What it is
An open-source knowledge base and methodology for mapping DORA (Regulation EU 2022/2554) obligations to any audit scope. 652 paragraph-level chunks across the main regulation and four Regulatory Technical Standards, each tagged with obligation type, entity scope, and cross-references. Feed it an audit topic and entity type, and it returns a structured five-section mapping, plus a fillable Excel testing workbook.
Who it’s for
IT auditors scoping DORA work. Whether you’re at a Big 4 firm, in-house at a financial entity, or a regulator, if you’ve ever manually re-derived DORA scope from scratch, this is for you.
What’s inside
- 652 paragraph-level chunks with 17 metadata fields each
- Production-tested system prompt (v8) for Claude, GPT-4, or Gemini
- Excel conversion prompt that outputs a formatted audit testing workbook
- Three worked examples (encryption, incident management, TLPT)
- MIT licensed
The five-section output
Every mapping the tool produces is structured into the same five sections, so audit teams and reviewers always know where to look:
- 01
Directly Applicable
Obligations that unambiguously apply to the scope you supplied.
- 02
Conditionally Applicable
Obligations that apply only if the entity meets a specific trigger (e.g. significant, critical, cross-border).
- 03
Cross-Referenced RTS/ITS
The Regulatory or Implementing Technical Standards that expand on each obligation.
- 04
Indirect or Awareness
Obligations that don’t apply directly but that an auditor should still be aware of.
- 05
Excluded From Scope
Documented reasons why other DORA articles do not apply. The paper trail regulators expect.