DI

    dora ict register audit

    by Elyas Shukri Elmi

    1

    Audits DORA ICT registers and contracts for template integrity, missing arrangements, and Article 30 clause compliance.

    Secure checkout via Stripe

    0 installsSecurity scanned

    Works with the AI tools you already use

    CClaude CodeCCursorCCodex CLIGGitHub CopilotGGemini CLIVVS CodeWWindsurf+15 more

    See it in action

    You say

    Audit our ICT register export and these three vendor contracts for DORA Article 30 compliance. We have marked the AWS arrangement as supporting a critical function.

    Your agent does

    Register Audit: 2 broken references found (Provider ID P-09 lacks LEI in Provider Template). Contract Audit: AWS contract lacks the Article 30(3) 'unrestricted audit rights' clause despite being marked critical. Two legacy contracts (signed 2023) lack mandatory insolvency data return clauses.

    What you get

    Identify missing sub-outsourcers and intra-group ICT providers in the register.Check relational integrity across all 15 DORA ITS register templates.Verify Article 30(2) and 30(3) clause presence in ICT contracts.Flag non-remediated legacy contracts signed before January 2025.

    About this skill

    The problem

    EU financial entities face severe regulatory risk if their ICT registers are incomplete or internally inconsistent. Most firms struggle with "shadow SaaS" bought outside IT and legacy contracts that lack mandatory DORA clauses, leading to failed ESA submissions.

    What it does

    • Audits the register of information for relational integrity across all 15 ITS templates to find broken cross-references.
    • Identifies missing arrangements, including sub-outsourcers, intra-group providers, and SaaS tools procured outside formal IT channels.
    • Maps ICT contracts against Article 30 mandatory clause requirements, distinguishing between standard and critical/important functions.
    • Flags legacy contracts signed before 2025-01-17 that require remediation to meet current standards.
    • Verifies that the entity's own critical/important function determinations are documented and correctly reflected in the contract set.

    Why this beats prompting it yourself

    General LLMs treat registers as flat lists rather than the complex relational models required by ITS 2024/2956. This skill enforces the specific cross-template reconciliation logic that supervisors use to find failures, and it prevents the common mistake of assuming pre-2025 contracts are grandfathered.

    Use cases

    • Reviewing a draft register before the annual April ESA submission deadline.
    • Conducting a gap analysis on legacy ICT contract portfolios to prioritize legal remediation.
    • Verifying relational integrity between provider tables and supported function templates.
    • Cross-checking internal "critical or important" determinations against required 30(3) enhanced clauses.

    Known limitations

    This skill cannot make binding critical/important function determinations or certify full DORA compliance. It does not cover the incident reporting, resilience testing, or governance pillars.

    How to install

    Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean today

    Listedtoday

    Creator

    Frequently Asked Questions

    Browse More Skills