ZIE MATPROOF OP JOUW STACK — BOEK EEN DEMO VAN 30 MINUTEN
All use cases
DORAAsset Management & Investment Firms

DORA compliance for asset managers - without the operational drag.

DORA applies to UCITS management companies, AIFMs, and investment firms - all five pillars. Matproof automates ICT risk management, builds your Article 28 third-party register, sets up incident reporting workflows, and cross-maps with MiFID II and AIFMD - so your compliance team focuses on risk, not regulatory paperwork.

Matproof for DORA

Your DORA programme, on one screen.

ICT risk, incident reporting, resilience testing and third-party registers — Articles 5–45, continuously evidenced.

  • Map controls once, reuse across every framework
  • Evidence collected and time-stamped automatically
  • Audit-ready packages generated on demand
app.matproof.com/doraLive

DORA coverage

updated just now
0%ICT risk
0%3rd-party
0%Incidents
ICT risk framework · approvedVERIFIED
Third-party register · 142 vendorsVERIFIED
TLPT resilience test · scheduledON TRACK
DORANIS2ISO 27001SOC 2
Export audit pack →

The Challenge

Why DORA matters for asset managers

Asset managers depend on ICT infrastructure for everything - trading, portfolio management, risk analytics, client reporting, and regulatory filings. DORA recognizes this dependency and mandates comprehensive ICT resilience. The regulation applies to your firm, your systems, and your entire vendor ecosystem.

DORA explicitly covers asset managers and funds

DORA scope includes UCITS management companies, alternative investment fund managers (AIFMs), and investment firms. All five DORA pillars apply - ICT risk management, incident reporting, resilience testing, third-party oversight, and information sharing. Many asset managers assumed DORA was primarily a banking regulation and now face a steep compliance curve.

Third-party ICT provider dependencies are deep

Asset managers rely heavily on outsourced ICT services - portfolio management systems, order management systems, market data feeds, fund administration platforms, and cloud infrastructure. The Article 28 register must document every ICT third-party provider, their criticality, sub-outsourcing chains, and exit strategies. For firms with 50+ vendor relationships, this is a major documentation exercise.

Incident reporting timelines are non-negotiable

DORA mandates that major ICT-related incidents are reported to the competent authority within strict timelines - initial notification within 4 hours of classification, intermediate report within 72 hours, and final report within one month. Asset managers must classify incidents using ESA criteria and report through the correct national channel.

MiFID II and AIFMD overlap creates complexity

Asset managers already comply with organizational requirements under MiFID II and risk management frameworks under AIFMD. DORA adds ICT-specific layers that overlap but differ in terminology, reporting formats, and governance expectations. Managing three frameworks without duplication requires systematic cross-mapping that manual processes cannot achieve efficiently.

Your Compliance Journey

From vendor inventory to DORA-ready in weeks

1

ICT Landscape Mapping

Connect your portfolio management systems, trading platforms, cloud infrastructure, and market data feeds. Matproof maps your ICT landscape and identifies all third-party dependencies against DORA requirements.

2

Gap Assessment & Register

Build your Article 28 third-party register. Matproof assesses each vendor for criticality, contract compliance, and concentration risk. Simultaneously identify gaps across all five DORA pillars.

3

Policy & Process Implementation

Generate DORA-compliant ICT policies, incident classification workflows, resilience testing plans, and information sharing arrangements. Cross-map with existing MiFID II and AIFMD controls to avoid duplication.

4

Continuous Monitoring

Automated evidence collection from your investment infrastructure. Real-time ICT risk scoring, vendor monitoring, incident detection, and compliance dashboard for management body oversight.

Key Requirements

DORA articles that matter most for asset managers

Art. 5-16

ICT Risk Management Framework

  • ICT risk management framework approved by management body (Art. 5)
  • Identification of ICT-supported business functions and assets (Art. 8)
  • ICT protection and prevention measures (Art. 9)
  • Detection of anomalous activities and ICT incidents (Art. 10)
  • Business continuity and disaster recovery plans (Art. 11-12)
  • Learning and evolving from incidents and tests (Art. 13)
Art. 17-23

Incident Classification & Reporting

  • Incident classification using ESA criteria (Art. 18)
  • Initial notification to competent authority within 4 hours (Art. 19)
  • Intermediate report within 72 hours of classification (Art. 19)
  • Final report within one month including root cause (Art. 19)
  • Voluntary notification of significant cyber threats (Art. 19)
  • Internal incident management and escalation procedures
Art. 28-44

Third-Party ICT Risk Management

  • Complete register of ICT third-party service providers (Art. 28(3))
  • Criticality assessment of each ICT provider relationship
  • Key contractual provisions including audit rights (Art. 30)
  • Concentration risk assessment across critical providers (Art. 29)
  • Sub-outsourcing chain monitoring and approval
  • Exit strategies for critical ICT service providers (Art. 28)

Why Matproof

Built for investment management compliance

Asset management-specific control mapping

Controls pre-mapped to DORA, MiFID II, and AIFMD. Matproof identifies where frameworks overlap - business continuity, ICT governance, risk management - and where DORA adds net-new requirements. Your compliance team maintains one unified control set.

Automated Article 28 register for investment infrastructure

Build the DORA-compliant third-party register covering portfolio management systems, OMS platforms, market data vendors, fund administrators, and cloud providers. AI-assisted criticality scoring and concentration risk analysis across your entire vendor ecosystem.

Incident reporting for financial authorities

Automated incident classification using ESA criteria, timeline tracking for the 4-hour/72-hour/1-month reporting deadlines, and report generation in the format your national competent authority expects. Never miss a deadline.

Management body compliance dashboard

DORA Article 5 requires the management body to approve and oversee the ICT risk management framework. Matproof provides real-time dashboards showing ICT risk posture, vendor status, incident history, and compliance gaps - the governance evidence your board needs.

Frequently asked questions

Does DORA apply to all asset managers, or only large ones?
DORA applies to UCITS management companies, alternative investment fund managers (AIFMs), and MiFID investment firms regardless of size. There is no de minimis threshold. However, Article 4 introduces a proportionality principle - smaller firms can implement simplified ICT risk management frameworks proportionate to their size, risk profile, and complexity. Matproof helps determine the appropriate level of proportionality for your firm.
How does DORA interact with existing MiFID II organizational requirements?
MiFID II already requires organizational arrangements including business continuity, IT systems, and record keeping. DORA adds specific ICT risk management requirements on top of these. Where MiFID II is general, DORA is prescriptive - specifying exactly how ICT risk must be managed, incidents reported, and third parties overseen. Matproof maps overlapping requirements so you do not duplicate controls or documentation.
What does the Article 28 register look like for a typical asset manager?
For a mid-size asset manager, the register typically includes 30-100 ICT third-party providers: portfolio management system vendor, OMS provider, market data feeds (Bloomberg, Refinitiv), fund administration platform, custodian IT systems, cloud providers (AWS, Azure), compliance monitoring tools, and communication systems. Each entry requires criticality assessment, contract analysis, sub-outsourcing documentation, and exit strategy planning.
How long does DORA implementation take for an asset manager?
Most asset managers achieve initial compliance in 4-8 weeks with Matproof. Week 1-2: ICT landscape mapping and vendor inventory. Week 2-4: Article 28 register build, policy generation, and incident workflow setup. Week 4-8: evidence collection automation, management body reporting, and resilience testing planning. The timeline depends on the number of ICT providers and complexity of your investment infrastructure.

Focus on returns. We handle DORA compliance.

Book a 30-minute demo and see how Matproof automates DORA compliance for asset managers - from the Article 28 register to incident reporting to management body dashboards.

Not ready for a demo?

Let's talk compliance

Leave your email and we will reach out personally to discuss your compliance needs.

We follow up personally within 24 hours. No automated spam.