Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Agent · dora-2022-2554-6

DORA artikel 6: ICT risk management framework

Structural tree: the article's own paragraphs, verbatim.

CELEX 32022R2554 · 2026-08-18 · Weight 86 · minimal-risk

ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.

DORAOfficial source

What this page is
Agent, DORA artikel 6
Checked against the official source
2026-08-18Current
Responsible publisher
ExploreWorld Legal, editorial deskLiability position

Jurisdiction

The same agent, read through one country's lens.

Inputs

  • in_scopeThe article applies to the situationboolean
  • punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)

Rule tree

  1. If: alla(in_scope = true, punkt = 1)

    Paragraph 1 applies

    1. Financial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system, which enables them to address ICT risk quickly, efficiently and comprehensively and to ensure a high level of digital operational resilience.

    Paragraph 1

  2. If: alla(in_scope = true, punkt = 2)

    Paragraph 2 applies

    2. The ICT risk management framework shall include at least strategies, policies, procedures, ICT protocols and tools that are necessary to duly and adequately protect all information assets and ICT assets, including computer software, hardware, servers, as well as to protect all relevant physical components and infrastructures, such as premises, data centres and sensitive designated areas, to ensure that all informa…

    Paragraph 2

  3. If: alla(in_scope = true, punkt = 3)

    Paragraph 3 applies

    3. In accordance with their ICT risk management framework, financial entities shall minimise the impact of ICT risk by deploying appropriate strategies, policies, procedures, ICT protocols and tools. They shall provide complete and updated information on ICT risk and on their ICT risk management framework to the competent authorities upon their request.

    Paragraph 3

  4. If: alla(in_scope = true, punkt = 4)

    Paragraph 4 applies

    4. Financial entities, other than microenterprises, shall assign the responsibility for managing and overseeing ICT risk to a control function and ensure an appropriate level of independence of such control function in order to avoid conflicts of interest. Financial entities shall ensure appropriate segregation and independence of ICT risk management functions, control functions, and internal audit functions, accordi…

    Paragraph 4

  5. If: alla(in_scope = true, punkt = 5)

    Paragraph 5 applies

    5. The ICT risk management framework shall be documented and reviewed at least once a year, or periodically in the case of microenterprises, as well as upon the occurrence of major ICT-related incidents, and following supervisory instructions or conclusions derived from relevant digital operational resilience testing or audit processes. It shall be continuously improved on the basis of lessons derived from implementa…

    Paragraph 5

  6. If: alla(in_scope = true, punkt = 6)

    Paragraph 6 applies

    6. The ICT risk management framework of financial entities, other than microenterprises, shall be subject to internal audit by auditors on a regular basis in line with the financial entities’ audit plan. Those auditors shall possess sufficient knowledge, skills and expertise in ICT risk, as well as appropriate independence. The frequency and focus of ICT audits shall be commensurate to the ICT risk of the financial e…

    Paragraph 6

  7. If: alla(in_scope = true, punkt = 7)

    Paragraph 7 applies

    7. Based on the conclusions from the internal audit review, financial entities shall establish a formal follow-up process, including rules for the timely verification and remediation of critical ICT audit findings.

    Paragraph 7

  8. If: alla(in_scope = true, punkt = 8)

    Paragraph 8 applies

    8. The ICT risk management framework shall include a digital operational resilience strategy setting out how the framework shall be implemented. To that end, the digital operational resilience strategy shall include methods to address ICT risk and attain specific ICT objectives, by:

    Paragraph 8

  9. If: alla(in_scope = true, punkt = 9)

    Paragraph 9 applies

    (a)

    Paragraph 9

  10. If: alla(in_scope = true, punkt = 10)

    Paragraph 10 applies

    explaining how the ICT risk management framework supports the financial entity’s business strategy and objectives;

    Paragraph 10

  11. If: alla(in_scope = true, punkt = 11)

    Paragraph 11 applies

    (b)

    Paragraph 11

  12. If: alla(in_scope = true, punkt = 12)

    Paragraph 12 applies

    establishing the risk tolerance level for ICT risk, in accordance with the risk appetite of the financial entity, and analysing the impact tolerance for ICT disruptions;

    Paragraph 12

  13. If: alla(in_scope = true, punkt = 13)

    Paragraph 13 applies

    (c)

    Paragraph 13

  14. If: alla(in_scope = true, punkt = 14)

    Paragraph 14 applies

    setting out clear information security objectives, including key performance indicators and key risk metrics;

    Paragraph 14

If no rule matches: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.

The article text as read

  1. 11. Financial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system, which enables them to address ICT risk quickly, efficiently and comprehensively and to ensure a high level of digital operational resilience.
  2. 22. The ICT risk management framework shall include at least strategies, policies, procedures, ICT protocols and tools that are necessary to duly and adequately protect all information assets and ICT assets, including computer software, hardware, servers, as well as to protect all relevant physical components and infrastructures, such as premises, data centres and sensitive designated areas, to ensure that all information assets and ICT assets are adequately protected from risks including damage and unauthorised access or usage.
  3. 33. In accordance with their ICT risk management framework, financial entities shall minimise the impact of ICT risk by deploying appropriate strategies, policies, procedures, ICT protocols and tools. They shall provide complete and updated information on ICT risk and on their ICT risk management framework to the competent authorities upon their request.
  4. 44. Financial entities, other than microenterprises, shall assign the responsibility for managing and overseeing ICT risk to a control function and ensure an appropriate level of independence of such control function in order to avoid conflicts of interest. Financial entities shall ensure appropriate segregation and independence of ICT risk management functions, control functions, and internal audit functions, according to the three lines of defence model, or an internal risk management and control model.
  5. 55. The ICT risk management framework shall be documented and reviewed at least once a year, or periodically in the case of microenterprises, as well as upon the occurrence of major ICT-related incidents, and following supervisory instructions or conclusions derived from relevant digital operational resilience testing or audit processes. It shall be continuously improved on the basis of lessons derived from implementation and monitoring. A report on the review of the ICT risk management framework shall be submitted to the competent authority upon its request.
  6. 66. The ICT risk management framework of financial entities, other than microenterprises, shall be subject to internal audit by auditors on a regular basis in line with the financial entities’ audit plan. Those auditors shall possess sufficient knowledge, skills and expertise in ICT risk, as well as appropriate independence. The frequency and focus of ICT audits shall be commensurate to the ICT risk of the financial entity.
  7. 77. Based on the conclusions from the internal audit review, financial entities shall establish a formal follow-up process, including rules for the timely verification and remediation of critical ICT audit findings.
  8. 88. The ICT risk management framework shall include a digital operational resilience strategy setting out how the framework shall be implemented. To that end, the digital operational resilience strategy shall include methods to address ICT risk and attain specific ICT objectives, by:
  9. 9(a)
  10. 10explaining how the ICT risk management framework supports the financial entity’s business strategy and objectives;
  11. 11(b)
  12. 12establishing the risk tolerance level for ICT risk, in accordance with the risk appetite of the financial entity, and analysing the impact tolerance for ICT disruptions;
  13. 13(c)
  14. 14setting out clear information security objectives, including key performance indicators and key risk metrics;

Lineage

treatyTFEU art. 288 (förordning)
act32022R2554
chapter
article6
paragraphs14
jurisdictionEuropean Union (EU)
supervisorFinansinspektionen — Sweden
national

Interface

callhttps://legal.exploreworldai.com/api/public/v1/agents/dora-2022-2554-6/run
methodGET
outputmatched, outcome, trace, missing, hash
Quota60 anrop per minut och adress, utan nyckel
stabilityRegelträdet versioneras. En ändring byter artefakthash, aldrig adress.

Hashes

textsha256:91bf28528f2f64d55e4a513a432b23f23a32b4f21f9aafa7e1406a5ed416665c
scriptsha256:f14755f69bd6aadf3a182760e6d046811376c63a353d3c750d9183029ef0088a
enginesha256:0a4bd50d21f8ec9be383fc091511008b76ad61909cbfb674eab56fe567fbd7a0
agentsha256:ce00136fb4b631cbb47e7645f83003bf42720eda27ad3800d9c89fbd2ab650d4
versionagent-engine-1+legal-2026-08-25 / ce00136fb4b631cb

Artefacts

No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.

Citation: 32022R2554 art. 6, ICT risk management framework. ExploreWorld Legal, https://legal.exploreworldai.com/agent/dora-2022-2554/artikel-6 (hämtad 2026-08-18, bevis sha256:3d0b93d61bc51814, bygge legal-2026-08-25).