AIXYRA
All Frameworks
Financial servicesApplies since January 17, 2025 to EU financial entities and critical ICT providers.

DORA

EU Digital Operational Resilience Act (Regulation (EU) 2022/2554)

The EU's operational resilience regime for finance: ICT risk management, incident reporting, resilience testing, and third-party risk — AI dependencies included.

32 individual requirements seeded and assessable in AIXYRA.

DORA requires EU financial entities — banks, insurers, investment firms, payment institutions, and more — to manage ICT risk end to end: governance and risk frameworks, incident classification and reporting, digital resilience testing, and rigorous management of ICT third-party providers, including a register of contractual arrangements. Critical ICT providers come under direct EU oversight.

AI systems are ICT assets under DORA, and AI providers are ICT third parties. Every model API, AI platform, and agent tool an institution depends on belongs in its risk framework and third-party register — with concentration risk, exit strategies, and impact analysis assessed. That demands dependency-level visibility most inventories don't have.

Who it applies to

EU financial entities across the sector — and the ICT providers, including AI providers, that serve them.

Key requirement themes

ICT risk management framework

Board-owned governance of ICT risk, covering identification, protection, detection, and recovery — AI assets in scope.

Third-party risk & register

A maintained register of ICT third-party arrangements, with concentration analysis — model providers and AI APIs included.

Incident management & reporting

Classify and report major ICT incidents on fixed timelines — requiring impact visibility across dependencies.

Resilience testing

Programmatic testing of critical systems, informed by which dependencies would propagate failure.

Orientation for evaluators — not legal advice. Consult counsel for obligations specific to your organization.

How AIXYRA helps

  • The registry with dependency graphs maps AI systems to the platforms, tools, and external services behind them — the factual basis for the third-party register
  • Entity concentration is a scored risk dimension, surfacing dependence on single providers
  • Impact analysis over the dependency chain supports incident classification and resilience-test scoping
  • Assessments against seeded DORA articles track coverage with evidence and audit-ready reporting

DORA FAQ

Does DORA apply to AI systems?

Yes — AI systems are ICT assets and AI providers are ICT third-party providers under DORA. They belong in the ICT risk framework, the third-party register, concentration analysis, and incident and resilience processes like any other critical ICT dependency.

How does AIXYRA support DORA's third-party requirements?

The registry records every AI provider, platform, and external tool as a governed entity; dependency graphs and concentration scoring show where reliance clusters; and assessments against seeded DORA articles attach the evidence supervisors expect.

Assess your AI systems against DORA

DORA ships built into AIXYRA — and the same assessment maps to every other enabled framework at once.