The ICT risk management framework shall be documented and reviewed at least once a year, or periodically in the case of microenterprises, as well as upon the occurrence of major ICT-related incidents, and following supervisory instructions or conclusions derived from relevant digital operational resilience testing or audit processes.
Comprehensive document describing the institution's ICT risk management framework, governance structure, risk appetite, and risk management methodology as required by DORA Article 6.
ict-risk-frameworkStructured JSON record documenting each periodic review of the ICT risk management framework, including review date, findings, changes made, and next review date.
framework-review-recordfs-ict-risk-framework-statusDORA-Art6-P1approval_datenext_review_date{
"properties": {
"approval_date": {
"format": "date",
"type": "string"
},
"framework_version": {
"pattern": "^\\d+\\.\\d+$",
"type": "string"
},
"has_governance_structure": {
"type": "boolean"
},
"has_risk_appetite": {
"type": "boolean"
},
"next_review_date": {
"format": "date",
"type": "string"
},
"risk_appetite_thresholds": {
"items": {
"properties": {
"category": {
"type": "string"
},
"threshold": {
"type": "number"
},
"unit": {
"type": "string"
}
},
"type": "object"
},
"type": "array"
}
},
"required": [
"framework_version",
"approval_date",
"next_review_date",
"has_governance_structure",
"has_risk_appetite"
],
"type": "object"
}
fs-framework-review-recordDORA-Art6-P8review_datenext_review_date{
"properties": {
"approved_by": {
"type": "string"
},
"change_summary": {
"type": "string"
},
"changes_made": {
"type": "boolean"
},
"findings_count": {
"minimum": 0,
"type": "integer"
},
"next_review_date": {
"format": "date",
"type": "string"
},
"review_date": {
"format": "date",
"type": "string"
},
"review_trigger": {
"enum": [
"periodic",
"major_incident",
"supervisory_instruction",
"audit_finding",
"resilience_test"
],
"type": "string"
},
"reviewer": {
"minLength": 1,
"type": "string"
}
},
"required": [
"review_date",
"reviewer",
"review_trigger",
"changes_made",
"next_review_date"
],
"type": "object"
}