DORA
DORA has applied to EU financial entities since 17 January 2025. When you put AI into operational processes — credit scoring, fraud detection, KYC, customer service — the model providers behind it (OpenAI, Anthropic, Google) become ICT third-party service providers in scope. Nyx is the single control point that makes that AI surface auditable, and generates a DORA evidence pack on demand.
| Reference | Requirement | Nyx capability |
|---|---|---|
| Pillar 1 · Art. 5–6 | ICT risk management framework | Centralized register of AI ICT assets with continuous risk scoring and policy enforcement, feeding the management body's framework |
| Pillar 1 · Art. 9 | Protection & prevention | On-device PII redaction and k-anonymity before data leaves the endpoint; Ed25519-signed policy, TLS + AES-256 |
| Pillar 2 · Art. 17–19 | Incident management & reporting | Automated detection with severity classification and the initial / intermediate / final reporting cadence |
| Pillar 3 · Art. 24–26 | Resilience testing | Structured audit logs and captured scenarios as inputs to vulnerability assessments and TLPT of the AI attack surface |
| Pillar 4 · Art. 28–29 | Third-party ICT risk | Per-provider risk scoring, jurisdiction tracking and the technical dependency layer of the Art. 5(9) register |
| Pillar 5 · Art. 45 | Information sharing | MITRE ATT&CK-enriched threat data and aggregated incident reporting for voluntary intelligence sharing |
The report is an auditor-facing evidence pack — control, requirement, metrics and reasoning — not a binary compliance verdict. Auditors map Nyx severity onto the DORA RTS classification criteria and reconcile the dependency inventory against the contractual register.
The information on this page is for informational purposes and does not constitute legal advice. For an assessment specific to your organization, consult a qualified professional. Nyx reports are evidence packs — control, requirement, metrics and reasoning — not a compliance verdict.