A tailored course, built for your situation
Mastering DORA for Software Engineers in Financial Services
Build compliant, resilient systems that expand your decision scope within Macquarie’s engineering landscape
The situation this course is for
Engineers are caught between fast-moving delivery goals and rigid compliance frameworks that weren’t built for modern architectures. Without clear mapping, compliance becomes rework.
Who this is for
Software Engineers in regulated financial institutions who are expected to deliver compliant systems but lack formal clarity on how engineering decisions map to DORA obligations
Who this is not for
Compliance auditors, risk managers, or non-technical stakeholders looking for high-level overviews
What you walk away with
- Map DORA requirements directly to system architecture decisions
- Own end-to-end design of resilience-critical components without mandatory senior review
- Produce audit-ready artefacts as a byproduct of development, not after-the-fact
- Become the internal reference for compliant cloud-native patterns
- Anticipate regulator questions during design, not during audit
The 12 modules (with all 144 chapters)
- DORA’s definition of critical ICT third parties
- Mapping digital services to resilience tiers
- Incident classification thresholds
- Required testing frequency by service type
- Internal audit expectations
- Documentation standards for system logs
- Cross-border data flow rules
- Mandatory reporting timelines
- ICT risk assessment depth
- Live testing vs simulated testing
- Vendor oversight requirements
- Escalation paths for severe incidents
- Turning uptime requirements into SLA design
- Logging standards for incident tracking
- Failover mechanism validation
- Automated drift detection for compliant configurations
- Version control for system documentation
- Access control for critical systems
- Time-bound access approvals
- Monitoring coverage for resilience tiers
- Alerting thresholds aligned to reporting
- Data retention for audit trails
- Encryption of test data
- Secure handoff protocols
- Resilience tiering in Kubernetes clusters
- Multi-region deployment strategies
- Stateful service recovery design
- Database failover within recovery time objectives
- Traffic rerouting during outages
- Chaos engineering scope under DORA
- Automated testing of recovery procedures
- Canary release compliance checks
- Rollback automation triggers
- Performance under stress thresholds
- Monitoring stack integration
- Alert suppression during planned tests
- Pre-commit hooks for configuration checks
- Automated policy validation in PRs
- DORA rule linter integration
- Gatekeeping production deployment
- Immutable audit trail generation
- Pipeline-level access controls
- Secrets scanning frequency
- Baseline configuration enforcement
- Compliance as code templates
- Versioned control mappings
- Pipeline incident logging
- Peer review requirements
- Vendor contract review checklist
- Right to audit clauses
- Incident reporting obligations
- Subprocessor transparency
- Data sovereignty guarantees
- Penalty triggers for non-compliance
- Exit strategy requirements
- Vendor testing participation
- Dependency tree documentation
- Risk tier assignment methodology
- Ongoing monitoring mechanisms
- Compliance evidence collection
- DORA incident severity matrix
- Automated classification rules
- Internal escalation timelines
- External regulator notification triggers
- Log preservation protocols
- Post-mortem documentation standards
- Recovery verification steps
- Cross-team coordination design
- Simulation exercise integration
- Real-time status dashboards
- Stakeholder comms templates
- Regulator-facing summary format
- Annual test planning under DORA
- Scenario selection criteria
- Tabletop exercise design
- Live failover test scope
- Participant roles and responsibilities
- Test documentation templates
- Gap identification process
- Remediation tracking
- Executive summary creation
- Regulator submission format
- Internal review cycle
- Lessons learned integration
- Audit trail structure design
- Event logging completeness checks
- Timestamp accuracy requirements
- Log retention duration rules
- Automated report generation
- Data format standards
- Access control for audit data
- Encryption in transit and at rest
- Chain of custody documentation
- Cross-platform log aggregation
- Query performance for audits
- Report validation scripts
- Component ownership definitions
- Escalation paths for incidents
- Change approval workflows
- Peer review requirements
- Documentation ownership
- Monitoring responsibility
- Incident response roles
- Test participation mandates
- Vendor management interface
- Compliance audit contact
- Regulator inquiry handling
- Team handover protocols
- Compliance-aware architecture diagrams
- Legend standards for resilience tiers
- Data flow annotations
- Incident response path mapping
- Third-party dependency labeling
- Recovery time objective indicators
- Failover mechanism notation
- Testing status tags
- Audit readiness badges
- Version control of diagrams
- Stakeholder-specific views
- Regulator-facing documentation
- Squad-level compliance checklists
- Embedded compliance champions
- Cross-squad knowledge sharing
- Compliance sprint goals
- Retrospective integration
- Incident simulation participation
- Tooling standardization
- Shared runbook ownership
- Team onboarding content
- Escalation drill frequency
- Feedback loops to architecture
- Metrics for compliance health
- Building internal credibility
- Presenting design choices to risk teams
- Influencing architecture standards
- Mentoring peers on compliance
- Contributing to policy drafting
- Speaking up in design reviews
- Documenting decision rationale
- Creating reusable templates
- Proposing tooling improvements
- Leading test exercises
- Engaging with regulators
- Shaping future resilience strategy
How this maps to your situation
- Onboarding new services under DORA
- Responding to internal audit findings
- Designing a new cloud platform
- Integrating third-party fintech partners
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3 hours per module, with self-paced access allowing completion over 4-6 weeks.
How this compares to the alternatives
Generic DORA overviews explain the regulation but don’t connect it to code. This course bridges policy to practice with concrete engineering patterns used in leading financial institutions.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.