Standards and guidance
DORA & AI Agents: Operational Resilience Evidence
EU legislation on digital operational resilience for the financial sector.
How to use this reference
Agent dependencies, ICT risk controls, testing, incident processes and supplier evidence may be relevant to the customer’s DORA programme. Applicability and legal obligations depend on the entity and arrangement. Agent testing alone does not establish DORA compliance.
Evidence to discuss
Identify the system scope, control owner, implementation evidence, test results, exceptions and the reviewer responsible for acceptance. Requirements are mapped to the agreed source version; missing and untested controls remain visible.
Source and status
Regulation (EU) 2022/2554, official text
Reference checked on 7 October 2026. This page is an engineering overview, not legal advice or a claim of accreditation, partnership or endorsement.
Operational resilience discussion
These are engineering discussion prompts, not a substitute for the source requirements or the appointed reviewer's criteria.
- Which agent-supported workflows matter to the institution and its service dependencies?
- Can owners trace tool providers, access changes and recovery responsibilities?
- Which resilience tests and exceptions are linked to the agreed review requirements?
Use the security review checklist to organise owners, test records and gaps. The assessment method explains how coverage limits are recorded.
Start with a clear scope
Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.