{"id":11389,"date":"2026-07-01T13:36:20","date_gmt":"2026-07-01T11:36:20","guid":{"rendered":"https:\/\/www.ozonaconsulting.com\/dora-audit-2\/"},"modified":"2026-07-01T13:36:20","modified_gmt":"2026-07-01T11:36:20","slug":"dora-audit","status":"publish","type":"page","link":"https:\/\/www.ozonaconsulting.com\/en\/dora-audit\/","title":{"rendered":"DORA \u00b7 Internal Audit"},"content":{"rendered":"<div class=\"wpb-content-wrapper\"><p>[vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; background_color=&#8221;#e8e8e8&#8243; padding_top=&#8221;70&#8243; padding_bottom=&#8221;50&#8243; css=&#8221;.vc_custom_1443952192133{background-color: #ffffff !important;}&#8221;][vc_column][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;grid&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text]<\/p>\n<h2>DORA Training \u00b7 Internal Audit<\/h2>\n<p>&nbsp;<\/p>\n<p>The Regulation (EU) 2022\/2554 (DORA) establishes a European regulatory framework that strengthens the digital operational resilience of financial sector entities, addressing ICT risk management, incident management, operational resilience testing, third-party management and information sharing.<\/p>\n<p>This training has been specifically designed for internal audit teams of financial entities, covering the planning, execution and reporting of audits on the five pillars of DORA. The contents are based on the experience of Ozona Consulting&#8217;s team of consultants in real implementation and audit projects on ISO 22301, ISO 27001 and ISO 20000, on the articles of the DORA regulation and on its Regulatory Technical Standards (RTS).<\/p>\n<p>The course is useful for internal audit teams and for any profile involved in the adoption, management and governance of DORA within the entity.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; padding_top=&#8221;10&#8243; padding_bottom=&#8221;10&#8243;][vc_column][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text]<\/p>\n<h2 style=\"text-align: center;\"><span style=\"color: #ce2558;\">KEY FEATURES OF THE COURSE<\/span><\/h2>\n<p>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_empty_space][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;grid&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner width=&#8221;1\/3&#8243;]<div class='q_icon_with_title medium circle center '><div class=\"icon_holder \" style=\" \"><span data-icon-type=\"circle\"   class=\"qode_iwt_icon_holder fa-stack fa-3x  \" style=\"\"><i class=\"qode_icon_font_awesome fa fa-shield qode_iwt_icon_element\" style=\"color: #000000;\" ><\/i><\/span><\/div><div class=\"icon_text_holder\" style=\"\"><div class=\"icon_text_inner\" style=\"\"><h3 class=\"icon_title\" style=\"\">PRACTICAL APPROACH<\/h3><p style=''>Audit programme applied to the five pillars of DORA, with real cases and examples.<\/p><\/div><\/div><\/div>[\/vc_column_inner][vc_column_inner width=&#8221;1\/3&#8243;]<div class='q_icon_with_title medium circle center '><div class=\"icon_holder \" style=\" \"><span data-icon-type=\"circle\"   class=\"qode_iwt_icon_holder fa-stack fa-3x  \" style=\"\"><i class=\"qode_icon_font_awesome fa fa-briefcase qode_iwt_icon_element\" style=\"color: #000000;\" ><\/i><\/span><\/div><div class=\"icon_text_holder\" style=\"\"><div class=\"icon_text_inner\" style=\"\"><h3 class=\"icon_title\" style=\"\">INTERNAL AUDIT FOCUSED<\/h3><p style=''>Designed specifically for internal audit teams of financial entities.<\/p><\/div><\/div><\/div>[\/vc_column_inner][vc_column_inner width=&#8221;1\/3&#8243;]<div class='q_icon_with_title medium circle center '><div class=\"icon_holder \" style=\" \"><span data-icon-type=\"circle\"   class=\"qode_iwt_icon_holder fa-stack fa-3x  \" style=\"\"><i class=\"qode_icon_font_awesome fa fa-book qode_iwt_icon_element\" style=\"color: #000000;\" ><\/i><\/span><\/div><div class=\"icon_text_holder\" style=\"\"><div class=\"icon_text_inner\" style=\"\"><h3 class=\"icon_title\" style=\"\">BASED ON THE REGULATION AND RTS<\/h3><p style=''>Contents based on the DORA articles, its Regulatory Technical Standards and good practice guides.<\/p><\/div><\/div><\/div>[\/vc_column_inner][\/vc_row_inner][vc_empty_space][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; background_color=&#8221;#e8e8e8&#8243; padding_top=&#8221;70&#8243; padding_bottom=&#8221;50&#8243;][vc_column][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;grid&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text]<\/p>\n<h2 style=\"text-align: center;\"><span style=\"color: #ce2558;\">TARGET AUDIENCE<\/span><\/h2>\n<p>[\/vc_column_text][vc_empty_space height=&#8221;15px&#8221;][vc_column_text]<\/p>\n<ul>\n<li>Internal audit teams of financial entities<\/li>\n<li>Auditors with responsibilities for DORA compliance<\/li>\n<li>ICT risk, compliance and governance officers<\/li>\n<li>Digital operational resilience officers<\/li>\n<li>Profiles involved in the adoption and governance of DORA within the entity<\/li>\n<\/ul>\n<p>Prior knowledge of DORA fundamentals recommended. Intermediate level.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; padding_top=&#8221;70&#8243; padding_bottom=&#8221;50&#8243;][vc_column width=&#8221;1\/6&#8243;][vc_empty_space][\/vc_column][vc_column width=&#8221;2\/3&#8243;][vc_column_text]<\/p>\n<h2 style=\"text-align: center;\"><span style=\"color: #ce2558;\">COURSE DETAILS<\/span><\/h2>\n<p>[\/vc_column_text][vc_column_text]<\/p>\n<h3>DURATION AND FORMAT<\/h3>\n<p>12 hours distributed across <strong>4 sessions of 3 hours<\/strong> (or 3 sessions of 4 hours), in live online or on-site format. Available in multi-client or in-company format.<\/p>\n<p>&nbsp;<\/p>\n<h3>LANGUAGE AND MATERIALS<\/h3>\n<p>Course in Spanish, materials in Spanish (PDF manual; printed copy optional).<\/p>\n<p>&nbsp;<\/p>\n<h3>CERTIFICATE<\/h3>\n<p>Attendance certificate upon completion.<\/p>\n<p>&nbsp;<\/p>\n<h3>WHAT IS INCLUDED?<\/h3>\n<ul>\n<li>Training<\/li>\n<li>Course manual in electronic PDF format<\/li>\n<li>Attendance certificate<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_empty_space height=&#8221;15px&#8221;][\/vc_column][vc_column width=&#8221;1\/6&#8243;][vc_empty_space][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; padding_top=&#8221;70&#8243; padding_bottom=&#8221;50&#8243;][vc_column width=&#8221;1\/6&#8243;][vc_empty_space][\/vc_column][vc_column width=&#8221;2\/3&#8243;][vc_column_text]<\/p>\n<h2 style=\"text-align: center;\"><span style=\"color: #ce2558;\">COURSE PROGRAMME<\/span><\/h2>\n<p style=\"text-align: center;\">12 hours distributed across 4 sessions of 3 hours each.<\/p>\n<p>[\/vc_column_text][vc_empty_space height=&#8221;15px&#8221;][vc_accordion collapsible=&#8221;yes&#8221; style=&#8221;accordion&#8221; disable_keyboard=&#8221;&#8221;][vc_accordion_tab title=&#8221;SESSION 1 \u00b7 INTRODUCTION TO THE DORA REGULATION (3 HOURS)&#8221; title_tag=&#8221;h4&#8243;][vc_column_text]<\/p>\n<ul>\n<li><strong>Context of the EU Digital Finance Package<\/strong>: EU digital financial environment and the need for a regulatory framework such as DORA.<\/li>\n<li><strong>Objectives and timeline of the DORA Regulation<\/strong>: main goals, implementation deadlines and obliged entities.<\/li>\n<li><strong>Consequences of non-compliance<\/strong>: sanctions, audits, reputational and financial risks.<\/li>\n<li><strong>The five pillars of DORA<\/strong>: ICT risk management, incident management, operational resilience testing, third-party management and information sharing.<\/li>\n<li><strong>Policy instruments related to DORA<\/strong>: relationship between legal and regulatory instruments and the organisation&#8217;s internal policies.<\/li>\n<\/ul>\n<p>[\/vc_column_text][\/vc_accordion_tab][vc_accordion_tab title=&#8221;SESSION 2 \u00b7 IMPACT OF DORA ON INTERNAL AUDIT (3 HOURS)&#8221; title_tag=&#8221;h4&#8243;][vc_column_text]<\/p>\n<ul>\n<li><strong>Direct requirements of DORA for internal audit<\/strong>: how DORA affects planning, execution and reporting of audits.<\/li>\n<li><strong>Other implications<\/strong>: necessary adjustments to internal processes and policies to ensure compliance.<\/li>\n<li><strong>Training and skills development<\/strong>: new competences that internal auditors must acquire, including ICT risk management and operational resilience.<\/li>\n<\/ul>\n<p>[\/vc_column_text][\/vc_accordion_tab][vc_accordion_tab title=&#8221;SESSION 3 \u00b7 AUDIT PROGRAMME FOR DORA (3 HOURS)&#8221; title_tag=&#8221;h4&#8243;][vc_column_text]<\/p>\n<ul>\n<li><strong>Audit planning<\/strong>: structuring the plan to address the five pillars of DORA.<\/li>\n<li><strong>Audit tests<\/strong>:\n<ul>\n<li>Digital operational resilience of the organisation.<\/li>\n<li>Identification and review of critical and important functions.<\/li>\n<li>Audit of recovery plans for ICT incidents.<\/li>\n<li>Incident management and notification process to regulators.<\/li>\n<li>ICT audits: controls and system security.<\/li>\n<li>Penetration testing: review of effectiveness on ICT infrastructure.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Outsourcing risk management<\/strong>: supervision of external ICT service providers and compliance with DORA.<\/li>\n<\/ul>\n<p>[\/vc_column_text][\/vc_accordion_tab][vc_accordion_tab title=&#8221;SESSION 4 \u00b7 CONTINUOUS IMPROVEMENT AND CLOSURE (3 HOURS)&#8221; title_tag=&#8221;h4&#8243;][vc_column_text]<\/p>\n<ul>\n<li><strong>Governance and organisation<\/strong>: assessment of the governance structure in relation to digital operational resilience.<\/li>\n<li><strong>ICT risk management<\/strong>: audit of the process for identifying, analysing and mitigating risks.<\/li>\n<li><strong>ICT incident management<\/strong>: classification, reporting and analysis according to DORA thresholds.<\/li>\n<li><strong>Digital operational resilience testing<\/strong>: testing programme, penetration tests and crisis simulations.<\/li>\n<li><strong>Third-party ICT providers<\/strong>: review of the provider management framework to ensure compliance.<\/li>\n<\/ul>\n<p>[\/vc_column_text][\/vc_accordion_tab][\/vc_accordion][\/vc_column][vc_column width=&#8221;1\/6&#8243;][vc_empty_space][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; background_color=&#8221;#ffffff&#8221; padding_top=&#8221;70&#8243; padding_bottom=&#8221;50&#8243;][vc_column][vc_column_text]<\/p>\n<h2 id=\"contact\" style=\"text-align: center;\"><span style=\"color: #ce2558;\">Request information about the DORA internal audit training<\/span><\/h2>\n<p>[\/vc_column_text][vc_separator type=&#8221;normal&#8221; transparency=&#8221;0&#8243; align=&#8221;align_center&#8221;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;grid&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221; css=&#8221;.vc_custom_1536054851436{margin-top: 20px !important;}&#8221;][vc_column_inner][vc_empty_space][vc_column_text]\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f11388-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"11388\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/pages\/11389#wpcf7-f11388-o1\" method=\"post\" class=\"wpcf7-form init\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"11388\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.6\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f11388-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_cf7a__timestamp\" value=\"UjsxlwWtV99VQU909TCG0Q==\" \/><input type=\"hidden\" name=\"_cf7a_version\" value=\"1.0\" \/><input type=\"hidden\" name=\"_cf7a_address\" value=\"\" \/><input type=\"hidden\" name=\"_cf7a_referer\" value=\"\" \/><input type=\"hidden\" name=\"_cf7a_protocol\" value=\"\" \/><input type=\"hidden\" name=\"_cf7a_bot_fingerprint\" value=\"UjsxlwWtV99VQU909TCG0Q==\" \/><input type=\"hidden\" name=\"_cf7a_bot_fingerprint_extras\" \/><input type=\"hidden\" name=\"_cf7a_append_on_submit\" \/>\n<\/fieldset>\n<p><span class=\"wpcf7-form-control-wrap\" data-name=\"session-online\"><span class=\"wpcf7-form-control wpcf7-checkbox\"><span class=\"wpcf7-list-item first\"><input type=\"checkbox\" name=\"session-online[]\" value=\"Interested in an in-company session\" \/><span class=\"wpcf7-list-item-label\">Interested in an in-company session<\/span><\/span><span class=\"wpcf7-list-item last\"><input type=\"checkbox\" name=\"session-online[]\" value=\"Other editions\" \/><span class=\"wpcf7-list-item-label\">Other editions<\/span><\/span><\/span><\/span>\n<\/p>\n<p><span class=\"wpcf7-form-control-wrap\" data-name=\"your-firstname\"><input type=\"text\" name=\"name\" value=\"\" autocomplete=\"fill\" class=\"fit-the-fullspace\" aria-hidden=\"true\" tabindex=\"-1\" \/><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required\" autocomplete=\"given-name\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"First name\" value=\"\" type=\"text\" name=\"your-firstname\" \/><\/span>\n<\/p>\n<p><span class=\"wpcf7-form-control-wrap\" data-name=\"your-lastname\"><input type=\"text\" name=\"email\" value=\"\" autocomplete=\"fill\" class=\"fit-the-fullspace\" aria-hidden=\"true\" tabindex=\"-1\" \/><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required\" autocomplete=\"family-name\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Last name\" value=\"\" type=\"text\" name=\"your-lastname\" \/><\/span>\n<\/p>\n<p><span class=\"wpcf7-form-control-wrap\" data-name=\"your-organization\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required\" autocomplete=\"organization\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Company\" value=\"\" type=\"text\" name=\"your-organization\" \/><input type=\"text\" name=\"address\" value=\"\" autocomplete=\"fill\" class=\"fit-the-fullspace\" aria-hidden=\"true\" tabindex=\"-1\" \/><\/span>\n<\/p>\n<p><span class=\"wpcf7-form-control-wrap\" data-name=\"your-position\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required\" autocomplete=\"organization-title\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Job title\" value=\"\" type=\"text\" name=\"your-position\" \/><input type=\"text\" name=\"zip\" value=\"\" autocomplete=\"fill\" class=\"fit-the-fullspace\" aria-hidden=\"true\" tabindex=\"-1\" \/><\/span>\n<\/p>\n<p><span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email\" autocomplete=\"email\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span>\n<\/p>\n<p><span class=\"wpcf7-form-control-wrap\" data-name=\"tel-79\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-text wpcf7-validates-as-tel\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"tel-79\" \/><\/span>\n<\/p>\n<p><span class=\"wpcf7-form-control-wrap\" data-name=\"additional-information\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea\" aria-invalid=\"false\" placeholder=\"Additional information (optional)\" name=\"additional-information\"><\/textarea><\/span>\n<\/p>\n<p><span class=\"wpcf7-form-control-wrap\" data-name=\"your-consent\"><span class=\"wpcf7-form-control wpcf7-acceptance\"><span class=\"wpcf7-list-item\"><label><input type=\"checkbox\" name=\"your-consent\" value=\"1\" aria-invalid=\"false\" \/><span class=\"wpcf7-list-item-label\">I agree to the <a href=https:\/\/www.ozonaconsulting.com\/en\/terminos-formacion\/ target=_blank>terms and conditions<\/a> for Ozona training services<\/span><\/label><\/span><\/span><\/span>\n<\/p>\n<p><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/>\n<\/p>\n\n\n\n<div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row]<\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>[vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; background_color=&#8221;#e8e8e8&#8243; padding_top=&#8221;70&#8243; padding_bottom=&#8221;50&#8243; css=&#8221;.vc_custom_1443952192133{background-color: #ffffff !important;}&#8221;][vc_column][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;grid&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text] DORA Training \u00b7 Internal Audit &nbsp; The Regulation (EU) 2022\/2554 (DORA) establishes a European regulatory framework that strengthens the digital operational resilience of financial sector entities, addressing&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"full_width.php","meta":{"ngg_post_thumbnail":0,"footnotes":""},"class_list":["post-11389","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/www.ozonaconsulting.com\/en\/wp-json\/wp\/v2\/pages\/11389","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ozonaconsulting.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.ozonaconsulting.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.ozonaconsulting.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ozonaconsulting.com\/en\/wp-json\/wp\/v2\/comments?post=11389"}],"version-history":[{"count":0,"href":"https:\/\/www.ozonaconsulting.com\/en\/wp-json\/wp\/v2\/pages\/11389\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.ozonaconsulting.com\/en\/wp-json\/wp\/v2\/media?parent=11389"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}