Does DORA apply to my company?
DORA applies to the financial entities listed in its Article 2, including payment and e-money institutions, crypto-asset service providers authorised under MiCA, investment firms and managers of alternative investment funds. We confirm the scope for your company in the quote.
Do you guarantee a bank account?
No. Bank and payment accounts are granted solely at the discretion of the financial institution. We introduce you and prepare the onboarding file; the institution decides.
Is your compliance audit a statutory audit?
No. It is an internal compliance review. A statutory audit of annual accounts is carried out by an auditor and is not part of this service.
Can I order these services without a licence project?
Yes. Each service is quoted on its own. Send a request with a short description of your company and its authorisation.
What is the DORA register of information?
Under Article 28(3) of Regulation (EU) 2022/2554 every financial entity keeps a register of all contractual arrangements for ICT services provided by third parties, makes it available to the authority on request and reports at least yearly on new arrangements.
Why does the DORA register need an annual update?
Because it changes whenever an ICT contract changes, and the authority expects it to be complete and consistent when it asks. Our annual service updates it from your contracts and checks it before submission.
What happens after your compliance audit finds issues?
The remediation plan lists each finding with its priority, the person responsible and a deadline, and we update the policies in scope. The authority, a bank or an auditor who later asks about a finding will expect to see both the plan and the evidence that it was carried out.
Can the remediation plan be ordered without your audit?
It is designed to follow our compliance audit, whose findings it closes. For findings of another reviewer, describe them in the request and we tell you in the quote whether the plan can be built on them.