Skip to content
Shoirly

DORA, explained for AI agent vendors

The EU's Digital Operational Resilience Act changes what banks must know about their technology suppliers. Here's what it asks, what it means when you sell an AI agent to a bank, and what evidence helps.

Plain-English guide. Not legal advice.

What DORA is

DORA, formally Regulation (EU) 2022/2554, sets one set of rules for how financial firms in the EU manage technology risk. It has applied since 17 January 2025.

It covers about twenty kinds of financial entity, including banks, insurers, payment and e-money institutions, investment firms and crypto-asset service providers. If you sell to them, their DORA obligations become your sales process.

The five areas DORA covers

  1. Chapter II

    ICT risk management

    Banks need a framework to identify, protect against, detect and recover from technology risk, and to keep it under review.

  2. Chapter III

    Incident management and reporting

    They must log and classify ICT-related incidents, and report major ones to their supervisor within set timeframes.

  3. Chapter IV

    Resilience testing

    They must test their systems regularly. Some larger firms must also run threat-led penetration tests.

  4. Chapter V

    ICT third-party risk

    They stay responsible for risk that comes from their technology suppliers, which includes you. This is the pillar vendors feel most.

  5. Chapter VI

    Information sharing

    Firms may share cyber threat information with each other in trusted arrangements.

What banks will ask of you as an AI agent vendor

A place in their register

Banks must keep a register of information on every contract with an ICT third-party provider (Art. 28). Expect detailed questions about what you do, where, and for which of their functions.

Contract terms you'll recognise

DORA lists what these contracts must include (Art. 30): service descriptions, data locations, incident support, cooperation with supervisors and termination rights. Where you support a critical or important function, add audit, access and inspection rights, plus exit plans.

Ongoing monitoring, not a one-off check

Third-party risk is managed across the life of the contract. A bank needs to keep showing its supervisor that your service is under control.

Proof that controls held

With AI agents acting for customers, risk teams want to know what the agent actually did and who allowed it. Policies and certificates describe intent. Records show outcomes.

How Shoirly evidence maps to DORA

Shoirly supports the bank's obligations. It doesn't discharge them. The mapping below is indicative.

DORA areas, what banks need, and the Shoirly evidence that supports it
DORA areaWhat the bank needsShoirly evidence
ICT third-party riskArt. 28-30Monitor the provider's performance and keep access, inspection and audit rights in practice.Per-customer records of what the provider's agent did for the bank, delivered on a schedule.
ICT risk managementArt. 5-16Know what systems do, control access and changes, and keep reliable logs.Each action tied to who or what authorised it, in signed, chained records.
Incident managementArt. 17-23Reconstruct what happened during an incident and report it accurately.A signed timeline of agent actions, with a coverage check showing nothing is missing.

Want to see it as a bank would? What a risk team receives.

Common questions

When did DORA start to apply?

DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025.

Does DORA apply directly to my startup?

Mostly through your customers. DORA places obligations on financial entities, and they pass requirements to you through due diligence and contracts. A small number of providers designated as critical are overseen directly by EU supervisors, which is unlikely to include an early-stage startup.

Is an AI agent an ICT service under DORA?

DORA defines ICT services broadly, covering digital and data services provided through ICT systems on an ongoing basis. An AI agent that acts in a bank's processes will usually be treated as one. Ask your customer how they classify you, especially whether you support a critical or important function.

Does using Shoirly make us or our customers DORA compliant?

No single tool does that. DORA compliance belongs to the bank and covers far more than one supplier. Shoirly gives the bank evidence about your agent that supports its third-party oversight, risk management and incident work.

What about UK banks?

DORA is EU law. UK firms follow the UK's own operational resilience and outsourcing rules, which ask similar questions about suppliers. The same evidence helps; the mapping is different.

Make DORA questions easier to answer.

We'll show you how per-customer evidence fits into a bank's third-party review.

Book a demo