AWS DORA audit
AWS audit and DORA: evidence for your ICT risk management
Banks, insurers, payment institutions, asset managers: DORA requires you to control ICT risk, cloud included. The audit assesses the configuration of your AWS accounts and produces dated evidence for your ICT risk management framework. It does not issue a DORA certification.
DORA in brief
- Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) has applied since 17 January 2025.
- It covers most financial entities in the Union: credit institutions, payment and e-money institutions, investment firms, insurance and reinsurance undertakings, management companies, among others (Article 2).
- It rests on five pillars: ICT risk management, incident management and reporting, digital operational resilience testing, ICT third-party risk, information sharing.
- Delegated Regulation (EU) 2024/1774 details the tools, methods and policies expected from the ICT risk management framework. In France, supervision lies with the ACPR and the AMF.
What DORA means for your AWS accounts
On AWS, the security of the infrastructure is AWS's job; the configuration of your accounts is yours. DORA asks you to demonstrate that your systems are protected, monitored, backed up and tested. For your AWS accounts, that means:
- knowing which resources run, and in which regions;
- proving that access, encryption and network segmentation are under control;
- showing that anomalous activity is logged and detected;
- documenting backups and recovery capability;
- testing regularly, and tracking the remediation of the gaps found.
Mapping DORA to the audit
The table maps DORA articles to the audit's analyses. It shows where the audit provides evidence; assessing compliance remains the job of your compliance function.
| DORA requirement | What the audit looks at | Domains |
|---|---|---|
| Art. 6 - ICT risk management framework, reviewed and audited | A dated, independent assessment of the AWS configuration, with findings, severity and an action plan. | All ten domains |
| Art. 8 - Identification of ICT assets | Inventory of resources per region and tagging quality. | Inventory |
| Art. 9 - Protection and prevention | Access control (IAM, MFA, least privilege), encryption (KMS, S3, EBS, RDS), secrets, network segmentation, FSBP and CIS v3.0 compliance. | Security, IAM, Networking, Secrets and encryption |
| Art. 10 - Detection of anomalous activities | CloudTrail, GuardDuty, Security Hub, CIS 4.1 to 4.15 alarms, VPC flow logs. | Security, Networking |
| Art. 11 and 12 - Response, recovery, backup | AWS Backup plans, snapshots, replication, Multi-AZ deployments, multi-region recovery, RTO and RPO estimates. | Resilience, Well-Architected |
| Art. 24 and 25 - Digital operational resilience testing | Configuration vulnerability assessment and network security assessment; optional DAST scan of public endpoints. | Security, Networking, Web security |
| Art. 28 - ICT third-party risk | Out of scope: the audit reviews neither contracts nor the register of information. It documents your side of the AWS shared responsibility model. | - |
Deliverables you can use as evidence
- Ten dated reports, one per domain, naming every affected resource (ARN, ID): the record of the assessment.
- A P0, P1, P2 Excel action plan: the basis of your remediation tracking, to reconcile with your findings register.
- An executive summary and a 19-slide deck: DORA makes the management body ultimately responsible for ICT risk (Article 5).
- Cross-domain attack scenarios, to illustrate the risks and justify the priorities.
Run again after the fixes, the audit measures progress on the same controls.
Your data stays in France
- Collection, analysis, storage and report delivery take place in the AWS
eu-west-3region (Paris). - The AI (Anthropic Claude models) is invoked through Amazon Bedrock with European inference profiles; your data is not used to train the models.
- Access goes through a read-only IAM role, protected by a unique External ID and revocable at any time.
- Collected data and reports are deleted automatically after 7 days. The only subprocessor is Amazon Web Services.
- For this service, Silamir Group is an ICT third-party service provider: record it in your register of information if your analysis requires it.
What the audit does not cover
- Threat-led penetration testing (TLPT, Article 26), reserved for testers meeting specific requirements.
- Incident management and reporting (Articles 17 to 23), contract reviews and provider exit strategies.
- Systems outside AWS, and AWS accounts not audited: an audit covers one account, at a given date.
- The opinion of your compliance function or your auditors, which the audit informs but does not replace.
AWS audit and DORA: frequently asked questions
Does the audit make my organisation DORA compliant?
No. DORA covers your whole ICT risk management: governance, incidents, testing, third parties. The audit assesses the configuration of your AWS accounts and provides evidence for part of these requirements, notably Articles 8 to 12.
Can it be part of our annual testing programme?
It can feed into it. Article 25 lists vulnerability assessments and scans and network security assessments among the possible tests; Article 24 requires systems supporting critical or important functions to be tested at least yearly. Fitting it into your risk-based programme remains your decision.
Where is our data processed?
In Paris, in the AWS eu-west-3 region, including the AI analysis through European Amazon Bedrock inference profiles. Artefacts are deleted after 7 days.
We have dozens of AWS accounts: how should we proceed?
An audit covers one account. Start with the accounts hosting critical or important functions, then extend: each audit is billed 299 USD, with no commitment.
What language are the reports in?
The reports, the summary and the deck are written in French.
Ready to audit your AWS account?
Subscribe on AWS Marketplace, deploy the read-only role and get your reports within the hour.