Licensed by the Estonian FIU · FIU000117Operating since 2014Punane 6, Tallinn

info@micaconsult.com+372 5089565

LexorCorp Global

Ordered and paid online

Regulatory infrastructure and compliance: DORA, banking partners and audits

The infrastructure a regulated company needs after — and alongside — its authorisation: ICT risk management under DORA, introductions to banking and payment partners, and internal compliance audits.

In short

Compliance for regulated firms: DORA ICT risk framework, banking and payment introductions, and compliance audits. The price is from €2,200, excluding VAT. How long it takes: DORA framework 8–12 weeks; introductions 2–6 weeks depending on the partners; audits 3–8 weeks.

How the process works

  1. Order. You choose the service and its add-ons in the order form at the end of this page and pay by card. The amount is our fee for the standard scope described on this page. Third-party costs are not part of it.
  2. Assessment. We assess the planned business against the requirements and, as a licensed provider, carry out due diligence on every client first. If the project needs work beyond the standard scope, we tell you the additional fee in writing and that work is done only with your written agreement; before the work has started you may cancel by email and receive a full refund.
  3. Preparation. We draft the framework, policies and registers from the information you give us. You review the drafts and name the owners.
  4. Delivery. You receive the documents with the evidence of what was checked, ready to be used by your own compliance function.

The documents that are prepared

A DORA project delivers:

  • a gap analysis
  • the ICT risk management framework and policies
  • the incident classification and reporting procedure
  • the testing programme
  • the third-party risk policy with a contract clause checklist
  • the first register of information

What LexorCorp does

  • analyse where your firm stands against the requirement
  • draft the documents listed above
  • deliver them with the evidence of what was checked
  • for banking and payment partners: prepare your introduction file — the partner alone decides

What you do

  • name the owner of each control in your firm — we do not replace your compliance officer or management board
  • give us the information on your ICT systems, providers and contracts that the documents describe
  • decide on banks and payment partners yourself; their decisions and fees are theirs

What the authority does

The authority is your own supervisory authority — these services are delivered to your firm; there is no application to an authority.

  • under DORA every financial entity keeps a register of all contractual arrangements for ICT services provided by third parties, makes it available to the authority on request and reports at least yearly on new arrangements
  • your supervisor assesses your firm, not our documents: we do not guarantee any supervisory outcome

Timeline

These are projects for your firm, not applications, so no authority's period applies. We confirm the delivery time for the scope you choose in writing before the work starts.

Our fee

ServicePrice
ICT and operational resilience
DORA ICT risk management framework and tooling (Regulation (EU) 2022/2554)Fee for the standard scope — ordered and paid onlinefrom €39,500
DORA register of information — annual updateFee for the standard scope — ordered and paid onlinefrom €2,400 / year
Banking and payment accounts
Extended banking onboarding — introductions to 6 banking and payment partnersFee for the standard scope — ordered and paid onlinefrom €3,900
Premium banking onboardingFee for the standard scope — ordered and paid onlinefrom €5,600
Introduction to a crypto-friendly e-money institutionFee for the standard scope — ordered and paid onlinefrom €2,200
Multi-currency IBAN account set-upFee for the standard scope — ordered and paid onlinefrom €2,800
Card issuing / BIN sponsor introductionFee for the standard scope — ordered and paid onlinefrom €4,500
Compliance audits
Compliance audit — Class 1 scope (internal compliance review, not a statutory financial audit)Fee for the standard scope — ordered and paid onlinefrom €8,500
Compliance audit — Class 2 scope (internal compliance review, not a statutory financial audit)Fee for the standard scope — ordered and paid onlinefrom €15,500
Compliance audit — Class 3 scope (internal compliance review, not a statutory financial audit)Fee for the standard scope — ordered and paid onlinefrom €27,000
Remediation plan after a compliance auditFee for the standard scope — ordered and paid onlinePrepared for your company: usually delivered within 7 working days after we have received the necessary information.from €1,700

This price is our professional fee for the corporate and regulatory work described. It is not the price of a licence and does not include state or supervisory fees, regulatory capital, or third-party costs. The authorisation is granted by the competent supervisory authority.

Order

State fees

No state fee is charged for these services. Fees of banks, payment institutions, software and data providers are third-party costs and are charged by them.

What is not included in our fee

We do not guarantee any account, partner decision or supervisory outcome, and we do not replace your compliance officer or management board.

This price is our professional fee for the corporate and regulatory work described. It is not the price of a licence and does not include state or supervisory fees, regulatory capital, or third-party costs. The authorisation is granted by the competent supervisory authority.

Our own licence FIU000117, issued by the Estonian Financial Intelligence Unit, covers LexorCorp Global's activity as a company service provider. It is not an authorisation for your business and gives us no right to grant one: the final decision on every licence, authorisation and registration is made by the competent supervisory authority alone.

DORA — digital operational resilience

Regulation (EU) 2022/2554 (DORA) applies from 17 January 2025 (Article 64) to financial entities including payment institutions, e-money institutions, crypto-asset service providers authorised under MiCA, investment firms and managers of alternative investment funds (Article 2). We set up the ICT risk management framework, the incident classification and reporting process, the register of ICT third-party arrangements and the testing plan, with the tooling to run them.

Banking and payment partners

A licensed company still needs accounts. We introduce you to banks, e-money institutions (including institutions that work with crypto-asset businesses), IBAN providers and card issuing or BIN sponsor partners, and prepare the onboarding file. Bank and payment accounts are granted solely at the discretion of the financial institution: an introduction is not an account, and no partner is obliged to accept you.

Compliance audits

Our compliance audit is an internal review of your compliance framework — policies, procedures, records and controls — against the rules that apply to your authorisation. The scope follows the class of the business (Class 1, 2 or 3; for crypto-asset service providers the MiCA classes). It is not a statutory audit of financial statements, which only an auditor can carry out.

What goes with each service: required and recommended add-ons

Required add-ons are added to the order with the service. Strongly recommended add-ons arrive ticked and can be removed. Each line names the provision it rests on, read in the official text. General information about our services, not legal advice.

DORA ICT risk management framework and tooling (Regulation (EU) 2022/2554)

Strongly recommended

Add-ons and upgrades

What you can add to regulatory infrastructure and compliance

Each add-on states what you receive and what is not included. Prices come from our price list; every add-on is ordered and paid in the order form on this page.

DORA register of information — annual update

from €2,400 / yearRecommended Strongly recommended

Full description

Annual update of the register of information on ICT third-party arrangements (Article 28(3) of Regulation (EU) 2022/2554) and its submission support.

Ordered together with: DORA ICT risk management framework and tooling (Regulation (EU) 2022/2554).

What you receive

  • Update of the register from your contracts
  • Consistency check before submission

Not included

  • Negotiating contracts with ICT providers
  • Supervisory fees

No state fee or notary fee applies to this service; banks, payment institutions and software providers charge their own fees directly.

Order Read the guide

Remediation plan after a compliance audit

from €1,700Recommended

Full description

A prioritised plan to close the findings of our compliance audit, with owners and deadlines, and the updated documents where needed.

Ordered together with: Compliance audit — Class 1 scope (internal compliance review, not a statutory financial audit); Compliance audit — Class 2 scope (internal compliance review, not a statutory financial audit); Compliance audit — Class 3 scope (internal compliance review, not a statutory financial audit).

What you receive

  • Remediation plan with priorities and deadlines
  • Updated policies for the findings in scope

Not included

  • Implementing IT changes
  • Statutory audit

No state fee or notary fee applies to this service; banks, payment institutions and software providers charge their own fees directly.

Order Read the guide

All prices are in euros and exclude VAT. VAT is added where it applies under the Estonian Value Added Tax Act.

All add-ons and upgrades · Price list

Each service in detail

General information, not legal advice. Prices are in the table above.

DORA ICT risk management framework and tooling (Regulation (EU) 2022/2554)

DORA ICT risk management framework and tooling, and the annual update of the register of information on ICT third-party providers.

For whom: Financial entities under DORA.

What you receive

  • ICT risk management framework documents
  • Register of information

Conditions

The entity remains responsible for implementation. FIU licence FIU000117 is LexorCorp's own licence for its trust and company services; it does not authorise the client.

Law and requirements

  • Regulation (EU) 2022/2554 (DORA)

Not included in the price

  • ICT systems and testing

Who does what

LexorCorp
Prepare the application and its documents and manage the procedure until the decision.
You
Provide information, capital and people that meet the legal requirements; sign and answer the authority's questions.
Authority
The competent supervisor.

DORA ICT risk management framework and tooling (Regulation (EU) 2022/2554): price, requirements, process and deadline on its own page

DORA register of information — annual update: see DORA ICT risk management framework and tooling (Regulation (EU) 2022/2554).

Extended banking onboarding — introductions to 6 banking and payment partners

Introductions to banking, payment, crypto-friendly e-money, IBAN and card issuing (BIN sponsor) partners, and support with their onboarding.

For whom: Regulated and fintech companies looking for accounts and partners.

What you receive

  • Introductions and onboarding support

Conditions

Each partner decides on onboarding; we cannot promise an account or partnership. We prepare you for each partner's onboarding requirements — business model, compliance framework, ownership and source of funds — and coordinate the process.

Law and requirements

  • The partners' own due diligence obligations

Not included in the price

  • The partners' fees

Who does what

LexorCorp
Prepare the application and its documents and manage the procedure until the decision.
You
Provide information, capital and people that meet the legal requirements; sign and answer the authority's questions.
Authority
The partners decide.

Extended banking onboarding — introductions to 6 banking and payment partners: price, requirements, process and deadline on its own page

Premium banking onboarding: see Extended banking onboarding — introductions to 6 banking and payment partners.

Introduction to a crypto-friendly e-money institution: see Extended banking onboarding — introductions to 6 banking and payment partners.

Multi-currency IBAN account set-up: see Extended banking onboarding — introductions to 6 banking and payment partners.

Card issuing / BIN sponsor introduction: see Extended banking onboarding — introductions to 6 banking and payment partners.

Compliance audit — Class 1 scope (internal compliance review, not a statutory financial audit)

An internal compliance review of a regulated firm in the chosen scope, and a remediation plan after it. It is not a statutory financial audit and not an auditor's service.

For whom: Licensed firms preparing for supervision or after findings.

What you receive

  • Review report
  • Remediation plan (if ordered)

Conditions

Scope agreed in writing.

Law and requirements

  • The firm's regulatory framework

Not included in the price

  • Statutory audit
  • Legal opinion

Who does what

LexorCorp
Prepare the application and its documents and manage the procedure until the decision.
You
Provide information, capital and people that meet the legal requirements; sign and answer the authority's questions.
Authority
None; the supervisor may review the firm separately.

Compliance audit — Class 1 scope (internal compliance review, not a statutory financial audit): price, requirements, process and deadline on its own page

Compliance audit — Class 2 scope (internal compliance review, not a statutory financial audit): see Compliance audit — Class 1 scope (internal compliance review, not a statutory financial audit).

Compliance audit — Class 3 scope (internal compliance review, not a statutory financial audit): see Compliance audit — Class 1 scope (internal compliance review, not a statutory financial audit).

Remediation plan after a compliance audit: see Compliance audit — Class 1 scope (internal compliance review, not a statutory financial audit).

Frequently asked questions

Does DORA apply to my company?

DORA applies to the financial entities listed in its Article 2, including payment and e-money institutions, crypto-asset service providers authorised under MiCA, investment firms and managers of alternative investment funds. We confirm the scope for your company in writing before the work starts.

Do you guarantee a bank account?

No. Bank and payment accounts are granted solely at the discretion of the financial institution. We introduce you and prepare the onboarding file; the institution decides.

Is your compliance audit a statutory audit?

No. It is an internal compliance review. A statutory audit of annual accounts is carried out by an auditor and is not part of this service.

Can I order these services without a licence project?

Yes. Each service is ordered and paid on its own on this page; you describe your company and its authorisation in the order form.

What is the DORA register of information?

Under Article 28(3) of Regulation (EU) 2022/2554 every financial entity keeps a register of all contractual arrangements for ICT services provided by third parties, makes it available to the authority on request and reports at least yearly on new arrangements.

Why does the DORA register need an annual update?

Because it changes whenever an ICT contract changes, and the authority expects it to be complete and consistent when it asks. Our annual service updates it from your contracts and checks it before submission.

What happens after your compliance audit finds issues?

The remediation plan lists each finding with its priority, the person responsible and a deadline, and we update the policies in scope. The authority, a bank or an auditor who later asks about a finding will expect to see both the plan and the evidence that it was carried out.

Can the remediation plan be ordered without your audit?

It is designed to follow our compliance audit, whose findings it closes. For findings of another reviewer, describe them in the order form and we tell you in writing before the work starts whether the plan can be built on them.

Can you guarantee a bank account?

No. Each bank or payment partner decides on onboarding; we prepare you and introduce you.

Is the compliance audit a statutory audit?

No. It is an internal compliance review; it is not a statutory financial audit and not an auditor's service.

What are the risks of DORA non-compliance?

Supervisory findings and measures by the competent authority; the entity remains responsible for its ICT risk framework.

Order

Choose the service and its add-ons, enter your details and pay by card. The total is shown before you pay and changes as you tick or untick an add-on.

1. Service and add-ons

Add-ons for this service — tick what you need

from €2,400 / year
from €1,700
2. Your project
3. Contact details (all required)

Address

Your order

  • Introduction to a crypto-friendly e-money institution€2,200

Total, excluding VAT€2,200

The amount you pay now is our fee for the standard scope described on this page. If your project needs work beyond that scope, we tell you the additional fee in writing before that work starts, and it is done only with your written agreement. Before the work has started you may cancel by email and receive a full refund (Terms of service, section 10).

Our service is the preparation of documents and the organisation of the work described. It is not legal advice, an advocate's service or a statutory audit; your supervisor assesses your firm, not our documents.

Total, excluding VAT €2,200

After you submit, Revolut's secure card payment page opens. All communication about your order takes place by email.