DOC 1
Register of information
Your ICT third-party arrangements in the format required by the European Supervisory Authorities,
maintained from the vendor module.
DOC 2
Major incident reports
Classification against the DORA criteria, followed by the initial, intermediate and final reports,
with deadlines tracked from the incident record.
Initial: 4 hoursIntermediate: 72 hoursFinal: 1 month
DOC 3
Board report
A quarterly summary of ICT risk for the management body, with every figure traceable to its
evidence.
DOC 4
Audit evidence pack
The controls in scope, their tests, the observations and the record entries showing when each took
place.