DORA-Art5-P1

Article
5 (1)
Pillar
ICT Risk Management
Regulation Ref
Regulation (EU) 2022/2554, Article 5(1)
Last Reviewed
2026-01-15

Financial entities shall have in place an internal governance and control framework that ensures an effective and prudent management of all ICT risks, in order to achieve a high level of digital operational resilience.

Evidence Profiles

ICT Governance and Control Framework Document COMMON

Board-approved document defining the internal governance and control framework for ICT risk management, including roles, responsibilities, reporting lines, and oversight mechanisms.

Formats
PDF
Evidence Class
ict-governance-framework
Availability
COMMON
Update Frequency
annual
Typical Author
CIO
Approval Chain
CIO → CRO → Board of Directors

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
ICT GOVERNANCE AND CONTROL FRAMEWORK
Nordvik Bank AG
Version 2.1 | Approved: 10 January 2025 | Next Review: 10 January 2026
Approving Body: Board of Directors
Classification: Internal — Restricted

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

EXECUTIVE SUMMARY

This document establishes the internal governance and control framework for ICT
risk management at Nordvik Bank AG ("the Bank"), as required by Article 5 of the
Digital Operational Resilience Act (Regulation (EU) 2022/2554, "DORA"). The
framework defines the organisational structure, roles, responsibilities, reporting
lines, and oversight mechanisms that ensure effective and prudent management of all
ICT risks across the Bank.

The governance framework is designed to achieve a high level of digital operational
resilience by embedding ICT risk management into the Bank's overall corporate
governance structure. It ensures that the management body is actively involved in
steering and adapting the ICT risk management framework, and that adequate resources
are allocated to ICT risk management activities.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

GOVERNANCE STRUCTURE

1.1 Organisational Overview

The Bank's ICT governance structure is organised around three principal layers:

  Strategic Layer:    Board of Directors and Board Risk Committee — responsible
                      for setting ICT risk appetite, approving the ICT risk
                      management framework, and overseeing its implementation.

  Tactical Layer:     Executive Management (CIO, CISO, CRO) and the ICT Risk
                      Committee — responsible for translating strategic direction
                      into operational policies, allocating resources, and
                      monitoring risk indicators.

  Operational Layer:  ICT Operations, Security Operations Centre, Business Units
                      — responsible for day-to-day implementation of controls,
                      incident management, and risk reporting.

1.2 Governance Model

The Bank operates a federated governance model where ICT risk management
responsibilities are distributed across business lines and technology functions,
with centralised oversight provided by the Risk Management function. This model
ensures that ICT risk decisions are made close to the operational context while
maintaining consistent standards and reporting across the organisation.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

BOARD OVERSIGHT RESPONSIBILITIES

2.1 Board of Directors

The Board of Directors shall:
  (a) Define and approve the Bank's ICT risk appetite and tolerance levels;
  (b) Approve the ICT risk management framework and any material amendments;
  (c) Ensure adequate budget and human resources are allocated to ICT risk
      management, including ICT security and digital operational resilience;
  (d) Receive and review quarterly ICT risk reports from the Board Risk Committee;
  (e) Approve the Bank's digital operational resilience strategy;
  (f) Ensure that members of the management body maintain sufficient knowledge
      and skills to understand and assess ICT risk, including through regular
      training on ICT-related topics (minimum annually).

Oversight frequency: Quarterly review of ICT risk posture at Board meetings.

2.2 Board Risk Committee

The Board Risk Committee ("BRC") shall:
  (a) Oversee the implementation of the ICT risk management framework;
  (b) Review the ICT risk dashboard and key risk indicators quarterly;
  (c) Review and challenge material ICT risk assessments and treatment plans;
  (d) Monitor the status of ICT risk remediation actions;
  (e) Recommend changes to the ICT risk appetite to the Board;
  (f) Review the results of digital operational resilience testing.

The BRC meets quarterly, with extraordinary sessions convened following material
ICT incidents or significant changes to the Bank's ICT risk profile.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

THREE LINES OF DEFENCE MODEL

The Bank applies the Three Lines of Defence model to ICT risk management in
accordance with DORA Article 5(2) and EBA Guidelines:

  FIRST LINE OF DEFENCE — Risk Ownership

    ICT Operations and Development:
      — Own and manage ICT risks within their operational domains
      — Implement and maintain ICT security controls
      — Maintain ICT asset inventories and configuration management
      — Report ICT incidents and near-misses
      — Conduct first-level risk assessments for change management

    Business Units:
      — Own business process-level ICT risks
      — Define business requirements for ICT resilience (RTO/RPO)
      — Participate in business continuity testing
      — Report ICT-related operational disruptions

  SECOND LINE OF DEFENCE — Risk Oversight

    Risk Management Function (CRO):
      — Maintain the ICT risk management framework and risk appetite
      — Provide independent challenge to first-line risk assessments
      — Maintain the enterprise ICT risk register
      — Report ICT risk posture to the Board Risk Committee
      — Coordinate ICT risk-related regulatory engagement

    Compliance Function:
      — Monitor adherence to DORA and related regulatory requirements
      — Advise on regulatory expectations for ICT risk management
      — Conduct compliance assessments of ICT policies and procedures

    Information Security Function (CISO):
      — Define ICT security policies and standards
      — Manage threat intelligence and vulnerability management
      — Oversee security incident response
      — Conduct security awareness training

  THIRD LINE OF DEFENCE — Independent Assurance

    Internal Audit:
      — Provide independent assurance on the effectiveness of ICT risk
        management and control frameworks
      — Conduct risk-based ICT audits per the annual audit plan
      — Report findings directly to the Audit Committee
      — Follow up on remediation of audit findings

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

ICT RISK COMMITTEE TERMS OF REFERENCE

5.1 Purpose

The ICT Risk Committee ("ICTRC") is an executive-level committee established to
provide focused oversight of ICT risk management activities across the Bank.

5.2 Composition

  Chair:     Chief Risk Officer (CRO)
  Members:   Chief Information Officer (CIO)
             Chief Information Security Officer (CISO)
             Head of Business Continuity
             Head of Vendor Management
             Head of IT Operations
             Representatives from material business lines (Retail Banking,
             Corporate Banking, Treasury, Payment Services)

5.3 Meeting Frequency

The ICTRC meets monthly, with extraordinary sessions as required following
material ICT incidents or emerging threats.

5.4 Responsibilities

  (a) Review and update the ICT risk register
  (b) Approve ICT risk treatment decisions within delegated authority
  (c) Monitor key risk indicators and escalate breaches
  (d) Review ICT incident trends and lessons learned
  (e) Oversee third-party ICT risk management activities
  (f) Recommend policy changes to the Board Risk Committee
  (g) Review digital operational resilience testing plans and results

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

REPORTING LINES AND ESCALATION

6.1 Reporting Structure

  Board of Directors
    └── Board Risk Committee (quarterly ICT risk reports)
          └── ICT Risk Committee (monthly risk register updates)
                ├── CIO — ICT operations and infrastructure reporting
                ├── CISO — Security posture and incident reporting
                ├── CRO — Risk assessment and appetite monitoring
                └── Business Lines — Operational disruption reporting

6.2 Escalation Thresholds

  Level 1 (Operational):  ICT incidents affecting non-critical systems
                          → Escalate to ICT Operations Manager within 1 hour

  Level 2 (Tactical):     ICT incidents affecting important functions or
                          risk appetite threshold breaches
                          → Escalate to CISO/CIO within 2 hours

  Level 3 (Strategic):    ICT incidents affecting critical functions or
                          material risk appetite breaches
                          → Escalate to CRO and ICTRC within 4 hours
                          → Notify Board Risk Committee Chair within 24 hours

  Level 4 (Crisis):       Major ICT incidents with potential systemic impact
                          → Activate Crisis Management Team immediately
                          → Notify Board Chair and competent authority per
                            DORA Article 19 timelines

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

REVIEW AND APPROVAL HISTORY

This framework is reviewed annually and following material changes to the Bank's
ICT risk profile, organisational structure, or regulatory requirements.

Document History:
  v2.1  10 Jan 2025  Updated for DORA compliance; enhanced Three Lines of Defence
  v2.0  15 Jan 2024  Major revision; established ICT Risk Committee
  v1.5  12 Jan 2023  Annual review; updated escalation thresholds
  v1.0  20 Mar 2022  Initial version

Approved by: Board of Directors
Signature:   [Board Chair]
Date:        10 January 2025

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

ict_governance_framework_status — fs-ict-governance-framework
{
  "factId": "c1d2e3f4-a5b6-7890-cdef-100000000001",
  "evidenceId": "a0b1c2d3-e4f5-6789-abcd-100000000001",
  "evidenceClassId": "ict-governance-framework",
  "factType": "ict_governance_framework_status",
  "data": {
    "governance_model": "Federated governance with centralised oversight by Risk Management function",
    "approval_date": "2025-01-10",
    "next_review_date": "2026-01-10",
    "has_three_lines_of_defence": true,
    "board_oversight_frequency": "quarterly",
    "ict_risk_committee_exists": true,
    "reporting_lines_documented": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-01-15T09:00:00Z",
  "supersededBy": null
}

Fact Schemas

ict_governance_framework_status

Schema ID
fs-ict-governance-framework
Control
DORA-Art5-P1

Valid Ranges

approval_date
within last 18 months
next_review_date
future date within 12 months of approval
board_oversight_frequency
at least quarterly for significant institutions

Related Schemas

JSON Schema

{
  "properties": {
    "approval_date": {
      "format": "date",
      "type": "string"
    },
    "board_oversight_frequency": {
      "enum": [
        "monthly",
        "quarterly",
        "semi-annual",
        "annual"
      ],
      "type": "string"
    },
    "governance_model": {
      "minLength": 1,
      "type": "string"
    },
    "has_three_lines_of_defence": {
      "type": "boolean"
    },
    "ict_risk_committee_exists": {
      "type": "boolean"
    },
    "next_review_date": {
      "format": "date",
      "type": "string"
    },
    "reporting_lines_documented": {
      "type": "boolean"
    }
  },
  "required": [
    "governance_model",
    "approval_date",
    "next_review_date",
    "has_three_lines_of_defence",
    "board_oversight_frequency"
  ],
  "type": "object"
}