Regulatory Mapping · DORA Regulation

DORA Compliance Mapping

Regulation (EU) 2022/2554 — Digital Operational Resilience Act. How AI systems in financial entities produce the operational evidence DORA requires.

What is DORA?

DORA (Regulation (EU) 2022/2554) is an EU law in force since 17 January 2025. It requires financial entities to prove they can withstand, respond to and recover from ICT disruptions — cyberattacks, system failures, operational incidents — without collapsing.

It applies to around 20 types of financial entity — banks, insurers, investment firms, payment and crypto-asset providers — and, critically, to the ICT third parties they depend on, including cloud, software and AI vendors.

What DORA actually requires

ICT risk management
Identify every ICT-supported function, map its dependencies, and keep it under continuous control (Art. 6).
Incident logging & classification
Identify, log, categorise and classify every ICT incident, and report major ones to the regulator within hours (Art. 17).
Resilience testing
Test critical systems at least annually, including threat-led penetration testing.
Third-party risk
Manage ICT third-party risk — including AI providers — as part of your own risk framework (Art. 28).

Why this affects you if you run AI agents

If you operate AI agents inside an EU financial entity, every automated decision an agent makes is an ICT operation. DORA expects that operation to be logged, classified, and demonstrable to a regulator who was not in the room when it happened.

The hard part is not writing the log. It is proving the log is true. A record the acting system produced about itself is a claim, not evidence. Under DORA, what an auditor needs is a record whose custody sits outside the system that acted — one that cannot be quietly edited after the fact.

How TrustLayers produces DORA evidence

TrustLayers captures each agent decision at the moment of execution, seals it in a tamper-evident chain, and holds custody independently of the system that acted. That is the difference between paperwork describing intent and evidence of what occurred.

DORA article → evidence produced
Art. 6 — ICT risk management
Continuous, per-agent record of every decision and its risk state.
Art. 9 — Protection & prevention
Policy checks captured at execution; blocked actions recorded as blocked.
Art. 10 — Detection
Anomaly and drift flags stored on the decision record itself.
Art. 11 — Response & recovery
Human overrides and interventions logged with timestamp and actor.
Art. 12 — Backup & restore
Append-only, hash-chained custody with defined retention.
Art. 17 — Incident classification
Each event categorised and classifiable for regulator reporting.
Art. 28 — Third-party risk
Independent custody: evidence not self-certified by the acting vendor.
Art. 30 — Contractual provisions
Exportable, verifiable records suitable for contractual audit rights.
DORA for AI systems — compliance checklist
A one-page checklist mapping each relevant DORA article to the runtime evidence an AI system must be able to produce. Print or save it.

Live evidence

The table below is not an illustration. It is generated from real decision records, evaluated against DORA criteria, agent by agent.

Agent Category Events Error rate Violations Drift Sensitive Encrypted Overrides DORA Criteria Resilience
TransparencyAgent
-ransparency-gent-297b…
Governance 1,156 0% 0 0 0 20% 0
7/8
RESILIENT
ClaraAI-Assistant
-lara-ssistant-a8ad…
Support 200 0% 0 0 0 3% 0
6/8
PARTIAL
HumanOversightAgent
-uman-versight-gent-01…
Governance 58 0% 0 0 0 0% 0
7/8
RESILIENT
ComplianceAlignment
-ompliance-lignment-08…
Governance 30 0% 0 0 0 0% 0
7/8
RESILIENT
AuditabilityAgent
-uditability-gent-aa78…
Governance 7 0% 0 0 0 0% 0
7/8
RESILIENT
ClaraAI-Voice
-lara-oice-7b52…
Support 6 0% 0 0 0 0% 0
6/8
PARTIAL
ClaraAI-Emergency
-lara-mergency-326e…
Support 4 0% 0 0 4 0% 0
6/8
PARTIAL
ClaraAI-Tracking
-lara-racking-c8c2…
Support 1 0% 0 0 0 0% 0
6/8
PARTIAL
DataGovernanceAgent
gov-datagovernance-005…
Governance 1 0% 0 0 0 0% 0
7/8
RESILIENT
SecurityAgent
gov-security-008…
Governance 1 0% 0 0 0 0% 0
7/8
RESILIENT
DocumentationAgent
gov-documentation-011…
Governance 1 0% 0 0 0 0% 0
7/8
RESILIENT
Generated 09/09/2026 11:23 · TrustLayers.eu · DORA Regulation (EU) 2022/2554 · trustlayer@danidanwin.eu