GRC / GRC-05
DORA and ICT risk-management support
Support for digital operational resilience at in-scope financial organisations and for evidence requested from their ICT providers.

WHEN IT HELPS
A focused response
to a defined need.
CISO, risk, compliance or ICT provider; DORA requirements, resilience reviews or financial-sector customer contracts.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Gap analysis within a validated scope
- ICT risk management
- incidents, testing, dependencies and provider governance
Deliverables
- Evidence matrix
- resilience plan
- action register and contract-clause recommendations for legal review
Acceptance evidence
Selected requirements map to relevant services; notification and approval responsibilities are formalised.
DELIVERY
How the work is structured.
Approach
Scope context; engage business owners and decision-makers; assess risks or gaps; decide controls; organise follow-up and evidence.
Prerequisites & responsibilities
Customer: sponsor, available business owners, risk decisions and legal advice where needed. Provider: methodology, facilitation, analysis and decision file.
Scope factors
Entities, processes, stakeholders, regulatory scope, document maturity and workshops. Project, periodic support or fractional CISO depending on need.
Questions to clarify
What is the regulatory status? Which functions are critical? Which providers and services support them?
IMPORTANT BOUNDARIES
Ordinary penetration testing and regulatory threat-led penetration testing have different requirements. Applicability, independence and the relevant rules are established before defining the engagement.
The work supports decisions and evidence for the agreed framework. Legal advice, independent certification and the decisions of regulators or assessors remain separate responsibilities.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A financial firm depends on one hosting provider. Project: assess continuity, contracts and exit arrangements. Target outcome: verifiable requirements, an exit plan and decisions on concentration risk.
Scenario 02
A SaaS provider receives a financial customer’s DORA questionnaire. Project: document controls, subcontractors and incident processes. Target outcome: factual answers; the customer’s obligations are not automatically treated as identical supplier obligations.
Technology and reference context
DORA and applicable related rules; risk and third-party tracking tools.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
