Skip to content

Clauses corner: DORA documentation requirements

One table, every document BaFin asks to see when it walks in, with the article numbers that justify each ask. Built from the BaFin overview "Documentation requirements for financial entities according to DORA" so you can map your policy stack to the regulation in one pass.

The page is a working index, not commentary. Use it to spot the documents you do not have yet, and to check that what you have is anchored in the right article. The companion policy template is the copy-paste skeleton for filling the gaps.

Download the builder

The DORA documentation builder (Excel) turns this index into a working tool. Pick a document type and a specific document, fill in your details, and export a formatted policy, standard, procedure, strategy or guideline to PDF or Word. The regulation references and section structure are built in, transcribed from the BaFin documentation overview. Always verify each article against EUR-Lex before you rely on it in a filing.

How to use it

  1. Walk the table top to bottom by DORA chapter.
  2. For each row, check whether the named document already exists in your policy register, and whether its current content references the listed articles.
  3. Where a row is empty, the cell shows which DORA article (or RTS article) closes it. Use the template, or the builder above, to draft it.
  4. The "Type" column is the language BaFin uses in the overview: a strategy sits above the policies, a policy states the rules, a procedure, register or plan is the operational evidence.

Every number re-checked against the source

The article numbers on this page were re-transcribed by a direct high-resolution reading of the BaFin overview, then cross-checked: the DORA (Level 1) citations against Regulation (EU) 2022/2554 and the RTS citations against RTS 2024/1774 and RTS 2024/1773 on EUR-Lex. Still confirm against the current consolidated text before relying on the mapping in a filing: RTS article numbers move when the Commission adopts technical amendments.

DORA Chapter II, ICT risk management (Articles 5 to 16)

Strategies

Document DORA article RTS / ITS Type
DOR strategy Article 6(8) in conjunction with Article 5(2)(d) DORA Strategy
Business strategy Article 6(8)(a) DORA Strategy
ICT risk management framework Article 6 DORA Strategy
Communication strategy for ICT-related incidents Article 14(3) in conjunction with Article 6(8)(h) DORA Strategy

Policies

Document DORA article RTS / ITS Type
Information security policy Article 9(4)(a) DORA Policy
ICT business continuity policy Article 11 in conjunction with Article 5(2)(e) and Article 8 DORA Article 24 RTS RMF Policy
(Overall) business continuity policy (incl. BIA) Article 11(1) and (5) in conjunction with Article 5(2)(e) DORA Policy
Backup policies Article 12(1)(a) and (2) DORA Policy
Communication policies for staff (in relation to the ICT risk management framework) Article 14(2) DORA Policy
ICT risk management policies Article 3 RTS RMF Policy
ICT asset management policy Article 9(2) and (4)(c) DORA Article 4 RTS RMF Policy
Policy on encryption and cryptographic controls Article 9(2) DORA Article 6 and 7 RTS RMF Policy
Policies for ICT operations Article 9(2) DORA Article 8 RTS RMF Policy
Policies for patches and updates Article 9(4)(f) DORA Policy
Policies on network security management Article 13 RTS RMF Policy
Policies to protect information in transit Article 14 RTS RMF Policy
ICT project management policy (incl. ICT project risk assessment) Article 15 RTS RMF Policy
Policy governing the acquisition, development and maintenance of ICT systems Article 16(1) RTS RMF Policy
Policies for ICT change management Article 9(4)(e) DORA Policy
Physical and environmental security policy Article 18 RTS RMF Policy
Human resources policy Article 19 RTS RMF Policy
Identity management policies Article 20 RTS RMF Policy
Policy as part of control of access management rights Article 9(4)(c) DORA Article 21 RTS RMF Policy

Procedures, registers and further documentation

Document DORA article RTS / ITS Type
Report on the ICT risk management framework review Article 6(5) DORA Article 27 RTS RMF Report
(ICT) audit plan incl. follow-up process of critical audit findings Article 6(6) to (7) in conjunction with Article 5(2)(f) DORA Plan
Inventory of all ICT supported business functions, roles and responsibilities Article 8(1) and (6) DORA Inventory
Inventory of all (critical) information assets and ICT assets Article 8(1), (4) and (6) DORA Inventory
Inventory of all processes that are dependent on ICT third-party service providers Article 8(5) to (6) DORA Inventory
ICT risk management procedures Article 3 RTS RMF Procedure
ICT asset management procedure Article 5 RTS RMF Procedure
Protection measures of cryptographic keys Article 9(4)(d) DORA Procedure
Procedures for ICT operations Article 9(2) DORA Article 8 RTS RMF Procedure
Register for all certificates and certificate-storing devices (for at least ICT assets supporting critical or important functions) Article 7(4) RTS RMF Register
Capacity and performance management procedures Article 9(2) DORA Article 9 RTS RMF Procedure
Vulnerability management procedures Article 9(2) DORA Article 10(1) to (2) RTS RMF Procedure
Patch management procedures Article 9(2) DORA Article 10(3) to (4) RTS RMF Procedure
Data and system security procedure Article 9(2) DORA Article 11 RTS RMF Procedure
Logging procedures, protocols and tools Article 12 RTS RMF Procedure
Procedures, protocols and tools on network security management Article 13 RTS RMF Procedure
Procedures, protocols and tools to protect information in transit Article 14 RTS RMF Procedure
ICT systems' acquisition, development and maintenance procedure Article 16(2) RTS RMF Procedure
Procedures and controls for ICT change management Article 9(4)(e) DORA Article 17 RTS RMF Procedure
Identity management procedures Article 20(1) RTS RMF Procedure
Procedures that address access rights Article 9(4)(c) DORA Procedure
Mechanisms to promptly detect anomalous activities Article 10 DORA Article 23 RTS RMF Procedure
ICT business continuity plans (ICT BCP) Article 11(6)(a) DORA Article 24 and 25 RTS RMF Plan
Documentation of testing of the ICT BCPs Article 25(5) RTS RMF Procedure
ICT response and recovery plans Article 11(3) in conjunction with Article 5(2)(e) DORA Article 24 and 26 RTS RMF Plan
Records of activities before and during disruption events when their ICT BCPs and ICT response and recovery plans are activated Article 11(8) DORA Records
Backup procedures Article 12(1)(a) and (2) DORA Procedure
Restoration and recovery procedures and methods Article 12(1)(b) and (2) in conjunction with Article 11(2)(c) DORA Procedure
ICT security awareness programmes Article 13(6) in conjunction with Article 5(2)(g) DORA Programme
Digital operational resilience training Article 13(6) in conjunction with Article 5(2)(g) DORA Programme
Document DORA article RTS / ITS Type
ICT-related incident management policy Article 22 and 23 RTS RMF Policy
Crisis communication plans Article 14(1) in conjunction with Article 11(2)(e), (6)(b) and (7) DORA Article 24 RTS RMF Plan
ICT-related incident management process Article 17 DORA RTS CCI; Article 23 RTS RMF Procedure
Records of all ICT-related incidents and significant cyber threats Article 17(2) DORA RTS CTIR and ITS TIR Records

DORA Chapter IV, Digital operational resilience testing (Articles 24 to 27)

Document DORA article RTS / ITS Type
Policies to prioritise, classify and remedy all issues revealed throughout the performance of the tests Article 24(5) DORA Policy
Digital operational resilience testing programme Article 25(1) in conjunction with Article 24(2) DORA Policy
Procedures to prioritise, classify and remedy all issues revealed throughout the performance of the tests Article 24(5) DORA Procedure
Validation methodologies Article 24(5) DORA Procedure

DORA Chapter V (Section I), Key principles for a sound management of ICT third-party risk (Articles 28 to 30)

Document DORA article RTS / ITS Type
Strategy on ICT third-party risk Article 28(2) DORA Strategy
ICT multi-vendor strategy (optional) Article 28(2) in conjunction with Article 6(9) DORA Strategy
Policy on the use of ICT services supporting critical or important functions Article 28(2) and (10) DORA Article 1 to 11 RTS TPPol Policy
Policy regarding the use of ICT services Article 5(2)(h) DORA Policy
Register of information Article 28(3) DORA ITS RoI Register
Exit plans Article 28(8) DORA Article 10 RTS TPPol Plan

Scope of this overview

The BaFin overview covers Chapter II (ICT risk management, section II), Chapter III (incident management, classification and reporting), Chapter IV (digital operational resilience testing) and Chapter V section I (ICT third-party risk). Chapter V sections II and III (the European oversight framework for critical ICT third-party providers) and Chapter VI (information sharing arrangements) are out of scope of the overview, as are requirements that apply only to a small subset of financial entities.

What to do next

  1. Open the builder, or print this table for a second screen.
  2. For each row, mark exists, partial or missing in your policy register.
  3. For every missing row, use the builder or the policy template to draft it, filling the article references from the row.
  4. Re-walk the table once a quarter. RTS articles get renumbered when the Commission adopts technical amendments.

Primary source. BaFin, Documentation requirements for financial entities according to DORA (one-page overview, dated 12.08.2025). Article numbers were transcribed from that document and cross-checked against the DORA Level 1 text and the named RTS on EUR-Lex. Always verify against the current consolidated text of Regulation (EU) 2022/2554 and RTS 2024/1774 before you rely on the mapping in a filing.