
Compliance · DORA
AI observability for DORA compliance
DORA has applied to EU financial entities since 17 January 2025. When an AI system supports an important function, its LLM provider is an ICT third-party service provider, and its failures can be reportable ICT incidents.
Last reviewed by the Perimattic AI Suite team
In short
How does DORA apply to AI systems?
DORA treats AI systems as part of a financial entity’s ICT estate. You must include them in your ICT risk framework, detect and classify their incidents, report major ones to your competent authority on fixed deadlines, and manage the external providers they depend on, including LLM APIs, as ICT third-party risk. Observability gives you the dependency map, incident timeline and service metrics those duties require.
Your LLM provider is in scope
If a model API supports a critical or important function, the contract, the exit strategy and the provider’s performance all fall under DORA’s third-party rules (Articles 28 to 30).
Quality failures can be incidents
An outage is obvious. A model that starts returning wrong answers to customers can also disrupt a service. Detecting it quickly is what makes a 4-hour reporting clock workable.

Regulation overview
What DORA requires
DORA sets one rulebook for ICT risk in EU finance. It has five pillars: ICT risk management, ICT incident management and reporting, digital operational resilience testing, ICT third-party risk, and information sharing. AI systems sit inside all of them as soon as they support a business function.
- Authority
- National competent authorities (for example the ECB, BaFin or the Central Bank of Ireland); the European Supervisory Authorities oversee critical ICT third-party providers
- Legal basis
- Regulation (EU) 2022/2554 on digital operational resilience for the financial sector, with its technical standards
- Penalties
- Set by each member state for financial entities. Critical ICT third-party providers can face periodic penalty payments of up to 1% of average daily worldwide turnover from the lead overseer.
Key dates
16 Jan 2023Applies now
DORA enters into force.
17 Jan 2025Applies now
DORA applies to financial entities, including its incident reporting and third-party rules.
Capabilities
What observability gives a DORA programme
Third-party dependency map
Which model providers and versions serve which business function, built from the spans themselves rather than a spreadsheet.
Signal it produces: Provider inventory for the register of information
Incident detection and timeline
Outages, latency spikes, error bursts and quality drops detected on live traffic, with the affected requests attached.
Signal it produces: Detection time, impact window, affected services
Classification inputs
Numbers of affected requests and customers, duration and services hit: the facts DORA’s classification criteria ask for.
Signal it produces: Data to decide whether an incident is major
Provider performance over time
Availability, latency and error rates per provider, measured from your side rather than taken from the vendor’s status page.
Signal it produces: Evidence for contract reviews and exit planning
Requirement to evidence
Which records each DORA duty expects
Article references are to Regulation (EU) 2022/2554. The right-hand column is the record you can produce for an internal audit or a supervisor.
| DORA requirement | Telemetry that supports it | Evidence you can produce |
|---|---|---|
| Art. 8 Identification of ICT assets and dependencies | Model, provider and version recorded on every span | Current list of AI components and the functions they support |
| Art. 10 Detection of anomalous activity | Alerts on error, latency, cost and quality thresholds | Alert history showing detection mechanisms in operation |
| Art. 17 ICT-related incident management | Incident record linked to the affected traces | Timeline from detection to resolution, with root cause |
| Arts. 18 and 19 Classification and reporting of major incidents | Counts of affected requests and users, duration, services hit | Facts for the initial, intermediate and final reports |
| Arts. 24 and 25 Resilience testing | Traces from failover and fallback-model tests | Test results showing the AI service degrades safely |
| Arts. 28 to 30 ICT third-party risk | Per-provider availability, latency and error metrics | Performance data for contract monitoring and exit strategies |
Sample evidence
What a DORA incident record looks like
A record your incident manager can build the regulatory reports from, without reconstructing the timeline from raw logs.
Perimattic AI Suite supports your DORA programme. It is not legal advice, and incident classification and reporting decisions stay with your organisation.
{
"record_type": "dora.ict_incident",
"function": "retail-customer-support",
"provider": "<llm-provider>",
"detected_at": "2026-09-14T09:12:04Z",
"signal": "error_rate > 20% for 9 min",
"affected_requests": 4182,
"classification_inputs": { "clients_affected": "<n>", "duration_min": 47 }
}Regulation details last verified on 1 October 2026.
FAQ
Common questions
Short answers to common questions. They are general information, not legal advice.
Which firms does DORA apply to?
EU financial entities including credit institutions, investment firms, payment and e-money institutions, insurers and reinsurers, crypto-asset service providers, central securities depositories, trading venues and others. It has applied since 17 January 2025.
Is an LLM API an ICT third-party service under DORA?
Yes, when a financial entity uses it to deliver a service. If it supports a critical or important function, the stricter rules apply: contract terms under Article 30, an exit strategy, and the provider recorded in your register of information.
Can an AI quality failure count as an ICT-related incident?
It can. DORA defines incidents by their effect on the availability, integrity or confidentiality of services and data. A model that returns systematically wrong answers in a customer-facing service can affect integrity and service delivery. Whether it is major depends on DORA’s classification criteria, such as clients affected, duration and data loss.
How fast must a major ICT incident be reported?
Under the technical standards, the initial notification is due within 4 hours of classifying the incident as major and no later than 24 hours after becoming aware of it. An intermediate report follows within 72 hours, and a final report within one month.
How do DORA and the EU AI Act overlap?
A bank using AI for credit scoring can fall under both. The EU AI Act adds logging, human oversight and post-market monitoring for the AI system; DORA adds ICT risk, incident reporting and third-party management. One set of telemetry can support both. The compliance hub covers how the frameworks fit together.
Go further
Related tools, guides and services
- IndustryAI for financial servicesHow Perimattic builds AI for banks, insurers and fintech, within their regulatory limits.Open
- IndustryAI for bankingUse cases and delivery approach for retail and commercial banks.Open
- White papersAI in finance white papersResearch on AI adoption, risk and governance in financial services.Open
- Free toolAI compliance readiness assessmentScore your readiness across AI regulations, now including DORA and SOC 2 sections.Open

See what your AI systems are doing, with evidence to back it up
Perimattic AI Suite is in early access. Tell us what you are building and a Perimattic engineer will follow up to scope your first instrumented system.
Prefer email? sales@perimattic.com