A tailored course, built for your situation
Mastering DORA for Financial Services Compliance Leaders
A structured path to full compliance and operational resilience under the Digital Operational Resilience Act
Who this is for
Compliance, risk, and governance practitioners in financial services, particularly IC-level roles at global institutions preparing for DORA compliance deadlines.
Who this is not for
Entry-level analysts, vendor auditors, or teams focused exclusively on non-financial sector regulations.
What you walk away with
- Map DORA requirements directly to internal controls with confidence
- Anticipate EBA supervisory expectations in audit and reporting cycles
- Structure testing evidence that satisfies internal and external reviewers
- Navigate ICT third-party risk management under DORA Article 25
- Lead internal stakeholders through mapping and gap assessments
The 12 modules (with all 144 chapters)
- Defining ICT-related services under DORA Article 4
- Determining materiality thresholds for reporting entities
- Applying DORA to non-EU branches with EU exposure
- Exemptions and exclusions under national transposition
- Mapping entity types: credit institutions vs. financial institutions
- Understanding ‘significant’ ICT third-party dependencies
- Role of national competent authorities in scope determination
- How DORA interacts with MiFID II and PSD2 classifications
- Case study: scope determination at a global investment bank
- Common misclassifications in pre-DORA assessments
- Key documentation required for initial scope submission
- First steps in scoping a multi-jurisdictional entity
- Core components of a DORA-compliant risk taxonomy
- Establishing risk ownership across business and IT units
- Integrating DORA with existing ISO 27001 and NIST CSF practices
- Documenting risk appetite statements for ICT disruptions
- Risk assessment frequency and trigger events
- Linking risk registers to incident reporting thresholds
- Third-party risk integration under DORA Article 25
- Tools for automated risk scoring and heat mapping
- Benchmarking against EBA’s risk tolerance expectations
- Common gaps in current-phase risk frameworks
- Role of internal audit in validating framework design
- How to structure evidence for supervisory review
- Understanding major vs. significant incident criteria
- Incident types: cyber, infrastructure, human error, vendor
- Calculating incident impact on operations and clients
- Time-based thresholds for initial and follow-up reports
- Required fields in EBA’s standardized reporting template
- Internal coordination between IT, legal, and compliance
- Handling cross-border incident implications
- Testing incident response workflows
- Documentation required for supervisory follow-up
- Common reporting delays and how to avoid them
- How regulators assess timeliness and completeness
- Case study: post-incident review at a European bank
- Types of testing: IST, BCT, scenario coverage
- Defining severity scenarios based on business impact
- Engaging internal and external red teams
- Third-party dependency testing under DORA Article 25
- Test frequency and independence standards
- Documentation of findings and action plans
- How to escalate unresolved gaps to senior management
- Integrating findings into risk register updates
- Supervisory expectations for test scope completeness
- Tools for tracking testing maturity over time
- Benchmarking against peer institution test depth
- Case example: progress tracking over three cycles
- Defining ‘critical’ and ‘important’ third parties
- Due diligence requirements before contract signing
- Right-to-audit provisions under DORA Article 25
- Ongoing monitoring of vendor performance and security
- Subcontractor oversight and transparency mandates
- Exit planning and transition readiness
- Joint resilience testing with vendors
- Escalation paths for vendor-related incidents
- Reporting third-party issues to competent authorities
- Common pitfalls in multi-vendor environments
- Role of procurement in pre-contract DORA screening
- Model clauses for DORA-aligned vendor contracts
- Understanding DORA’s five information sharing arrangements
- Eligibility criteria for joining sectoral information-sharing bodies
- Types of information that can be shared under safe harbor
- Internal approval process for submissions
- Handling anonymization requirements
- Response time expectations for shared alerts
- Legal protections under Article 15
- Coordination between internal CSIRT and external bodies
- Documentation of information shared and received
- Case study: responding to a cross-institution phishing alert
- How information feeds into risk and incident frameworks
- Building a culture of proactive sharing
- Compliance vs. CISO vs. business unit responsibilities
- Oversight of framework alignment and update cycles
- Reporting lines to senior management and boards
- Tracking regulatory change across EBA, ECB, and ESMA
- Internal assurance over DORA control effectiveness
- Coordination with external auditors and consultants
- Handling audit findings and remediation timelines
- Maintaining independence in review functions
- Escalation protocols for non-compliance issues
- Training plans for compliance team DORA readiness
- Supervisory expectations for compliance documentation
- How to demonstrate continuous improvement
- Understanding EBA’s timeline for supervisory convergence
- Common inspection focus areas by jurisdiction
- Document requests: what to prepare in advance
- Interview expectations for compliance and IT leads
- Evidence folder structure for efficient review
- Handling follow-up questions from supervisors
- How findings are classified and remediated
- Cross-border coordination between regulators
- Benchmarking against other institution reviews
- Public disclosure requirements post-review
- Internal preparation checklist for audit cycles
- Case example: resolving a major deficiency finding
- Mapping DORA controls to MiFID II Article 38
- GDPR and DORA intersection on incident reporting
- SOX and DORA overlap on internal control documentation
- How ISO 27001 supports DORA evidence generation
- NIST CSF as a foundation for resilience testing
- Integrating BCBS 239 data resilience principles
- Avoiding duplication in audit and reporting
- Creating a unified compliance calendar
- Tooling for cross-framework control tracking
- Reporting efficiency gains from integrated frameworks
- Case study: single source of truth for compliance
- How to structure cross-functional alignment
- Required board-level reporting elements
- Minutes content expectations for DORA compliance
- Documentation of management oversight meetings
- Escalation thresholds for executive awareness
- Role of CEO and CRO in sign-off cycles
- Business continuity integration points
- Strategic risk appetite statements
- Resource allocation decisions for resilience
- Succession planning for key DORA roles
- Training records for senior management
- External reporting to shareholders
- How to structure annual compliance statements
- Defining audit scope in a multi-jurisdictional context
- Sampling strategies for control testing
- Evidence requirements for control effectiveness
- Assessing third-party testing sufficiency
- Reporting findings to management and audit committee
- Linking audit results to risk appetite breaches
- Coordination with external supervisory audits
- Using audit results to update risk frameworks
- Audit follow-up on remediation progress
- Training internal auditors on DORA specifics
- Benchmarking audit maturity across cycles
- Building long-term assurance capacity
- Monitoring regulatory updates from EBA and ESAs
- Updating frameworks to reflect new guidance
- Change management for control adjustments
- Annual review and refresh of testing programs
- Maintaining staff training and awareness
- Tracking key compliance metrics over time
- Benchmarking against industry peers
- Preparing for future EU regulatory waves
- Building institutional memory
- Documenting lessons learned
- Handover protocols for key roles
- Creating a living compliance playbook
How this maps to your situation
- Initial scoping and classification
- Framework design and integration
- Testing and incident readiness
- Ongoing governance and audit
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 90 minutes per module, designed for completion over 6-8 weeks with flexible pacing.
How this compares to the alternatives
Unlike generic compliance overviews, this course delivers actionable, DORA-specific workflows and evidence templates tailored to financial institutions. No other resource provides this level of structural depth for IC practitioners.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.