Appearance
Operationalizing in Modulos
DORA execution works best when organization governance (OFF-16) and application execution (MFF-16) are coordinated as one delivery program.
Recommended project structure
Most teams use:
- one organization project for
OFF-16governance obligations - one or more AI-application projects for
MFF-16execution obligations
Where in Modulos
Project → Settings → Frameworks: addOFF-16andMFF-16to relevant projectsProject → Requirements: assign owners and track readiness per requirementProject → Controls: execute controls and preserve review decisionsProject → Evidence: store incident, testing, third-party, and governance artifacts
A sequence that works
- Determine entity scope and proportionality (
ORF-361,ORF-362). - Establish management-body accountability and the ICT risk-governance foundation (
ORF-363toORF-366,MRF-293). - Implement the resilience backbone across capacity, inventories, risk, protection, detection, response, backup, and learning (
ORF-367toORF-375;MRF-294toMRF-301). - Operationalize the incident and reporting family (
ORF-376toORF-381;MRF-302toMRF-304). - Run digital operational resilience testing and TLPT workflows where applicable (
ORF-382,ORF-383;MRF-305,MRF-306). - Operationalize ICT third-party, register, and subcontracting workflows (
ORF-384toORF-387;MRF-307toMRF-310). - If used, govern Article 45 information-sharing arrangements (
ORF-388).
How to handle conditional duties
The current DORA model relies on requirement-level applicability notes rather than a separate questionnaire or static tag family.
In practice:
- review the Applicability section on any conditional requirement
- record why the duty is in scope or out of scope for the relevant entity or application
- keep the supporting scoping evidence with the requirement and control evidence package
Evidence package baseline
A defensible DORA package usually includes:
- entity-category and proportionality decision records
- management body governance and training evidence
- ICT inventory, risk assessment, and control operation evidence
- major-incident staging and reporting evidence
- resilience testing and TLPT outcomes with remediation tracking
- ICT third-party due diligence, contract, and register evidence
- subcontracting assessments where relevant
- Article 45 participation records where relevant
Related pages
DORA overview
Framework structure and OFF-16/MFF-16 split
Testing and third-party risk
Resilience testing and ICT third-party execution model
Information sharing and Level 2 acts
Article 45 participation and the threaded Level 2 act model
Disclaimer
This page is for general informational purposes and does not constitute legal advice.