← Mandate Registry · 7 mandate layers · dora
financial · DORA Article 17 · DORA Article 19 · DORA Article 28
DORA / Financial Operational Resilience
ICT third-party AI provider = critical function — register + audit or supervisory fine
—DORA in force — ICT risk management
Regulatory exposure — commonly overlooked:
Bank uses cloud AI — bank owns DORA compliance, cloud vendor owns shared responsibility matrix gap.
Art 28 register
Critical ICT providers must be registered — AI vendors increasingly on list.
Incident reporting
4-hour initial notification — AI-caused incident needs decision receipt.
TLPT
Threat-led penetration testing includes AI attack paths.
7 mandate layers (live)
Regulatory Clock
Countdown to operative regulatory deadline — NAIC adoption, GSE mandate, EU transposition.
Open →
Domain Classifier
Industry-specific SAFE/CRISIS/VIOLATION with regulatory framework mapping.
Open →
Exhibit / Filing Pack
Regulator-ready external validation — NAIC Exhibit D, Fannie QC, EU FRIA, FDA Part 11.
Open →
Mandate Registry
Enroll deployers/insureds under vertical-specific governance mandate.
Open →
Bind / Action Gate
ALLOW/BLOCK before consequential action — bind policy, sell loan, deactivate worker.
Open →
Compliance Certificate
Deployer-facing downloadable cert — forward to counsel, auditor, regulator.
Open →
Actuarial / Risk Feed
Anonymized asymmetry signals for pricing, reserving, reinsurance correlation.
Open →