Licensed by the Estonian FIU · FIU000117Operating since 2014Punane 6, Tallinn

info@micaconsult.com+372 5089565

LexorCorp Global

Quote on request

Regulatory infrastructure and compliance

The infrastructure a regulated company needs after — and alongside — its authorisation: ICT risk management under DORA, introductions to banking and payment partners, and internal compliance audits.

DORA — digital operational resilience

Regulation (EU) 2022/2554 (DORA) applies from 17 January 2025 (Article 64) to financial entities including payment institutions, e-money institutions, crypto-asset service providers authorised under MiCA, investment firms and managers of alternative investment funds (Article 2). We set up the ICT risk management framework, the incident classification and reporting process, the register of ICT third-party arrangements and the testing plan, with the tooling to run them.

Banking and payment partners

A licensed company still needs accounts. We introduce you to banks, e-money institutions (including institutions that work with crypto-asset businesses), IBAN providers and card issuing or BIN sponsor partners, and prepare the onboarding file. Bank and payment accounts are granted solely at the discretion of the financial institution: an introduction is not an account, and no partner is obliged to accept you.

Compliance audits

Our compliance audit is an internal review of your compliance framework — policies, procedures, records and controls — against the rules that apply to your authorisation. The scope follows the class of the business (Class 1, 2 or 3; for crypto-asset service providers the MiCA classes). It is not a statutory audit of financial statements, which only an auditor can carry out.

What we do not do

We do not guarantee any account, partner decision or supervisory outcome, and we do not replace your compliance officer or management board.

This price is our professional fee for the corporate and regulatory work described. It is not the price of a licence and does not include state or supervisory fees, regulatory capital, or third-party costs. The authorisation is granted by the competent supervisory authority.

Frequently asked questions

Does DORA apply to my company?

DORA applies to the financial entities listed in its Article 2, including payment and e-money institutions, crypto-asset service providers authorised under MiCA, investment firms and managers of alternative investment funds. We confirm the scope for your company in the quote.

Do you guarantee a bank account?

No. Bank and payment accounts are granted solely at the discretion of the financial institution. We introduce you and prepare the onboarding file; the institution decides.

Is your compliance audit a statutory audit?

No. It is an internal compliance review. A statutory audit of annual accounts is carried out by an auditor and is not part of this service.

Can I order these services without a licence project?

Yes. Each service is quoted on its own. Send a request with a short description of your company and its authorisation.

What is the DORA register of information?

Under Article 28(3) of Regulation (EU) 2022/2554 every financial entity keeps a register of all contractual arrangements for ICT services provided by third parties, makes it available to the authority on request and reports at least yearly on new arrangements.

Why does the DORA register need an annual update?

Because it changes whenever an ICT contract changes, and the authority expects it to be complete and consistent when it asks. Our annual service updates it from your contracts and checks it before submission.

What happens after your compliance audit finds issues?

The remediation plan lists each finding with its priority, the person responsible and a deadline, and we update the policies in scope. The authority, a bank or an auditor who later asks about a finding will expect to see both the plan and the evidence that it was carried out.

Can the remediation plan be ordered without your audit?

It is designed to follow our compliance audit, whose findings it closes. For findings of another reviewer, describe them in the request and we tell you in the quote whether the plan can be built on them.

Request a quote

We send the quote by email. No payment is taken on this page.

1. Service
2. The transaction
3. Contact details (all required)

Address

Add-ons and upgrades

What you can add to regulatory infrastructure and compliance

Each add-on states what you receive and what is not included. Prices come from our price list; items marked "quote" are confirmed in a written quote by email.

DORA register of information — annual update

Recommended Quote

Annual update of the register of information on ICT third-party arrangements (Article 28(3) of Regulation (EU) 2022/2554) and its submission support.

Ordered together with: DORA ICT risk management framework and tooling (Regulation (EU) 2022/2554).

What you receive

  • Update of the register from your contracts
  • Consistency check before submission

Not included

  • Negotiating contracts with ICT providers
  • Supervisory fees

State fees, notary fees and the fees of the Financial Supervision Authority or any other public authority are never included in our price; they are paid separately. The decision on any licence, authorisation, registration or register entry is made by the competent authority alone.

Request a quote Read the guide

Remediation plan after a compliance audit

Recommended Quote

A prioritised plan to close the findings of our compliance audit, with owners and deadlines, and the updated documents where needed.

Ordered together with: Compliance audit — Class 1 scope (internal compliance review, not a statutory financial audit); Compliance audit — Class 2 scope (internal compliance review, not a statutory financial audit); Compliance audit — Class 3 scope (internal compliance review, not a statutory financial audit).

What you receive

  • Remediation plan with priorities and deadlines
  • Updated policies for the findings in scope

Not included

  • Implementing IT changes
  • Statutory audit

Request a quote Read the guide

All prices are in euros and exclude VAT. VAT is added where it applies under the Estonian Value Added Tax Act.

All add-ons and upgrades · Price list