DORA ICT Risk Management Checklist Template

Most firms built their DORA framework as a project with a January 2025 deadline. The regulation asks for something harder: a framework reviewed at least once a year and after every major ICT-related incident, and approved by a management body that can show what it approved.

The Digital Operational Resilience Act, Regulation (EU) 2022/2554, has applied since 17 January 2025 to EU banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, fund managers and most other regulated financial entities. What remains after go-live is the recurring work: current inventories, tested plans, classified incidents, an up-to-date register of information and a reviewed framework. This free DORA compliance checklist gives ICT risk managers, CISOs and compliance teams a quarterly review with an annual deep review. Conditional logic shows the full or simplified framework tasks, adds the annual phase once a year and adds post-incident tasks after a major incident. Every task has an owner and its evidence, and the management body’s decision is recorded by name.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: September 2026

A DORA Gap Analysis vs a Recurring Framework Review

Many DORA checklists online are gap assessments: forty-odd questions answered once, before the regulation applied. That was the right tool in 2024. Article 6(5) asks for something else: the ICT risk management framework must be reviewed at least once a year (periodically for microenterprises), and also after major ICT-related incidents, supervisory instructions or findings from testing and audits. The competent authority can ask for a report on the review. Other duties are yearly too: asset classification and risk scenarios (Article 8), continuity plan tests (Article 11(6)), tests of systems supporting critical or important functions (Article 24(6)) and register of information reporting (Article 28(3)).

Article 2 lists twenty types of financial entity, from credit institutions to securitisation repositories, with a few exclusions such as occupational pension funds whose schemes have no more than 15 members in total. Article 4 makes the rules proportionate to size, risk profile and complexity. Article 16 puts some smaller entities, such as small and non-interconnected investment firms and exempted payment and e-money institutions, on a simplified framework. Microenterprises outside Article 16 (fewer than 10 staff, turnover or balance sheet up to EUR 2 million) follow the full framework with some lighter duties.

Gap analysis

Are we compliant?

When: once, before go-live or after a restructure.

Output: a list of gaps and a remediation plan.

Weakness: stale the day it is signed.

Recurring framework review

Is the framework still working?

When: quarterly checks, plus the annual review under Article 6(5).

Output: an approved review report, a current register and tested plans.

This template: Phases 1–7.

Event-driven review

What failed, and what changes?

When: after a major incident, a supervisory instruction or a test or audit finding.

Output: a post-incident review under Article 13(2) and framework changes.

This template: conditional tasks in Phase 5.

What the DORA ICT Risk Management Checklist Covers

Phases 1, 2, 5 and 7 run every quarter. Your answers in Phase 1 choose between Phase 3 (full framework) and Phase 4 (simplified framework), switch on Phase 6 for the annual review and add post-incident tasks to Phase 5.

Phase 1

Phase 1: Scope the Review

Owned by the ICT risk management function. Its three answers decide which phases and tasks appear.

  • Open the review record for the period — dates, and whether this is the annual review
  • Confirm which ICT risk management framework applies — full (Articles 5 to 15) or simplified (Article 16)
  • Record whether a major ICT-related incident was classified in the period — attach the incident log
  • Carry forward open findings — audit, testing, supervisory and last quarter’s actions
  • Name the management body approver for this review — who records the Phase 7 decision
Phase 2

Phase 2: Governance, Strategy & ICT Risk

  • Compare ICT risk metrics with the approved risk tolerance — the key risk metrics in the resilience strategy
  • Update the ICT risk register — new risks, changed scores and a risk assessment for each major change
  • Track ICT audit findings to closure — critical findings verified and remediated on time
  • Check what the management body was told this quarter — third-party changes and major incidents
Phase 3 — Full Framework

Phase 3: Protect, Detect & Recover (Articles 7–14)

Shown when the full framework applies. Sample the evidence; do not re-test every control.

  • Check the ICT asset inventories were updated after major changes — assets, critical asset mapping and dependencies (Article 8)
  • Review access, patching and change management exceptions — overdue patches, unapproved changes, stale access (Article 9)
  • Review detection coverage and alert thresholds — new systems monitored, thresholds still firing (Article 10)
  • Confirm backups ran and a restore was tested — on segregated systems, within recovery objectives (Article 12)
  • Record threat intelligence and vulnerability findings assessed — and lessons fed into the risk assessment (Article 13)
  • Confirm the crisis communication plan and contacts are current — including the incident communication lead (Article 14)
Phase 4 — Simplified Only

Phase 4: Simplified Framework (Article 16)

Shown when the entity uses the simplified framework. Title III of Commission Delegated Regulation (EU) 2024/1774 sets out the detail.

  • Confirm the documented simplified framework is current — policies, asset classification and risk management
  • Check continuous monitoring of ICT systems is working — anomalies detected and incidents handled promptly
  • Update the list of key ICT third-party dependencies — new providers and changed services
  • Confirm business continuity, backup and restoration measures were tested — record results and failures
  • Record lessons from tests and incidents in the ICT risk assessment — and any training needs
Phase 5

Phase 5: Incidents & ICT Third Parties

Runs every quarter. The last three tasks appear only when a major ICT-related incident was classified in the period.

  • Reconcile the incident log to classifications — every incident classified under Delegated Regulation (EU) 2024/1772, including recurring ones
  • Review new and changed ICT third-party arrangements — register updated; authority told of planned critical arrangements
  • Check contracts for critical or important functions — Article 30 terms in place, exit plans tested
  • Check each major incident report met its deadline — initial, intermediate and final
  • Confirm affected clients were informed — where their financial interests were affected (Article 19(3))
  • Complete the post-incident review and update the framework — causes and required changes (Articles 6(5) and 13(2))
Phase 6 — Annual Only

Phase 6: Annual Framework Review

Shown only when the review is marked as the annual framework review.

  • Review the ICT risk management framework and strategy — at least once a year (Article 6(5))
  • Refresh the asset classification, risk scenarios and legacy system assessment — each at least yearly (Article 8)
  • Confirm the yearly resilience tests and plan the next cycle — system tests, continuity plan tests and TLPT status
  • Refresh and submit the register of information — data as at 31 December, in your authority’s window
  • Confirm ICT security and resilience training — staff, senior management and the management body
  • Prepare the framework review report — in the Delegated Regulation (EU) 2024/1774 format
Phase 7 — Approval

Phase 7: Management Body Review & Approval

Assigned to the approver named in Phase 1. The management body bears ultimate responsibility for ICT risk (Article 5), so the preparer cannot approve.

  • Present the review pack to the management body — metrics, incidents, tests and open findings
  • Record the management body decision — approved, or returned with the changes required
  • Assign every remediation action an owner and due date — carried into next quarter
  • File the approved review for the competent authority — with the approval date

DORA Requirements Map

DORA sets principles in the regulation and detail in Commission delegated and implementing regulations drafted by the European Supervisory Authorities (EBA, EIOPA and ESMA). The table maps each recurring requirement to its source and the phase that evidences it. Which rules apply to you depends on your entity type, your size and whether you use the simplified framework, so treat the table as a starting point, not legal advice.

Requirement Article / RTS-ITS What evidences it Phase
Management body responsibilityArt. 5(2) and 5(4)Minutes approving the strategy and key policies; training records2, 7
Framework reviewArt. 6(5); Delegated Reg. (EU) 2024/1774, Art. 27Dated review report approved by the management body6, 7
Resilience strategy and risk toleranceArt. 6(8)Strategy with key risk metrics, tracked quarterly2, 6
ICT audit and follow-upArt. 6(6)–(7)Audit plan and a findings tracker with remediation dates2
IdentificationArt. 8Inventories; yearly classification, scenario and legacy reviews3, 6
Protection and detectionArts 9–10; Delegated Reg. (EU) 2024/1774, Title IIAccess reviews, patch and change records, alert thresholds3
Response, recovery and backupArts 11–12Continuity and recovery plan tests at least yearly; restore test results3, 6
Learning, training and communicationArts 13–14Post-incident reviews, training completion, crisis communication plan3, 5, 6
Simplified frameworkArt. 16; Delegated Reg. (EU) 2024/1774, Title IIIDocumented framework, dependency list, test results4
Incident classification and reportingArts 17–19; Delegated Regs (EU) 2024/1772 and 2025/301; Implementing Reg. (EU) 2025/302Incident log, classification record, timestamped reports1, 5
Resilience testing and TLPTArts 24–27; Delegated Reg. (EU) 2025/1190Yearly test results; TLPT at least every 3 years for entities the authority identifies6
ICT third-party risk and registerArts 28–30; Implementing Reg. (EU) 2024/2956; Delegated Reg. (EU) 2024/1773Register of information, authority notifications, contract reviews, exit plans5, 6

DORA does not apply in the UK. UK firms in scope follow the FCA and PRA operational resilience rules, which required them to be able to stay within impact tolerances for important business services by 31 March 2025. New UK incident and third-party reporting rules apply from 18 March 2027, and UK oversight of the first four designated critical third parties began on 13 July 2026. In the EU, the ESAs designated the first critical ICT third-party providers in November 2025; under Article 28 the financial entity stays fully responsible either way. The Commission’s November 2025 Digital Omnibus proposal would add a single EU entry point for incident reports, DORA included. At the time of writing it is still a proposal, and the Commission says it would not change the reporting obligations themselves.

Why Run Your DORA Framework Review in CheckFlow?

1

It starts itself every quarter

A recurring schedule opens the review each quarter and assigns Phase 1 to the ICT risk manager. Mark the review as annual and the yearly obligations appear, so nobody has to remember them.

2

Approval by a named person

The decision task goes to the approver chosen in Phase 1 and records who decided and when. Approval workflows keep the person who prepared the pack separate from the person who approves it.

3

Ready when the authority asks

The competent authority can ask for your review report at any time. Test results, incident reports and minutes sit on the tasks they support, so you export completed reviews with timestamps instead of rebuilding the story from inboxes.

CheckFlow is a checklist and workflow tool, not a GRC suite, SIEM or regulatory reporting portal. It does not classify incidents, run penetration tests or produce the register of information file your authority accepts. It runs the review, evidence and approval work around those systems. Our guide to financial services workflow automation covers DORA alongside KYC and SOX, and CheckFlow for financial services shows other recurring compliance workflows.

Operating in the US too? The GLBA Safeguards Rule Checklist covers the FTC’s security rule for non-bank financial institutions: a different regime and scope, with a similar annual rhythm. See also CheckFlow’s compliance checklist software.

Frequently Asked Questions

Who does DORA apply to?

+

DORA applies to the twenty types of EU financial entity listed in Article 2(1), including credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, fund managers, insurers, insurance intermediaries, occupational pension funds, trading venues and central counterparties. ICT third-party service providers are also in scope, mainly through the oversight of critical providers. Article 2(3) excludes some entities, and Article 4 scales the rules to size and risk. A non-EU group is in scope for its EU-authorised entities.

How often must the ICT risk management framework be reviewed under DORA?

+

At least once a year, or periodically for microenterprises. Article 6(5) also requires a review after major ICT-related incidents, and after supervisory instructions or findings from resilience testing or audits. Entities on the simplified framework review periodically and after major incidents under Article 16(2). In both cases the competent authority can ask for a report on the review, in the format set by Delegated Regulation (EU) 2024/1774. Lighter quarterly checks, as in this template, give the annual review evidence to draw on.

What are the DORA incident reporting deadlines?

+

Under Delegated Regulation (EU) 2025/301, the initial notification of a major ICT-related incident is due within 4 hours of classifying it as major, and no later than 24 hours after becoming aware of it. The intermediate report is due within 72 hours of the initial notification. The final report is due within one month of the latest intermediate report. Weekend and bank holiday relief exists but does not cover every entity, so check it before relying on it. Whether an incident is major is decided with the criteria in Delegated Regulation (EU) 2024/1772.

What is the DORA register of information, and when is it submitted?

+

It is a register of all your contractual arrangements for ICT services, required by Article 28(3) and kept in the templates set by Implementing Regulation (EU) 2024/2956. Entities report it to their competent authority once a year, and authorities pass it to the ESAs by 31 March. In 2026 the data was as at 31 December 2025, and national windows closed around the end of March (the Central Bank of Ireland’s ran from 2 to 31 March). Check your own authority’s window each year.

Does DORA apply to UK firms?

+

Not to UK-authorised firms. They follow the FCA and PRA operational resilience rules and the UK critical third parties regime. A UK group with an EU-authorised subsidiary applies DORA in that subsidiary. The template’s review structure still works in the UK, mapped to important business services and impact tolerances instead of DORA articles.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

An Approved Framework Review Every Year, With the Evidence Attached

Free trial — no credit card required.