Offer · Information Security & Governance

Annual DORA review and maintenance

DORA is not an implementation project that gets finished. The framework has to be followed up, tested, updated and improved over time.

DORAICT risk frameworkAnnual reviewThird-party riskManagement report

Who it is for and when

Many financial firms put substantial resources into being ready for DORA. Now the next phase begins. Processes are used. Incidents happen. Suppliers change. Tests are carried out. Risks are updated. Contracts are added. Controls reveal strengths and weaknesses.

DORA requires the ICT risk management framework to be kept current and improved. For financial entities other than microenterprises the framework must be documented and reviewed at least annually. A review must also follow major ICT-related incidents, and can be triggered by supervisory instructions or by conclusions from tests and audits. The report on the review must be available to the competent authority on request.

Kristensson i Skåne AB helps you carry out the annual review as one coherent and usable piece of maintenance work, rather than as a fresh full-scale DORA implementation every year.

The offer suits financial firms that:

  • have already implemented the bulk of DORA,
  • need to carry out the recurring review of the ICT risk management framework,
  • want to bring together the year’s incidents, tests, risks and improvements,
  • need to get the evidence and documentation in order,
  • want a clear basis for management decisions,
  • have several DORA workstreams that are followed up separately today,
  • need senior external reinforcement but want to own the framework themselves.

For microenterprises and entities covered by the simplified ICT risk management framework the approach needs adapting, because DORA sets separate rules for them.

What we do

  1. Planning. The scope, the period and the available source material are established.
  2. Collection and workshops. Relevant functions such as IT, information security, risk, compliance, procurement and continuity are involved.
  3. Analysis and report. We compile the results and identify gaps and improvements.
  4. Management walkthrough. The risk picture and the priorities are presented to the relevant management forum.
  5. Maintenance plan. Activities for the next period are structured and can then be followed up continuously.

What is included

Changes since the previous review

We start by identifying what has actually changed. For example:

  • the organisation,
  • critical or important functions,
  • systems,
  • suppliers,
  • the threat picture,
  • major projects,
  • governing documents,
  • risks,
  • regulatory requirements.

Delegated Regulation 2024/1774 requires the report on the review to describe, among other things, major changes to the ICT risk management framework since the previous review.

The current ICT risk picture

We go through:

  • the most significant ICT risks,
  • changed risk scenarios,
  • risk acceptances,
  • open actions,
  • identified control weaknesses,
  • the overall security position.

The result is summarised in a way that also works for management reporting.

Critical functions, systems and dependencies

We check whether the documentation still reflects reality. DORA also requires the classification of ICT-supported business functions, information assets, ICT assets and dependencies to be reviewed as needed and at least annually.

Incidents and lessons learned

We go through the relevant incidents during the period. This is not only about reportable incidents. Other events can equally reveal control weaknesses, recurring faults, supplier problems and improvement needs.

For a review following ICT-related incidents the regulation sets specific requirements: incidents and root-cause analysis may need to form part of the report.

Digital operational resilience and testing

We compile and assess results from, for example:

  • restore tests,
  • continuity tests,
  • technical security tests,
  • tabletop exercises,
  • other resilience exercises,
  • TLPT where relevant.

We also check that identified weaknesses have been given an owner and follow-up.

Third-party risk

We go through changes in, for example:

  • critical ICT third parties,
  • supplier risks,
  • incidents,
  • subcontractors,
  • the contractual position,
  • exit plans,
  • the register of information.

That does not necessarily mean every supplier is reviewed from scratch each year. The focus is on what has changed and on what the risk-based follow-up shows.

Continuity and recovery

We review the relevant changes and test results tied to:

  • continuity plans,
  • the DRP,
  • backup and restore,
  • alternative ways of working,
  • supplier dependencies,
  • RTO and RPO.

DORA’s framework explicitly covers continuity, response and recovery, and regular testing.

Audit, compliance and assurance

Results from internal audit, compliance assessments, control testing and external reviews are taken in as relevant inputs.

The delegated regulation explicitly names internal audits, compliance assessments and resilience and TLPT results among the sources of information for the report.

The previous actions

We follow up what was decided last year, what is done, what remains and whether the measures worked. This is also an explicit part of the report format under 2024/1774.

A prioritised annual plan

The review should not only describe the history. It should also give a clear basis for the next period:

  • the highest risks,
  • the most important improvements,
  • ownership,
  • prioritisation,
  • planned follow-up.

What you get

Depending on the scope, the delivery can contain:

  • a structured annual review,
  • an updated picture of the ICT risk framework,
  • a compilation of the major changes,
  • the status of the previous improvements,
  • an assessment of incidents and lessons learned,
  • a compilation of testing and assurance,
  • the third-party and continuity status,
  • identified weaknesses and improvements,
  • a prioritised action plan for the next period,
  • a management presentation,
  • report material structured according to DORA and Regulation 2024/1774.

Regulation 2024/1774 sets out in detail what the report on the review of the ICT risk management framework must contain, including the business context, the risk profile, changes, findings, actions, previous reviews and the sources of information used.

Scope and price

A defined engagement per period, with the scope set by the size of the business, how many DORA workstreams are included and how much source material is already gathered when we start.

The price varies from engagement to engagement and depends on the scope. You get an estimated cost proposal and, where possible, a fixed price. If we also carry out the improvement work, that is scoped separately.

You keep the ownership

The offer is intended as senior reinforcement to the organisation’s own governance. Kristensson i Skåne AB can hold the work together, challenge it, structure it and produce the documentation.

The organisation’s responsible functions and management keep the decisions and the ownership DORA requires. That matters particularly because the regulation also sets requirements on separation and independence between ICT risk management, the control functions and internal audit.

Can the support continue between the annual reviews?

Yes. After the annual review Kristensson i Skåne AB can contribute continuously where needed with, for example:

  • GRC support,
  • follow-up of actions,
  • supplier reviews,
  • continuity,
  • testing and exercises,
  • risk work,
  • governing documents,
  • management reporting.

Our DORA service already describes continuous follow-up and improvement as a natural part of DORA maintenance.

How it works

  1. A first conversation. We listen to your situation and explain how we usually set up the work. You get our assessment straight away, free of charge.
  2. A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
  3. Delivery and handover. We work together with your organisation, report continuously and hand over so that you can maintain the result yourselves.

Frequently asked questions

Does DORA require an annual review?

Yes. For the ordinary ICT risk management framework, financial entities other than microenterprises must review it at least once a year. For microenterprises a periodic review is specified.

Does the report have to be sent to the supervisory authority every year?

DORA states that the report on the review must be available to the competent authority on request. That does not in itself mean every entity automatically submits it each year.

Is this the same as the internal audit of DORA?

No. Internal audit is a separate, independent control activity. Its results can however be an input to the annual review.

Can you help with the improvement work itself?

Yes, but it is scoped separately. If Kristensson i Skåne AB also carries out implementation, roles and any independent review need organising appropriately.

Make DORA a maintained framework, not a finished project

Contact us