DORA reporting and audit: keep the obligations separate
The ICT agreement register, planned-contract notices, incident reports and internal audit have different purposes. Assign owners and use the current submission rules.
The cover image is an AI-generated editorial illustration. Screens and documents are illustrative concepts.
DORA creates several reporting and assurance tasks. They should share accurate underlying information, but they are not one annual compliance submission.
Confirm the rules for your legal entity first. Norway’s September 2026 extension applies adapted requirements and reporting arrangements to additional categories. Instructions for a bank should not automatically be copied into every other firm’s procedure.
Maintain the ICT agreement register throughout the year
DORA Article 28 requires a register of contractual arrangements for ICT services. Keep the relationships between entities, agreements, providers and supported functions accurate as contracts change.
Use Finanstilsynet’s register reporting page for the current reference date, deadline, format and validation requirements. A previous year’s deadline is not a reliable basis for the next submission.
Validate identifiers and links before uploading. Keep the submitted version, receipt and any corrections so the firm can reconcile the report with its source records.
Put planned-contract notices into procurement
For relevant arrangements supporting critical or important functions, Finanstilsynet’s ICT agreement guidance explains advance notification and the Norwegian timing expectations.
Make the assessment early enough to affect the procurement schedule. Assign responsibility for material changes as well as new agreements. A register entry and an advance notice serve different purposes.
Keep the incident clock usable
For major ICT incidents under the standard reporting regime, Finanstilsynet’s guidance sets an initial notification as soon as possible, within four hours of classification and generally no later than 24 hours after awareness. The first status report is due within 72 hours of the initial notification; the final report follows within one month of the last status report.
Use the detailed rules for classification, exceptions and later updates. Record awareness and classification times rather than delaying the decision until an investigation is complete.
A supplier may support or perform agreed reporting tasks, but the financial entity retains responsibility. Ensure someone can access the correct reporting channel during an incident.
Preserve independent assurance and follow-up
DORA’s audit and governance requirements include appropriate competence, independence and management-body oversight, subject to the applicable regime. A consultant who implements a control should not automatically be treated as its independent assurance provider.
Keep findings connected to corrective actions and evidence of completion. The useful record is not merely that an audit occurred, but what it found and what changed.
The DORA checklist links these activities to the wider programme. A reporting calendar should identify each obligation, owner, deputy and source of the current rule.