96%
of EMEA financial organisations believe they still need to strengthen their resilience to meet DORA.
DORA requires you to know your ICT providers, the services they deliver and the functions that depend on them. Boldo links this information in a governed repository, to prepare the register and keep your mapping up to date.
In force since 17 January 2025, DORA requires financial entities to manage the risks tied to information and communication technologies, including those carried by third-party providers.
The register of information documents the contractual arrangements covering the use of ICT services. To be usable, it must also be reconcilable with the business functions, applications and dependencies concerned.
The real challenge is therefore not only to produce a file by a given deadline. It is to keep the information reliable between two submissions and to explain the consequences of a failure.
of EMEA financial organisations believe they still need to strengthen their resilience to meet DORA.
now make it their number one digital resilience priority.
DORA covers ICT risk management, the reporting of major incidents, resilience testing and the control of risks tied to third-party providers.

In particular, your organisation must be able to:
Boldo does not cover all of these obligations on its own. It structures an essential foundation of the framework: knowledge of the assets, functions, providers and their dependencies.
Boldo links the data needed for your resilience mapping and for preparing the register of information, without replacing your regulatory submission tools.

Structure ICT providers, the services delivered, the contracts and the entities concerned in a shared base fed by files or by API.

Link business functions to the applications, ICT assets and providers they depend on to understand the potential impacts of a failure.

Document criticality, responsibilities, recovery objectives (RTO/RPO) and the other indicators useful to your analysis, following your organisation's metamodel.
Boldo lets you structure ICT providers, services, contracts and their links to the functions and assets concerned.
You can then filter, control and export this data to prepare your regulatory register or to reconcile the information already maintained in your compliance tools.
Boldo does not replace the templates, taxonomies and submission channels mandated by your competent authority.


A list of suppliers is not enough to understand your exposure. A single function may depend on several applications, ICT services and providers, some of them shared with other activities.
Typed relationships let you start from a function, an asset or a supplier and walk through the dependencies that connect them.
Impact analysis stops being a one-off collection. It relies on a verifiable, reusable model.
A continuity plan cut off from the repository becomes hard to maintain and hard to check against real dependencies.
You can model your interruption scenarios, your continuity plans and the associated responsibilities, then link them to the functions, applications, assets and providers concerned.
Impact views, diagrams and dashboards then let you prepare resilience reviews from the same knowledge of the IT landscape.


DORA compliance does not end when the register is submitted. Providers, contracts, services and dependencies keep evolving throughout the year.
In Boldo, every asset can have an identified owner and every change is versioned. Roles and access domains govern what the IT, risk, security, compliance or audit teams can view and edit.
The same base thus supports both the regulatory work and the CIO's day-to-day steering of the IT landscape.
The information required for DORA is often spread across supplier files, contract databases, a CMDB, questionnaires and compliance tools.
Bring in existing providers, contracts, services and assets, then map the columns to the properties and relationships of your model.
Build the synchronisations you need when certain sources must keep feeding your mapping and your controls.
Give each team the rights it needs to check and enrich the information within its scope.
Need regulatory guidance? We can connect you with partner consultants who specialise in DORA initiatives.
Boldo structures an essential part of the knowledge the DORA framework requires: business functions, ICT assets, providers, services, contracts and their dependencies.
The platform does not replace the tools for incident reporting, test management or regulatory submission. It provides a living repository those processes can rely on.
A register to prepare, dependencies to map or information to make reliable: discover how to structure the knowledge your DORA work requires.
30 minutes dedicated to your register and your mapping.