Compliance
DORA
ICT risk and incident reporting for EU financial entities, with AI systems part of the operational record.
At a glance
Who this covers, and who enforces it
EU financial entities and their critical ICT third-party providers, including AI systems that form part of ICT risk management.
- Instrument
- Regulation (EU) 2022/2554 — binding law
- Enforced by
- EBA, ESMA, EIOPA + national supervisors
- Applies since
- 17 Jan 2025
- Scope
- Banks, insurers, funds, and other EU financial entities
- Focus
- ICT risk, incident reporting, resilience testing
Requirements
What it asks for
- 1ICT risk management framework covering AI
- 2Incident classification and reporting
- 3Digital operational resilience testing
- 4Third-party ICT risk oversight
Evidence mapping
What PRISM records against each requirement
Every plan records this evidence as your AI runs. Compliance Reports, which turn it into a reviewed, framework-mapped report, are delivered as a service, on request.
- ICT risk framework
- Model Inventory treats each AI system as a registered ICT asset with an owner.
- Incident reporting
- Scores & Alerts timestamp and classify incidents as they happen.
- Resilience testing
- Synthetic Scenarios exercise systems against realistic failure conditions.
- Third-party oversight
- Connectors log every external AI dependency feeding the environment.
Primary source
Read the actual text
Everything on this page is drawn from EIOPA — Digital Operational Resilience Act (DORA). The capture is live, not a paraphrase — go straight to the source and check us.

Evidence, not certification
This page describes DORA’s publicly available requirements and how PRISM’s evidence layer supports them. It is not legal advice, and it does not constitute certification, regulatory approval, or a guarantee of compliance. DORA compliance remains your organization’s responsibility, in consultation with qualified counsel.
Keep reading
Ask us about your framework
Tell us how DORA applies to your systems and we'll show you the evidence path.