ISS-003Compliance gapHighOpen
ICT risk-management framework not integrated with enterprise risk
1 of 1 action plans are still open. An issue can only be closed once all its action plans close.
Description
Mapping review found DORA Art. 6(1) unmapped — there is no documented ICT risk-management framework that sits inside the overall enterprise risk-management system. This is a regulatory compliance gap that must be closed before the DORA readiness audit.
Action-plan SLA
Plans required by
16 Apr 2026
Action plans
1AP-003Document ICT risk framework integration into ERM
Overdue30%
MA Marcus AllenTarget 15 Jul 2026
What this issue addresses
Requirements
DORA Art. 6(1)