Context · FinTech · DACH
DORA-ready control plane on AWS
Mapped ICT risk to cloud controls, stood up an information register workflow, and closed critical identity gaps before the next supervisory review.
- to audit-ready baseline
- 6 wks
- critical findings closed
- 18
to audit-ready baseline
critical findings closed
Challenge
A payment-adjacent FinTech had grown AWS accounts faster than its control catalogue. DORA expectations were clear, but ICT risk, third-party registers and identity baselines lived in different spreadsheets - and eighteen critical findings were still open two months before a supervisory touchpoint.
Approach
Started with a fixed-scope Quick Assessment: account inventory, IAM posture, logging coverage and a DORA-aligned gap list the CTO could take to the board without translation.
Prioritised identity and evidence first - SSO baselines, break-glass, CloudTrail and config exports wired into an information-register workflow the compliance lead could maintain.
Delivered remediation in two-week slices with written acceptance criteria, so security and engineering shared the same definition of closed before audit prep.
Outcome
Within six weeks the team had an audit-ready baseline, the information register was live, and all eighteen critical findings were closed with evidence attached - no slide theatre, no open-ended retainer.
FAQ
Was this a full DORA certification?
No. We mapped ICT and cloud controls, built evidence workflows and closed technical gaps. Legal interpretation and BaFin supervision stay with your counsel and regulators.
Why anonymise the client?
The engagement is real; the sector label is enough for peers to judge fit. Names stay off until the client approves a public reference.