IGX Solutions

DORA

DORA requires financial entities to maintain a register of ICT third-party arrangements and to demonstrate that ICT risk is managed end to end, not just documented. Most firms can produce the register. Far fewer can show, process by process, how an ICT incident at a named third party actually propagates through the operations that depend on it. IGX360 Insights connects the register to the operating model it is supposed to describe.

9 problems for DORA

We think we are compliant but cannot prove it

  • Continuous compliance
  • Control assurance
  • Audit readiness

Compliance gaps remain invisible until assurance activity begins. The underlying weakness is the absence of traceability from obligation through process, owner, system, control, execution and retained evidence.

We do not know where operational failure will spread

  • Operational resilience
  • Critical service mapping
  • Dependency analysis

Single points of failure remain embedded in the operating model. The underlying weakness is the absence of an end-to-end view of critical outcomes, dependencies, concentration, substitution, controls and recovery assumptions.

Risks, controls, processes and obligations are disconnected

  • Risk-control traceability
  • Obligation mapping
  • Connected assurance

The organisation cannot see which processes create each risk, which controls operate within them or where coverage is absent. The underlying weakness is the absence of traceability from obligation through process, owner, system, control, execution and retained evidence.

DORA evidence is fragmented across ICT, risk and operations

  • DORA
  • Operational resilience evidence
  • ICT third-party traceability

Critical functions, ICT assets, third parties, risks, controls, incidents and testing evidence are not represented end to end. The underlying weakness is the absence of traceability from obligation through process, owner, system, control, execution and retained evidence.