Lesson14 min

The eleven expected deliverables

The list, in production order

#DeliverableArticleDepends on
1Scope and proportionality note2, 4, 16
2Approved ICT risk management framework5, 61
3Digital operational resilience strategy62
4Function / asset / third-party mapping81
5ICT business continuity policy114
6Backup and restoration policy124
7Incident management and classification procedure17, 184
8Notification procedure and report templates197
9Multi-year testing programme24, 254
10Register of information284
11ICT contract clause set3010

Why this order

Deliverable 4 — the mapping — appears early and conditions five others. An organisation that starts with the register of information without having identified its critical functions fills the "function supported" field by guesswork, and will have to redo it all.

The duplication trap

Many organisations already hold an ISO/IEC 27001 ISMS, an ISO 22301 BCMS or arrangements aligned with the EBA guidelines. The reflex is to write brand-new DORA documents alongside the existing ones.

That is an expensive and detectable error: the supervisor finds two backup policies that diverge, two risk registers, two testing programmes. The right approach is to enrich the existing documents and produce a mapping note stating, article by article, where the DORA requirement is met.

What the supervisor looks at first

In the order observed: the board resolution approving the framework (Article 5), the register of information (Article 28), the year's test reports (Article 25), and the record of the last major incident notification (Article 19).

All four are dated, signed documents. None can be improvised the day before a review.

Key takeaways

  • Eleven deliverables cover the bulk of the regulation
  • The Article 8 mapping conditions four other deliverables
  • The register of information is built last but planned first