Article by Aenix Team

DORA compliance checklist for financial services — what to demonstrate to supervisors

What DORA means by demonstrable operational resilience, the findings that recur in audits, and how to work through the architecture checklist.

DoraCozystackFinancial ServicesPlatform EngineeringComplianceObservability

Why DORA timing matters

DORA has been in force since 17 January 2025. Supervisor expectations are sharpening. TLPT exercises are reaching architectures assumed compliant when DORA went live.

For financial entities, “we have a DORA policy” is now insufficient. Supervisors expect demonstrable evidence — at the architecture level — that controls are met.

What demonstrable means

For each Article 6 and Article 28 requirement, you should be able to:

  • Name the control that satisfies it
  • Locate it in the running system (not just policy)
  • Provide evidence in a regulator-consumable format (logs, configurations, test results)

Most-common findings

In Ænix DORA engagements, four findings recur:

  1. Observability data leaving the regulator’s perimeter
  2. Exit plans never tested
  3. Concentration risk treated as procurement question
  4. Sub-contractor chain invisible past first hop

How to use the checklist

Download, walk through with your platform engineering and compliance teams. Identify gaps. Prioritize remediation.

For deeper engagement: DORA compliance services.

Test yourself: DORA evidence checklist

5 questions · ~2 min