1. Governance and management accountability

Responsibility under DORA cannot be fully delegated to IT or an external provider. Management does not need to run technical tasks, but it must set direction, approve the framework and make informed decisions.

  • Has the management body approved the ICT risk management framework and does it oversee its operation regularly?
  • Are decision, control, incident and supplier-risk owners clearly assigned?
  • Do management-body members receive sufficient training to understand material technology dependencies and risk scenarios?
  • Are security and resilience investments connected to material services, risk and approved tolerance levels?

2. ICT risk management framework

  • Does the framework cover strategy, policies, roles, risk assessment, controls and continual improvement?
  • Is ICT risk integrated into enterprise risk management and regular executive reporting?
  • Are gaps assessed by their impact on material services rather than technical severity alone?
  • Is the framework reviewed following significant incidents, changes, tests and supervisory findings?

3. Assets, services and dependencies

An equipment inventory is not enough. Management needs a service view: what stops, what impact follows and what recovery depends upon.

  • Are critical or important functions and the systems, data, people, locations and suppliers supporting them understood?
  • Do inventories include ownership, classification, lifecycle and interdependencies?
  • Do architecture and change processes prevent new dependencies from falling outside risk assessment?

4. Protection, detection and vulnerability management

  • Are access, privileged accounts, changes, configurations, patches and logs managed according to risk?
  • Does detection cover material systems and enable timely escalation of anomalies?
  • Do vulnerability and penetration-test findings have owners, dates, risk exceptions and evidence of verification?

5. Incident classification and reporting

  • Does one process cover detection, recording, classification, escalation, response and communication?
  • Can the team determine promptly when an event becomes a major ICT-related incident?
  • Are contacts, decision rights and information needed for initial, intermediate and final reporting prepared?
  • Do lessons learned become specific improvements to processes, technology or controls?

6. Continuity, backup and recovery

  • Are continuity and recovery objectives linked to critical or important functions?
  • Are backups segregated, protected, monitored and demonstrably restorable?
  • Do exercises test technology, decisions, people, suppliers, communications and the return to normal operations?
  • Are gaps between business expectations and actual recovery capability visible to management?

7. Digital operational resilience testing

  • Is the testing programme risk-based and does it cover the right systems and scenarios?
  • Are tester independence and competence sufficient for the activity?
  • Are findings prioritised, remediated, retested and included in consolidated progress reporting?
  • Has the organisation determined whether threat-led penetration testing (TLPT) applies?

8. ICT third-party risk

  • Is the register of ICT contractual arrangements aligned to actual services, providers and subcontractors?
  • Before contracting, are criticality, concentration, data, location, substitutability and exit risks assessed?
  • Do contracts contain applicable audit, incident, security, continuity, data-return and termination requirements?
  • Are material providers monitored periodically against agreed indicators and risk signals?

9. Training, communication and crisis decisions

  • Are employee and management training activities tailored to roles and realistic risk scenarios?
  • During a crisis, is it clear who declares it, accepts operational trade-offs and communicates with customers, authorities and partners?
  • Do management and material external providers participate in exercises?

10. Evidence and executive reporting

A good evidence model is not a general document repository. It demonstrates what was decided, what happened, whether the control operated and how deviations were addressed.

  • Does each material control have an owner, frequency, operating criterion and retained evidence?
  • Does executive reporting highlight breached tolerances, overdue material actions, incidents, testing results and supplier risk?
  • Do risk acceptances have rationale, approval, expiry and review dates?
  • Can the decision and action trail be reconstructed quickly for supervisory review?

What management can do now

This checklist is a practical starting point, not a legal opinion or complete compliance assessment. Scope depends on entity type, activities, proportionality and the applicable regulatory technical standards.

  • Select 3–5 material services and validate their technology and supplier dependency view.
  • Request one consolidated list of priority ICT risks, open material gaps and accepted exceptions.
  • Trace the evidence chain for one incident, one recovery test and one material provider from decision to outcome.
  • Agree the indicators and decisions that the management body will review regularly.

Official sources

Turn the next decision into a managed action.