Skip to main content
Tool · Open source

DORA Audit Mapper

stop re-reading the regulation.

What it is

An open-source knowledge base and methodology for mapping DORA (Regulation EU 2022/2554) obligations to any audit scope. 652 paragraph-level chunks across the main regulation and four Regulatory Technical Standards, each tagged with obligation type, entity scope, and cross-references. Feed it an audit topic and entity type, and it returns a structured five-section mapping, plus a fillable Excel testing workbook.

Who it’s for

IT auditors scoping DORA work. Whether you’re at a Big 4 firm, in-house at a financial entity, or a regulator, if you’ve ever manually re-derived DORA scope from scratch, this is for you.

What’s inside

  • 652 paragraph-level chunks with 17 metadata fields each
  • Production-tested system prompt (v8) for Claude, GPT-4, or Gemini
  • Excel conversion prompt that outputs a formatted audit testing workbook
  • Three worked examples (encryption, incident management, TLPT)
  • MIT licensed

The five-section output

Every mapping the tool produces is structured into the same five sections, so audit teams and reviewers always know where to look:

  1. 01

    Directly Applicable

    Obligations that unambiguously apply to the scope you supplied.

  2. 02

    Conditionally Applicable

    Obligations that apply only if the entity meets a specific trigger (e.g. significant, critical, cross-border).

  3. 03

    Cross-Referenced RTS/ITS

    The Regulatory or Implementing Technical Standards that expand on each obligation.

  4. 04

    Indirect or Awareness

    Obligations that don’t apply directly but that an auditor should still be aware of.

  5. 05

    Excluded From Scope

    Documented reasons why other DORA articles do not apply. The paper trail regulators expect.