.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 90 minutes per module, designed for completion over 6-8 weeks with flexible pacing.

If nothing changes
Without structured DORA mastery, compliance efforts risk inefficiency, regulatory scrutiny, and missed opportunities for professional influence.

How this compares to the alternatives

Unlike generic compliance overviews, this course delivers actionable, DORA-specific workflows and evidence templates tailored to financial institutions. No other resource provides this level of structural depth for IC practitioners.

Frequently asked

Is this course relevant for non-EU subsidiaries?
Yes. If your institution serves EU clients or has EU regulatory exposure, DORA applies. The course includes jurisdictional mapping and threshold guidance.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Will this help with EBA Q&A submissions?
Yes. Modules cover how to structure responses, provide evidence, and align with EBA expectations.
$199 one-time. Approximately 90 minutes per module, designed for completion over 6-8 weeks with flexible pacing..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours