NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
DORA Audit: What to Expect
Learn

DORA Audit: What to Expect

·Alexander Sverdlov

A DORA audit is two different things, and most of the pages ranking for this query describe only one of them. The first is supervisory: Regulation (EU) 2022/2554 gives your existing competent authority the powers in Article 50(2) to access any document or data you hold, take a copy of it, carry out on-site inspections, summon your representatives for explanations and require corrective measures. The second is internal: Article 6(6) requires financial entities other than microenterprises to subject their ICT risk management framework to internal audit on a regular basis, by auditors with sufficient ICT knowledge and appropriate independence. The supervisor is entitled to see the results of the second when it runs the first.

Two facts frame everything else. DORA has applied since 17 January 2025, so there is no preparation window left. And DORA does not create a new regulator or a DORA certificate. Article 46 assigns supervision to the authority that already oversees your type of entity under sectoral law, and for credit institutions classified as significant, to the ECB. The review, when it comes, arrives from a supervisor you already know.

FactDetail
Governing lawRegulation (EU) 2022/2554, applicable since 17 January 2025 (Article 64). A regulation, so no national transposition of the substance.
Who audits youYour existing competent authority under Article 46. The ECB for significant credit institutions. Not the European Commission.
Supervisory powersArticle 50(2): access to and copies of any document or data, on-site inspections and investigations, summoning representatives, interviews with consent, corrective and remedial measures.
What gets testedThe Chapter II framework (Articles 5 to 16), incident management and reporting (Articles 17 to 23), resilience testing (Articles 24 to 27) and ICT third-party risk (Articles 28 to 30).
The audit you run yourselfArticle 6(6) internal audit of the framework, with a formal follow-up process for critical findings under Article 6(7).
Fixed cyclesFramework reviewed at least yearly (Article 6(5)), asset classification reviewed at least yearly (Article 8(1)), critical or important function systems tested at least yearly (Article 24(6)), TLPT at least every three years where designated (Article 26(1)).
If it goes badlyArticle 50(4) measures, applied with the Article 51(2) factors, and published under Article 54 once no appeal remains.
The six things Article 50(2) of DORA allows a competent authority to do: access any document, copy any data, inspect on site, summon representatives, interview with consent and require remediation

What actually happens in a DORA audit?

DORA fixes the powers, not the procedure. Article 50(1) requires competent authorities to have all supervisory, investigatory and sanctioning powers necessary for their duties, and Article 50(2) lists the minimum. How those powers are exercised, with what notice and on what timetable, is a matter for the authority and for the national framework it operates under, which Article 51(1) says may be directly, in collaboration with other authorities, by delegation, or by application to a court.

In practice a review follows a recognisable sequence: a scope letter with an initial document request, a desk review of what you send, an on-site or remote inspection to see processes working rather than described, interviews that reach the management body as well as the technical functions, and a findings letter with remedial expectations. Our guide to DORA supervisory assessments walks that sequence phase by phase. This article concentrates on what the text lets a supervisor demand at each step, and on what the text makes you produce before anyone asks.

How a DORA supervisory review runs: scope letter and document request, desk review of the framework and register, on-site or remote inspection, interviews with the board and control functions, findings and remedial measures

Who audits you, and when?

Article 46 answers who. For each category of financial entity it names the authority designated under the relevant sectoral act, so a credit institution is reviewed by its prudential supervisor, an investment firm by its markets authority, an insurer by its insurance supervisor, and so on. Critical ICT third-party providers are a separate case: they sit under the Oversight Framework in Chapter V, Section II, with one of the ESAs as Lead Overseer. That oversight runs above yours and does not replace your own obligations towards the provider.

When is not fixed by DORA. There is no review cycle, no notice period and no agenda in the Regulation. What the text does fix is a set of dates on which you owe something, and each one is a natural moment for a supervisor to look:

ObligationCycleArticle
Review of the ICT risk management framework, with a report submitted to the authority on requestAt least once a year, and after major incidents or supervisory instructions6(5)
Review of the classification of ICT-supported functions, assets and dependenciesAt least yearly8(1)
Tests on all ICT systems and applications supporting critical or important functionsAt least yearly24(6)
Threat-led penetration testing, for entities identified for itAt least every three years, adjustable by the authority26(1)
Report on new ICT contractual arrangements, provider categories and servicesAt least yearly28(3)
The full Register of Information, or specified sections of itOn request28(3)
Complete and updated information on ICT risk and on the frameworkOn request6(3)

Read as a calendar, that table says something useful: a supervisor does not need to open a formal review to test you. The yearly report on new contracts and the on-request register under Article 28(3) are routine supervision, and the register is the one artefact that can be checked mechanically. If you want a single predictor of how a review will go, it is whether that register validates, which is why why your Register of Information keeps getting rejected is worth reading before any letter arrives.

DORA workspace showing the Register of Information, gap assessment and resilience testing status in one view
The register is the first thing most supervisors can check without asking you anything, so its validation status is the readiness number that matters.

What evidence will a supervisor ask for?

Article 50(2)(a) covers any document or data the authority considers relevant. The practical index is the set of things DORA itself says must exist, because those are the items an authority can request by article number without having to justify the request further.

AreaWhat DORA requires to existWhat proves it
Governance, Art. 5Management body defines, approves and oversees the framework, approves the digital operational resilience strategy, and approves and periodically reviews ICT internal audit plans (Art. 5(2)(f))Board minutes with the approval decisions, and the audit plan the board signed off
Framework, Art. 6A documented framework reviewed at least yearly (6(5)), internal audit on a regular basis (6(6)), a formal follow-up process for critical findings (6(7))The review report, the audit reports, and a findings register with dates and closure evidence
Identification, Art. 8All ICT-supported business functions, information assets and ICT assets identified, classified and documented, reviewed at least yearlyA dated inventory and classification that reconcile to the register
Incidents, Arts. 17 to 19All ICT-related incidents and significant cyber threats recorded (17(2)); major incidents classified under Delegated Regulation (EU) 2024/1772 and reported to the authorityThe incident log, the classification decisions, and the notifications with timestamps
Testing, Art. 24Tests by independent parties (24(4)), procedures to prioritise, classify and remedy findings (24(5)), yearly tests on critical or important function systems (24(6))Test reports, the remediation tracker, and the internal validation that findings were closed
TLPT, Art. 26Where identified, TLPT at least every three years on live production systems, with the scope validated by the authorityThe scoping document the authority validated, and the test summary
Third parties, Arts. 28 to 30A register of information at entity, sub-consolidated and consolidated levels (28(3)); pre-contract assessments (28(4)); contracts with the Art. 30 provisions in one written documentThe register export, due diligence files, and contracts with the required clauses located

Two things about this list are easy to miss. First, several rows are not policies but records of things happening: the incident log, the test results, the follow-up on audit findings. A policy with no records behind it is exactly what an on-site inspection exists to find. Second, the Article 19 reporting clocks are fixed in Delegated Regulation (EU) 2025/301, Article 5: an initial notification within four hours of classifying an incident as major and no later than 24 hours from becoming aware of it, an intermediate report within 72 hours of the initial notification, and a final report no later than one month after the intermediate report or its latest update. A supervisor can put your timestamps next to those numbers, and our guide to DORA major incident classification sets out the criteria that start the clock.

The fixed cycles in DORA a supervisor can check: yearly framework review, asset classification and testing, TLPT every three years, four hours for the initial major incident notification, and yearly reporting on new ICT contracts

The audit DORA makes you run on yourself

This is the part the search results skip. Article 6(6) is not a suggestion to have an audit function. It requires that the ICT risk management framework of every financial entity other than a microenterprise is subject to internal audit by auditors on a regular basis, in line with the entity's audit plan, and that those auditors possess sufficient knowledge, skills and expertise in ICT risk as well as appropriate independence. The frequency and focus of ICT audits must be commensurate to the entity's ICT risk.

Three further provisions turn that into a chain of evidence. Article 6(4) requires segregation and independence between ICT risk management, control functions and internal audit, according to the three lines of defence model or an equivalent. Article 5(2)(f) makes the management body approve and periodically review the ICT internal audit plans, the ICT audits and material modifications to them. And Article 6(7) requires a formal follow-up process, including rules for the timely verification and remediation of critical ICT audit findings.

The consequence for a supervisory review is direct. A supervisor who asks for your last three internal ICT audit reports, the board's approval of the audit plan and the status of every critical finding is not fishing. Each of those documents is required to exist, and a gap in any of them is a finding in its own right before the supervisor has looked at a single control. Article 6(5) closes the loop: the framework must be reviewed following conclusions derived from audit processes, so your own audit findings are supposed to change the framework, and a supervisor can reasonably ask to see where they did.

Evidence vault listing controls with attached evidence, owners and refresh dates
Internal audit findings, board approvals and test results belong in one place with dates, because Article 6(7) is about closure, not discovery.

Who pays for a DORA audit?

The Article 6(6) internal audit is yours to resource, and the tests in Article 24 must be undertaken by independent parties, whether internal or external, with sufficient resources dedicated where the tester is internal. Unlike NIS2, DORA contains no provision requiring the entity to pay for a targeted audit ordered by the authority; the supervisory powers in Article 50 are exercised by the authority itself. The cost DORA does place on you is the recurring one: the audit plan, the yearly testing, and where you are designated, a threat-led penetration test every three years, which our guide to DORA TLPT describes as a multi-month engagement by design.

What happens if the audit finds gaps?

Article 50(4) lists the minimum measures Member States must give their authorities: an order to cease the conduct and not repeat it, temporary or permanent cessation of a practice the authority considers contrary to the Regulation, any measure including of a pecuniary nature to ensure continued compliance, access to telecommunications data traffic records where national law permits and there is reasonable suspicion of a breach, and public notices identifying the person and the nature of the breach. Article 50(5) allows those measures to be applied, subject to national law, to members of the management body and to other individuals responsible for the breach.

There is no EU-wide fine ceiling for financial entities in DORA. Article 50(3) requires Member States to lay down administrative penalties and remedial measures that are effective, proportionate and dissuasive, and leaves the amounts to national law. Article 51(2) fixes what the authority must weigh: whether the breach was intentional or negligent, its materiality, gravity and duration, the degree of responsibility, the financial strength of the person, profits gained or losses avoided, losses caused to third parties, the level of cooperation with the authority, and previous breaches. Two protections apply. Article 50(6) requires any decision imposing penalties or remedial measures to be properly reasoned and subject to a right of appeal. Article 54 then requires publication on the authority's website once no appeal remains, with deferral or anonymisation available where publication would be disproportionate or would jeopardise financial stability or a criminal investigation.

What the other results get wrong

Three errors recur across the pages ranking for this query.

The first is stating that major incidents must be notified within 24 hours. The initial notification clock under Delegated Regulation (EU) 2025/301 runs from classification, and it is four hours. The 24 hours is a backstop measured from awareness, not the deadline. An entity that designs its process around 24 hours will be late whenever classification happens quickly, which is precisely when the supervisor is most likely to look.

The second is quoting a DORA fine as a percentage of turnover. The only turnover-based figure in DORA's enforcement provisions is the periodic penalty payment the Lead Overseer can impose on a critical ICT third-party provider under Article 35, at up to 1 percent of average daily worldwide turnover per day for up to six months. It does not apply to financial entities. Your exposure is set by your Member State's rules under Article 50(3), and by the supervisory measures in Article 50(4), which for a regulated firm bite long before any fine.

The third is describing a DORA audit as a certification or a one-off event. There is no DORA certificate and no DORA auditor accreditation in the Regulation. Supervision is continuous and folds into the relationship you already have with your authority, and the yearly obligations in the table above mean the evidence has to be current all the time rather than assembled for a date. That is the same conclusion we reached about NIS2 audits, with the difference that DORA is a regulation and the substance does not vary by country.

A DORA audit readiness view tracking Register of Information validation errors, critical or important functions tested this year, overdue internal audit findings and board ICT risk items minuted

Could you pass one next month?

Fill this in for your own entity. Any row you cannot complete is the row a supervisor will find first.

QuestionYour answerWhy it matters
Which authority supervises you under Article 46, and do they have a DORA contact on file?The review comes from an existing relationship, not a new regulator.
When was the framework last reviewed, and could you send the Article 6(5) report today?At least yearly, and on request.
When was the last internal ICT audit, and how many critical findings are open past their date?Articles 6(6) and 6(7). Missing either is a finding before any control is tested.
Does the Register of Information validate, and does it reconcile to your asset inventory?Article 28(3) on request, and Article 8(1) yearly. The mechanical check.
Could you file a four hour initial notification tonight, with a named filer and a fallback?Delegated Regulation 2025/301, Article 5(1)(a).
Have all systems supporting critical or important functions been tested in the last twelve months?Article 24(6), by independent parties under 24(4).

If most rows are blank, the useful next step is a baseline rather than a project plan. Our guide to scoring your DORA readiness sets out the domains and the weighting, and our guide to how to collect audit evidence covers how to keep the records in the table above current instead of rebuilding them for each request. A free compliance check will tell you which rows you can actually evidence, and our DORA compliance software keeps the register, the test results and the audit findings in one place between supervisory contacts.

The bottom line on DORA audits: the first DORA auditor is the one you appoint under Article 6(6), and the supervisor reads that auditor's findings

Frequently asked questions

Is there a DORA certification?

No. DORA contains no certificate for financial entities and no accreditation for DORA auditors. Compliance is supervised by the authority designated under Article 46, using the powers in Article 50.

How often will we be audited under DORA?

The Regulation sets no supervisory cycle. It does fix your own cycles: the framework review at least yearly under Article 6(5), internal audit on a regular basis under Article 6(6), yearly testing of critical or important function systems under Article 24(6), and TLPT at least every three years under Article 26(1) where you are identified for it.

Does the simplified framework exempt us from audit?

Entities listed in Article 16(1), such as small and non-interconnected investment firms and exempted payment and electronic money institutions, are outside Articles 5 to 15, so the Article 6(6) internal audit duty does not apply to them as written. They remain subject to the simplified framework in Article 16 and to supervision under Article 50.

Can our directors be held personally responsible?

Article 50(5) allows administrative penalties and remedial measures to be applied, subject to national law, to members of the management body and to other individuals responsible for a breach. Article 5(2) places ultimate responsibility for managing ICT risk on the management body.

Does ISO 27001 or a SOC 2 report mean we pass?

It helps and it does not settle it. A working management system produces much of the Chapter II evidence, but the register under Article 28(3), the reporting clocks under Article 19 and the board duties under Article 5 are DORA specific and are assessed on their own terms.

Primary sources

Every article reference above is taken from the text of Regulation (EU) 2022/2554 on EUR-Lex, specifically Articles 5, 6, 8, 16, 17, 19, 24, 26, 28, 30, 35, 46, 50, 51, 54 and 64. Reporting time limits are from Article 5 of Commission Delegated Regulation (EU) 2025/301, and the classification criteria it refers to are in Delegated Regulation (EU) 2024/1772. Because penalties are set nationally under Article 50(3), confirm the rules of your own Member State before relying on any figure.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING