Control frameworkCompliance & Audit

DORA policy template

Review this template's scope and control areas. Then, open it in the Verdictan console to adapt and test the configuration for your environment.

Map selected Digital Operational Resilience Act duties for European Union financial entities. The template covers information and communications technology risk, incidents, continuity, resilience testing and third-party oversight. Use its gateway controls and evidence fields only where they apply.

Use this template as a starting configuration and control map. It does not provide certification, legal advice or a compliance guarantee. Confirm your obligations, adapt the configuration and test every outcome before deployment.

Regions

EU

Source references

3 source references

Control areas

6 mapped control areas

Deployment options

Regulated SaaS, Financial (cache disabled), Sovereign region

Source frameworks, standards and obligations

EU Regulation 2022/2554 (DORA — Digital Operational Resilience Act)Commission Delegated Regulation (EU) 2024/1774 (DORA ICT risk management RTS)DORA delegated and implementing acts (Joint ESA RTS/ITS)

Control areas mapped by this template

ICT risk management
Incident response
Resilience testing
Third-party oversight
Business continuity
Digital testing

Deployment options

Regulated SaaS
Financial (cache disabled)
Sovereign region

Adapt the template in three steps

1

Review the scope

Confirm that the regions, source references, control areas and deployment options fit your use case.

2

Adapt the configuration

Open the template in the Verdictan console. Set its policies, thresholds, routing and review requirements for your environment.

3

Test before deployment

Test each policy outcome. Confirm that allowed, redacted, blocked and reviewed requests behave as expected.