
DORA Gap Assessment for EU Financial Firms
The Digital Operational Resilience Act has applied since 17 January 2025. In-scope financial entities must be able to show how they manage ICT risk, handle significant incidents, test resilience and control ICT third-party risk. A policy library alone is not enough. Management needs evidence that the framework operates in practice.
Published 2026-09-09 | Updated 2026-09-09 | GoalTech Ltd
DORA is now an operating requirement
What a gap assessment should examine
The assessment should map evidence to the provisions that apply to the entity. DORA includes proportionality, so the depth of review should reflect the organisation’s size, risk profile and services.
- Governance, accountability and reporting to the management body.
- The ICT risk management framework and asset dependencies.
- Incident detection, classification, response, reporting and learning.
- Business continuity, backup, restoration and crisis communication.
- Digital operational resilience testing and remediation tracking.
- ICT third-party contracts, concentration risk and the register of information.
Consulting support should lead to remediation
GoalTech positions this work as consulting rather than a once-only audit. We review the current framework, interview control owners, sample operating evidence and produce a prioritised action plan. We can then support policy revision, register preparation, control design, testing coordination and management reporting.
Independent assurance may still be required in some circumstances. Consulting work should therefore preserve clear responsibilities and avoid presenting management decisions as the consultant’s own.