• 1000

The Digital Operational Resilience Act (DORA) obliges financial organisations in the EU to systematically strengthen their digital resilience. The German Federal Financial Supervisory Authority (BaFin) and the ESAs - i.e. the three European supervisory authorities EBA, EIOPA and ESMA - are scrutinising its implementation with increasing intensity.

The supervisory focus is on:

  • ICT risk management and governance
  • ICT incident management and resilience testing
  • Third party risk management (TPRM)
  • Information register and exit strategies
  • Technical implementation (e.g. encryption, backup, network segmentation)

Many checks are carried out at short notice, are in-depth and require a high degree of process maturity, documentation and security awareness.

Holistic support in all examination phases

KPMG supports you from the initial assessment to the structured implementation of all audit findings - regulatory sound, practical and individually tailored to your organisation.

Dora Phasen

Objective: Early identification of weak points and risks

We analyse your DORA readiness, identify weaknesses and develop a roadmap with measures that can be implemented in the short term.

Scope of services

  • GAP analysis based on DORA and other relevant regulations such as Minimum Requirements for Risk Management (MaRisk) and EU AI ACT
  • Heat map for prioritising fields of action
  • 100-point checklist for organisational and technical preparation for an audit
  • Development of a roadmap with quick wins
  • Comparison with other market participants

Your advantage: Minimisation of regulatory risks and targeted preparation for the audit

Objective: to build up audit compliance and internal security

We train your employees, simulate supervisory meetings and prepare all documents in a structured and audit-proof manner.

Scope of services:

  • Awareness training and rules of conduct for exams
  • Simulation of supervisory discussions with individual feedback
  • Preparation of kick-off presentations for each examination area
  • Document review and argumentation guidelines
  • Setting up the audit office with clear governance structures

Your advantage: Structured processes and secure communication during the audit

Objective: Efficient and controlled execution of the audit

We operate a centralised audit office, coordinate all enquiries and provide you with technical support throughout the audit.

Scope of services:

  • Operation of a central audit office
  • Coordination of enquiries, interviews and documents
  • Logging and anticipation of critical queries
  • Technical support and argumentation strategies
  • Daily briefings and structured status reports

Your advantage: Relief of internal resources and professional external impact

Objective: Efficiently analyse audit findings and implement them in a regulatory compliant manner

We analyse the findings, define ambition levels and create a prioritised action plan for implementation.

Scope of services:

  • Analysis of the factual report
  • Definition of ambition levels and target images
  • Creation of a prioritised action plan
  • Support in communicating with the supervisory authority
  • Introduction of best practices

Your advantage: Sustainable compliance and strengthened governance structures

Objective: Comprehensible and complete closure of the findings

We accompany the implementation of the measures, ensure their quality and provide support in communicating with the supervisory authority.

Scope of services:

  • Project management and progress monitoring
  • Implementation of the measures for shooting the findings
  • Quality assurance of the measures and proof of implementation
  • Support with quarterly reporting
  • Follow-up audits and structured documentation
  • Employee training on new processes

Your advantage: Reduction of reputational risks, reliable evidence and a long-term strengthening of your organisation.

Have DORA readiness checked now

A well-founded assessment of the current situation is the first step towards successful preparation for DORA regulatory audits. A structured analysis allows regulatory risks to be identified at an early stage, fields of action to be prioritised and audit compliance to be increased in a targeted manner.

Our expertise at a glance:

  • Over 100 GAP analyses in the DORA and xAIT context
  • Accompaniment of more than 35 IT supervisory audits
  • Scalable team of experts with in-depth expertise in governance, IT and compliance
  • Close cooperation with supervisory authorities, audit networks and industry associations

 

Contact us for a non-binding initial consultation.