Skip to content

Home Expertise / Risk & governance

GRC / GRC-05

DORA and ICT risk-management support

Support for digital operational resilience at in-scope financial organisations and for evidence requested from their ICT providers.

WHEN IT HELPS

A focused response
to a defined need.

CISO, risk, compliance or ICT provider; DORA requirements, resilience reviews or financial-sector customer contracts.

AT A GLANCE

Family
Risk & governance

Engagement
Advisory

Reference
GRC-05

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Gap analysis within a validated scope
  • ICT risk management
  • incidents, testing, dependencies and provider governance

Deliverables

  • Evidence matrix
  • resilience plan
  • action register and contract-clause recommendations for legal review

Acceptance evidence

Selected requirements map to relevant services; notification and approval responsibilities are formalised.

DELIVERY

How the work is structured.

Approach

Scope context; engage business owners and decision-makers; assess risks or gaps; decide controls; organise follow-up and evidence.

Prerequisites & responsibilities

Customer: sponsor, available business owners, risk decisions and legal advice where needed. Provider: methodology, facilitation, analysis and decision file.

Scope factors

Entities, processes, stakeholders, regulatory scope, document maturity and workshops. Project, periodic support or fractional CISO depending on need.

Questions to clarify

What is the regulatory status? Which functions are critical? Which providers and services support them?

IMPORTANT BOUNDARIES

Ordinary penetration testing and regulatory threat-led penetration testing have different requirements. Applicability, independence and the relevant rules are established before defining the engagement.

The work supports decisions and evidence for the agreed framework. Legal advice, independent certification and the decisions of regulators or assessors remain separate responsibilities.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A financial firm depends on one hosting provider. Project: assess continuity, contracts and exit arrangements. Target outcome: verifiable requirements, an exit plan and decisions on concentration risk.

Scenario 02

A SaaS provider receives a financial customer’s DORA questionnaire. Project: document controls, subcontractors and incident processes. Target outcome: factual answers; the customer’s obligations are not automatically treated as identical supplier obligations.

Technology and reference context

DORA and applicable related rules; risk and third-party tracking tools.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.