Clauses corner: DORA documentation requirements¶
One table, every document BaFin asks to see when it walks in, with the article numbers that justify each ask. Built from the BaFin overview "Documentation requirements for financial entities according to DORA" so you can map your policy stack to the regulation in one pass.
The page is a working index, not commentary. Use it to spot the documents you do not have yet, and to check that what you have is anchored in the right article. The companion policy template is the copy-paste skeleton for filling the gaps.
Download the builder
The DORA documentation builder (Excel) turns this index into a working tool. Pick a document type and a specific document, fill in your details, and export a formatted policy, standard, procedure, strategy or guideline to PDF or Word. The regulation references and section structure are built in, transcribed from the BaFin documentation overview. Always verify each article against EUR-Lex before you rely on it in a filing.
How to use it¶
- Walk the table top to bottom by DORA chapter.
- For each row, check whether the named document already exists in your policy register, and whether its current content references the listed articles.
- Where a row is empty, the cell shows which DORA article (or RTS article) closes it. Use the template, or the builder above, to draft it.
- The "Type" column is the language BaFin uses in the overview: a strategy sits above the policies, a policy states the rules, a procedure, register or plan is the operational evidence.
Every number re-checked against the source
The article numbers on this page were re-transcribed by a direct high-resolution reading of the BaFin overview, then cross-checked: the DORA (Level 1) citations against Regulation (EU) 2022/2554 and the RTS citations against RTS 2024/1774 and RTS 2024/1773 on EUR-Lex. Still confirm against the current consolidated text before relying on the mapping in a filing: RTS article numbers move when the Commission adopts technical amendments.
DORA Chapter II, ICT risk management (Articles 5 to 16)¶
Strategies¶
| Document | DORA article | RTS / ITS | Type |
|---|---|---|---|
| DOR strategy | Article 6(8) in conjunction with Article 5(2)(d) DORA | Strategy | |
| Business strategy | Article 6(8)(a) DORA | Strategy | |
| ICT risk management framework | Article 6 DORA | Strategy | |
| Communication strategy for ICT-related incidents | Article 14(3) in conjunction with Article 6(8)(h) DORA | Strategy |
Policies¶
| Document | DORA article | RTS / ITS | Type |
|---|---|---|---|
| Information security policy | Article 9(4)(a) DORA | Policy | |
| ICT business continuity policy | Article 11 in conjunction with Article 5(2)(e) and Article 8 DORA | Article 24 RTS RMF | Policy |
| (Overall) business continuity policy (incl. BIA) | Article 11(1) and (5) in conjunction with Article 5(2)(e) DORA | Policy | |
| Backup policies | Article 12(1)(a) and (2) DORA | Policy | |
| Communication policies for staff (in relation to the ICT risk management framework) | Article 14(2) DORA | Policy | |
| ICT risk management policies | Article 3 RTS RMF | Policy | |
| ICT asset management policy | Article 9(2) and (4)(c) DORA | Article 4 RTS RMF | Policy |
| Policy on encryption and cryptographic controls | Article 9(2) DORA | Article 6 and 7 RTS RMF | Policy |
| Policies for ICT operations | Article 9(2) DORA | Article 8 RTS RMF | Policy |
| Policies for patches and updates | Article 9(4)(f) DORA | Policy | |
| Policies on network security management | Article 13 RTS RMF | Policy | |
| Policies to protect information in transit | Article 14 RTS RMF | Policy | |
| ICT project management policy (incl. ICT project risk assessment) | Article 15 RTS RMF | Policy | |
| Policy governing the acquisition, development and maintenance of ICT systems | Article 16(1) RTS RMF | Policy | |
| Policies for ICT change management | Article 9(4)(e) DORA | Policy | |
| Physical and environmental security policy | Article 18 RTS RMF | Policy | |
| Human resources policy | Article 19 RTS RMF | Policy | |
| Identity management policies | Article 20 RTS RMF | Policy | |
| Policy as part of control of access management rights | Article 9(4)(c) DORA | Article 21 RTS RMF | Policy |
Procedures, registers and further documentation¶
| Document | DORA article | RTS / ITS | Type |
|---|---|---|---|
| Report on the ICT risk management framework review | Article 6(5) DORA | Article 27 RTS RMF | Report |
| (ICT) audit plan incl. follow-up process of critical audit findings | Article 6(6) to (7) in conjunction with Article 5(2)(f) DORA | Plan | |
| Inventory of all ICT supported business functions, roles and responsibilities | Article 8(1) and (6) DORA | Inventory | |
| Inventory of all (critical) information assets and ICT assets | Article 8(1), (4) and (6) DORA | Inventory | |
| Inventory of all processes that are dependent on ICT third-party service providers | Article 8(5) to (6) DORA | Inventory | |
| ICT risk management procedures | Article 3 RTS RMF | Procedure | |
| ICT asset management procedure | Article 5 RTS RMF | Procedure | |
| Protection measures of cryptographic keys | Article 9(4)(d) DORA | Procedure | |
| Procedures for ICT operations | Article 9(2) DORA | Article 8 RTS RMF | Procedure |
| Register for all certificates and certificate-storing devices (for at least ICT assets supporting critical or important functions) | Article 7(4) RTS RMF | Register | |
| Capacity and performance management procedures | Article 9(2) DORA | Article 9 RTS RMF | Procedure |
| Vulnerability management procedures | Article 9(2) DORA | Article 10(1) to (2) RTS RMF | Procedure |
| Patch management procedures | Article 9(2) DORA | Article 10(3) to (4) RTS RMF | Procedure |
| Data and system security procedure | Article 9(2) DORA | Article 11 RTS RMF | Procedure |
| Logging procedures, protocols and tools | Article 12 RTS RMF | Procedure | |
| Procedures, protocols and tools on network security management | Article 13 RTS RMF | Procedure | |
| Procedures, protocols and tools to protect information in transit | Article 14 RTS RMF | Procedure | |
| ICT systems' acquisition, development and maintenance procedure | Article 16(2) RTS RMF | Procedure | |
| Procedures and controls for ICT change management | Article 9(4)(e) DORA | Article 17 RTS RMF | Procedure |
| Identity management procedures | Article 20(1) RTS RMF | Procedure | |
| Procedures that address access rights | Article 9(4)(c) DORA | Procedure | |
| Mechanisms to promptly detect anomalous activities | Article 10 DORA | Article 23 RTS RMF | Procedure |
| ICT business continuity plans (ICT BCP) | Article 11(6)(a) DORA | Article 24 and 25 RTS RMF | Plan |
| Documentation of testing of the ICT BCPs | Article 25(5) RTS RMF | Procedure | |
| ICT response and recovery plans | Article 11(3) in conjunction with Article 5(2)(e) DORA | Article 24 and 26 RTS RMF | Plan |
| Records of activities before and during disruption events when their ICT BCPs and ICT response and recovery plans are activated | Article 11(8) DORA | Records | |
| Backup procedures | Article 12(1)(a) and (2) DORA | Procedure | |
| Restoration and recovery procedures and methods | Article 12(1)(b) and (2) in conjunction with Article 11(2)(c) DORA | Procedure | |
| ICT security awareness programmes | Article 13(6) in conjunction with Article 5(2)(g) DORA | Programme | |
| Digital operational resilience training | Article 13(6) in conjunction with Article 5(2)(g) DORA | Programme |
DORA Chapter III, ICT-related incident management, classification and reporting (Articles 17 to 23)¶
| Document | DORA article | RTS / ITS | Type |
|---|---|---|---|
| ICT-related incident management policy | Article 22 and 23 RTS RMF | Policy | |
| Crisis communication plans | Article 14(1) in conjunction with Article 11(2)(e), (6)(b) and (7) DORA | Article 24 RTS RMF | Plan |
| ICT-related incident management process | Article 17 DORA | RTS CCI; Article 23 RTS RMF | Procedure |
| Records of all ICT-related incidents and significant cyber threats | Article 17(2) DORA | RTS CTIR and ITS TIR | Records |
DORA Chapter IV, Digital operational resilience testing (Articles 24 to 27)¶
| Document | DORA article | RTS / ITS | Type |
|---|---|---|---|
| Policies to prioritise, classify and remedy all issues revealed throughout the performance of the tests | Article 24(5) DORA | Policy | |
| Digital operational resilience testing programme | Article 25(1) in conjunction with Article 24(2) DORA | Policy | |
| Procedures to prioritise, classify and remedy all issues revealed throughout the performance of the tests | Article 24(5) DORA | Procedure | |
| Validation methodologies | Article 24(5) DORA | Procedure |
DORA Chapter V (Section I), Key principles for a sound management of ICT third-party risk (Articles 28 to 30)¶
| Document | DORA article | RTS / ITS | Type |
|---|---|---|---|
| Strategy on ICT third-party risk | Article 28(2) DORA | Strategy | |
| ICT multi-vendor strategy (optional) | Article 28(2) in conjunction with Article 6(9) DORA | Strategy | |
| Policy on the use of ICT services supporting critical or important functions | Article 28(2) and (10) DORA | Article 1 to 11 RTS TPPol | Policy |
| Policy regarding the use of ICT services | Article 5(2)(h) DORA | Policy | |
| Register of information | Article 28(3) DORA | ITS RoI | Register |
| Exit plans | Article 28(8) DORA | Article 10 RTS TPPol | Plan |
Scope of this overview¶
The BaFin overview covers Chapter II (ICT risk management, section II), Chapter III (incident management, classification and reporting), Chapter IV (digital operational resilience testing) and Chapter V section I (ICT third-party risk). Chapter V sections II and III (the European oversight framework for critical ICT third-party providers) and Chapter VI (information sharing arrangements) are out of scope of the overview, as are requirements that apply only to a small subset of financial entities.
What to do next¶
- Open the builder, or print this table for a second screen.
- For each row, mark exists, partial or missing in your policy register.
- For every missing row, use the builder or the policy template to draft it, filling the article references from the row.
- Re-walk the table once a quarter. RTS articles get renumbered when the Commission adopts technical amendments.
Primary source. BaFin, Documentation requirements for financial entities according to DORA (one-page overview, dated 12.08.2025). Article numbers were transcribed from that document and cross-checked against the DORA Level 1 text and the named RTS on EUR-Lex. Always verify against the current consolidated text of Regulation (EU) 2022/2554 and RTS 2024/1774 before you rely on the mapping in a filing.