The Digital Operational Resilience Act (DORA) obliges financial organisations in the EU to systematically strengthen their digital resilience. The German Federal Financial Supervisory Authority (BaFin) and the ESAs - i.e. the three European supervisory authorities EBA, EIOPA and ESMA - are scrutinising its implementation with increasing intensity.
The supervisory focus is on:
- ICT risk management and governance
- ICT incident management and resilience testing
- Third party risk management (TPRM)
- Information register and exit strategies
- Technical implementation (e.g. encryption, backup, network segmentation)
Many checks are carried out at short notice, are in-depth and require a high degree of process maturity, documentation and security awareness.
Holistic support in all examination phases
KPMG supports you from the initial assessment to the structured implementation of all audit findings - regulatory sound, practical and individually tailored to your organisation.
Objective: Early identification of weak points and risks
We analyse your DORA readiness, identify weaknesses and develop a roadmap with measures that can be implemented in the short term.
Scope of services
- GAP analysis based on DORA and other relevant regulations such as Minimum Requirements for Risk Management (MaRisk) and EU AI ACT
- Heat map for prioritising fields of action
- 100-point checklist for organisational and technical preparation for an audit
- Development of a roadmap with quick wins
- Comparison with other market participants
Your advantage: Minimisation of regulatory risks and targeted preparation for the audit
Objective: to build up audit compliance and internal security
We train your employees, simulate supervisory meetings and prepare all documents in a structured and audit-proof manner.
Scope of services:
- Awareness training and rules of conduct for exams
- Simulation of supervisory discussions with individual feedback
- Preparation of kick-off presentations for each examination area
- Document review and argumentation guidelines
- Setting up the audit office with clear governance structures
Your advantage: Structured processes and secure communication during the audit
Objective: Efficient and controlled execution of the audit
We operate a centralised audit office, coordinate all enquiries and provide you with technical support throughout the audit.
Scope of services:
- Operation of a central audit office
- Coordination of enquiries, interviews and documents
- Logging and anticipation of critical queries
- Technical support and argumentation strategies
- Daily briefings and structured status reports
Your advantage: Relief of internal resources and professional external impact
Objective: Efficiently analyse audit findings and implement them in a regulatory compliant manner
We analyse the findings, define ambition levels and create a prioritised action plan for implementation.
Scope of services:
- Analysis of the factual report
- Definition of ambition levels and target images
- Creation of a prioritised action plan
- Support in communicating with the supervisory authority
- Introduction of best practices
Your advantage: Sustainable compliance and strengthened governance structures
Objective: Comprehensible and complete closure of the findings
We accompany the implementation of the measures, ensure their quality and provide support in communicating with the supervisory authority.
Scope of services:
- Project management and progress monitoring
- Implementation of the measures for shooting the findings
- Quality assurance of the measures and proof of implementation
- Support with quarterly reporting
- Follow-up audits and structured documentation
- Employee training on new processes
Your advantage: Reduction of reputational risks, reliable evidence and a long-term strengthening of your organisation.
Have DORA readiness checked now
A well-founded assessment of the current situation is the first step towards successful preparation for DORA regulatory audits. A structured analysis allows regulatory risks to be identified at an early stage, fields of action to be prioritised and audit compliance to be increased in a targeted manner.
Our expertise at a glance:
- Over 100 GAP analyses in the DORA and xAIT context
- Accompaniment of more than 35 IT supervisory audits
- Scalable team of experts with in-depth expertise in governance, IT and compliance
- Close cooperation with supervisory authorities, audit networks and industry associations
Contact us for a non-binding initial consultation.
Further interesting content for you
Your Contacts
Peter Hertlein
Partner, Financial Services, IT Compliance & Cyber Resilience
KPMG AG Wirtschaftsprüfungsgesellschaft
Vaike Metzger
Partner, Financial Services, Head of IT Compliance Solution, DORA EMA Lead
KPMG AG Wirtschaftsprüfungsgesellschaft
Nadine Schmitz
Partner, Financial Services
KPMG AG Wirtschaftsprüfungsgesellschaft
Florian Göltl
Partner, Financial Services
KPMG AG Wirtschaftsprüfungsgesellschaft