Perimattic

Compliance · DORA

AI observability for DORA compliance

DORA has applied to EU financial entities since 17 January 2025. When an AI system supports an important function, its LLM provider is an ICT third-party service provider, and its failures can be reportable ICT incidents.

Last reviewed by the Perimattic AI Suite team

In short

How does DORA apply to AI systems?

DORA treats AI systems as part of a financial entity’s ICT estate. You must include them in your ICT risk framework, detect and classify their incidents, report major ones to your competent authority on fixed deadlines, and manage the external providers they depend on, including LLM APIs, as ICT third-party risk. Observability gives you the dependency map, incident timeline and service metrics those duties require.

  • Your LLM provider is in scope

    If a model API supports a critical or important function, the contract, the exit strategy and the provider’s performance all fall under DORA’s third-party rules (Articles 28 to 30).

  • Quality failures can be incidents

    An outage is obvious. A model that starts returning wrong answers to customers can also disrupt a service. Detecting it quickly is what makes a 4-hour reporting clock workable.

Person holding a payment card while typing on a laptop

Regulation overview

What DORA requires

DORA sets one rulebook for ICT risk in EU finance. It has five pillars: ICT risk management, ICT incident management and reporting, digital operational resilience testing, ICT third-party risk, and information sharing. AI systems sit inside all of them as soon as they support a business function.

Authority
National competent authorities (for example the ECB, BaFin or the Central Bank of Ireland); the European Supervisory Authorities oversee critical ICT third-party providers
Legal basis
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector, with its technical standards
Penalties
Set by each member state for financial entities. Critical ICT third-party providers can face periodic penalty payments of up to 1% of average daily worldwide turnover from the lead overseer.

Key dates

  1. 16 Jan 2023Applies now

    DORA enters into force.

  2. 17 Jan 2025Applies now

    DORA applies to financial entities, including its incident reporting and third-party rules.

Capabilities

What observability gives a DORA programme

  • Third-party dependency map

    Which model providers and versions serve which business function, built from the spans themselves rather than a spreadsheet.

    Signal it produces: Provider inventory for the register of information

  • Incident detection and timeline

    Outages, latency spikes, error bursts and quality drops detected on live traffic, with the affected requests attached.

    Signal it produces: Detection time, impact window, affected services

  • Classification inputs

    Numbers of affected requests and customers, duration and services hit: the facts DORA’s classification criteria ask for.

    Signal it produces: Data to decide whether an incident is major

  • Provider performance over time

    Availability, latency and error rates per provider, measured from your side rather than taken from the vendor’s status page.

    Signal it produces: Evidence for contract reviews and exit planning

Requirement to evidence

Which records each DORA duty expects

Article references are to Regulation (EU) 2022/2554. The right-hand column is the record you can produce for an internal audit or a supervisor.

Which records each DORA duty expects
DORA requirementTelemetry that supports itEvidence you can produce
Art. 8 Identification of ICT assets and dependenciesModel, provider and version recorded on every spanCurrent list of AI components and the functions they support
Art. 10 Detection of anomalous activityAlerts on error, latency, cost and quality thresholdsAlert history showing detection mechanisms in operation
Art. 17 ICT-related incident managementIncident record linked to the affected tracesTimeline from detection to resolution, with root cause
Arts. 18 and 19 Classification and reporting of major incidentsCounts of affected requests and users, duration, services hitFacts for the initial, intermediate and final reports
Arts. 24 and 25 Resilience testingTraces from failover and fallback-model testsTest results showing the AI service degrades safely
Arts. 28 to 30 ICT third-party riskPer-provider availability, latency and error metricsPerformance data for contract monitoring and exit strategies

Sample evidence

What a DORA incident record looks like

A record your incident manager can build the regulatory reports from, without reconstructing the timeline from raw logs.

Perimattic AI Suite supports your DORA programme. It is not legal advice, and incident classification and reporting decisions stay with your organisation.

{
  "record_type": "dora.ict_incident",
  "function": "retail-customer-support",
  "provider": "<llm-provider>",
  "detected_at": "2026-09-14T09:12:04Z",
  "signal": "error_rate > 20% for 9 min",
  "affected_requests": 4182,
  "classification_inputs": { "clients_affected": "<n>", "duration_min": 47 }
}
Illustrative record with sample values, not customer data.

Regulation details last verified on 1 October 2026.

FAQ

Common questions

Short answers to common questions. They are general information, not legal advice.

Which firms does DORA apply to?

EU financial entities including credit institutions, investment firms, payment and e-money institutions, insurers and reinsurers, crypto-asset service providers, central securities depositories, trading venues and others. It has applied since 17 January 2025.

Is an LLM API an ICT third-party service under DORA?

Yes, when a financial entity uses it to deliver a service. If it supports a critical or important function, the stricter rules apply: contract terms under Article 30, an exit strategy, and the provider recorded in your register of information.

Can an AI quality failure count as an ICT-related incident?

It can. DORA defines incidents by their effect on the availability, integrity or confidentiality of services and data. A model that returns systematically wrong answers in a customer-facing service can affect integrity and service delivery. Whether it is major depends on DORA’s classification criteria, such as clients affected, duration and data loss.

How fast must a major ICT incident be reported?

Under the technical standards, the initial notification is due within 4 hours of classifying the incident as major and no later than 24 hours after becoming aware of it. An intermediate report follows within 72 hours, and a final report within one month.

How do DORA and the EU AI Act overlap?

A bank using AI for credit scoring can fall under both. The EU AI Act adds logging, human oversight and post-market monitoring for the AI system; DORA adds ICT risk, incident reporting and third-party management. One set of telemetry can support both. The compliance hub covers how the frameworks fit together.