DORA Audit & Supervisory Review: Navigate Internal and External DORA Examinations

DORA requires financial institutions to conduct regular internal ICT audits and prepares them for external supervisory reviews by BaFin and statutory auditors.

  • 01BaFin supervisory review preparation with mock examinations
  • 02Internal ICT audit programs meeting DORA requirements
  • 03Audit-ready documentation and complete evidence trails
  • 04Third-party audit coverage across your ICT supply chain
  • 05Sustainable audit readiness through continuous monitoring
11+Years of experience
120+Employees
540+Projects
ISO 27001certified

DORA Audits: Governance Review, Not Just IT Control

DORA audits are not traditional IT audits. BaFin and statutory auditors examine governance, accountability, and the effectiveness of your ICT risk framework - not just whether policies exist, but whether they are actively lived. Our experts support you with internal audits, BaFin supervisory review preparation, and sustainable audit readiness.

6 service modules

What we take on for you

Bookable individually or as an end-to-end programme.

01

DORA Compliance Audit and Readiness Assessment

Comprehensive assessment of your DORA compliance position through systematic audits of all relevant requirement areas and identification of improvement opportunities.

  • Complete assessment of all DORA requirement areas and compliance status
  • Risk-based audit methodology and gap analysis
  • Assessment of the effectiveness of implemented controls and processes
  • Prioritized action recommendations and remediation roadmap
02

Regulatory Review Preparation

Specialized preparation for regulatory DORA inspections and external reviews through simulated audits and readiness checks.

  • Simulation of regulatory review procedures and inspection readiness tests
  • Preparation of documentation and evidence for supervisory authorities
  • Training and coaching for review discussions and presentations
  • Development of response strategies and communication plans
03

Third-Party Audit and Vendor Assessment

Systematic assessment of your ICT third-party providers and critical service providers to ensure DORA compliance throughout the supply chain.

  • Comprehensive audits of critical ICT third-party providers and service providers
  • Assessment of third-party controls and resilience measures
  • Development of vendor risk assessment programs
  • Continuous monitoring and re-assessment processes
04

Continuous Monitoring and Assurance

Establishment of systematic monitoring programs for continuous validation of DORA compliance and early identification of risks.

  • Design and implementation of continuous monitoring programs
  • Automated compliance checks and alert mechanisms
  • Regular assurance reviews and trend analyses
  • Integration into existing GRC platforms and reporting systems
05

Technical ICT Audits and Penetration Testing

Specialized technical audits for assessing ICT security and operational resilience of your critical systems and infrastructures.

  • Comprehensive technical audits of critical ICT systems and infrastructures
  • DORA-compliant penetration tests and vulnerability assessments
  • Assessment of cybersecurity controls and incident response capabilities
  • Threat-based testing and red team exercises
06

Audit Program Development and Governance

Building solid internal audit programs and governance structures for sustainable DORA compliance and continuous improvement.

  • Development of customized DORA audit programs and methodologies
  • Building internal audit capabilities and competency development
  • Integration into existing three-lines-of-defense models
  • Establishment of audit governance and quality assurance processes

5 phases

Our Systematic Audit Approach

We develop customized DORA audit programs with you that ensure both regulatory compliance and operational effectiveness.

  1. Strategic audit planning and risk assessment

  2. Systematic execution of compliance assessments

  3. Detailed documentation and reporting

  4. Remediation support and improvement recommendations

  5. Continuous monitoring and follow-up processes

Sarah Richter

Your contact

Sarah Richter

Head of Information Security, Cyber Security

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Effective DORA audits are more than compliance validation, they are strategic instruments for strengthening operational resilience. Our risk-based audit approach identifies not only regulatory gaps but also creates sustainable value through continuous improvement of digital resilience.

6 QUESTIONS, BRIEFLY ANSWERED

Frequently asked questions about DORA Audit & Supervisory Review

What are the basic DORA audit requirements, and how do they differ from classic IT audits?

A DORA audit doesn't just check technical IT controls; it verifies whether the processes required across all five DORA pillars actually work: risk management, incident reporting, resilience testing, third-party management, and information sharing. A classic IT audit usually checks a narrower set of technical controls without this supervisory framing and without the documentation depth DORA requires.

How do you prepare for a supervisor-ready DORA audit?

Before the actual audit, an internal review against the real DORA requirements is worthwhile, not just against an internal policy, since internal policies can drift from the regulatory baseline. It's especially important that all evidence, such as logs of completed tests or the third-party register, actually exists and isn't just documented as an intention, since that's exactly what supervisors check first.

What role do penetration testing and TLPT play in a DORA audit?

Threat-Led Penetration Testing (TLPT) is mandatory for certain, typically larger, financial entities and simulates real attack scenarios against critical systems under the oversight of an accredited tester. A DORA audit checks whether such tests were performed at the required frequency, whether results are documented, and whether identified weaknesses were actually remediated rather than just logged.

How should the scope of a DORA audit be defined?

Scope should be driven by the criticality of the systems and processes being reviewed rather than treating all areas with equal depth. A first-time audit usually covers more ground to surface baseline gaps; follow-up audits can focus more on previously identified weaknesses and particularly critical third-party relationships.

How are DORA audits conducted for critical ICT third-party providers?

Since ICT risk responsibility stays with the financial entity, the effectiveness of outsourced controls must also be verified, either through contractually secured audit rights at the provider or through the provider's certifications and audit reports, provided these are sufficiently substantive. For particularly critical providers, a certificate alone is often not enough; independent audit rights should be contractually secured.

How are remediation plans from DORA audit findings developed and tracked?

Findings should be prioritized by risk relevance and tied to concrete, time-bound actions with clear ownership. A tracking process that checks implementation status at fixed intervals is essential; unresolved findings carried over from a prior audit are a particularly strong red flag for supervisors at the next review.

Certificates, partners and more

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance