Standards and guidance

DORA & AI Agents: Operational Resilience Evidence

EU legislation on digital operational resilience for the financial sector.

How to use this reference

Agent dependencies, ICT risk controls, testing, incident processes and supplier evidence may be relevant to the customer’s DORA programme. Applicability and legal obligations depend on the entity and arrangement. Agent testing alone does not establish DORA compliance.

Evidence to discuss

Identify the system scope, control owner, implementation evidence, test results, exceptions and the reviewer responsible for acceptance. Requirements are mapped to the agreed source version; missing and untested controls remain visible.

Source and status

Regulation (EU) 2022/2554, official text

Reference checked on 7 October 2026. This page is an engineering overview, not legal advice or a claim of accreditation, partnership or endorsement.

Operational resilience discussion

These are engineering discussion prompts, not a substitute for the source requirements or the appointed reviewer's criteria.

  • Which agent-supported workflows matter to the institution and its service dependencies?
  • Can owners trace tool providers, access changes and recovery responsibilities?
  • Which resilience tests and exceptions are linked to the agreed review requirements?

Use the security review checklist to organise owners, test records and gaps. The assessment method explains how coverage limits are recorded.

Start with a clear scope

Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.