The GapAI AutomationWho we work withApproachFintech GardenBlogStart a conversation

DORA operational resilience & ICT risk automation.

Continuous ICT risk monitoring, third-party vendor risk scoring, incident management, and automated examiner evidence packs for licensed EMIs, PIs, and crypto-fiat institutions across the EU and UK.

Request DORA Gap AuditView DORA Architecture
EU/UKRegulated ICT Compliance
100%Ex-Solarisbank Leadership
0Data Exfiltration Guarantee

DORA compliance is not a static PDF checklist. European supervisory authorities expect continuous ICT risk logging, vendor concentration risk tracking, and verifiable evidence trails for every automated control.

Manual Reality

Scattered spreadsheets

Outdated vendor registers, delayed incident logs, and manual evidence gathering during regulator audits.

Novafin DORA Architecture

Automated Control Environment

Automated ICT incident logging, real-time third-party vendor risk scoring, and zero-data-exfiltration audit trails.

DORA Articles 5-16 and 28-30 demand active operational controls, not static policy binders.

What we implement for DORA.

Turnkey operational resilience modules built specifically for payments and financial entities.

01

ICT Risk Management Framework (Art. 5-16)

Automated control validation, continuous policy gap analysis, and real-time operational risk dashboard for your management body.

02

ICT Third-Party Risk Management (Art. 28-30)

Information register automation, subprocessor monitoring, concentration risk scoring, and vendor contractual gap flags.

03

Major ICT Incident Reporting (Art. 17-23)

Initial notification and intermediate report drafting within strict supervisory timelines using standardized EBA/ESMA templates.

04

Digital Operational Resilience Testing (Art. 24-27)

Automated vulnerability assessment tracking, scenario testing logging, and remediation action plan management.

05

Examiner Evidence Packs & Audit Trail

Single-click export of deterministic control execution logs for regulators, card schemes, and external auditors.

06

Continuous Model & Control Assurance

Continuous health monitoring, rule drift detection, and quarterly re-validation reports for audit committees.

Engagement Tiers for DORA

Fixed-scope architecture and automation engagements designed for payment institutions.

Tier 1

DORA Gap Diagnostic

€8,000 · 2 weeks fixed timeline

Complete ICT risk mapping, third-party vendor register audit, DORA gap assessment, and 5 ranked automation priorities with written report.

Tier 2

DORA & AI Act Governance Module

€35,000 · 4–6 weeks fixed build

Automated ICT control mapping, vendor register automation, transaction monitoring evidence harness, and examiner compliance pack.

Tier 3

Managed Assurance Retainer

€2,800 / mo · Recurring service

Continuous automated health monitoring, model deprecation watch, and quarterly re-validation reports for regulatory examiners.

Operator Credibility

Led by Dumitru Condrea

Founder & Managing Partner | Ex-Solarisbank General Manager

15+ years leading licensed payment entities, PSD2 compliance frameworks, and multi-jurisdiction risk operations. Dumitru has opened EMI and PI licenses across Lithuania, Cyprus, Malta, the UK, and Romania, and builds risk engines for high-throughput PSPs.

Co-host of Fintech Garden (170+ episodes with global payment leaders) and architect of Novafin's AI automation methodology.

Connect on LinkedIn →

Vendor Risk & Security Guarantee

Built to satisfy European banking supervisors and strict vendor onboarding requirements.

01

Data Residency & Sovereignty

All data processed strictly within EU/EEA boundaries or on local, isolated customer infrastructure.

02

DPA & DORA Article 28 Alignment

Standardized Data Processing Agreement with clear subprocessor disclosures, audit rights, and regulatory compliance clauses.

03

Zero Data Exfiltration

Client operational data and audit findings never leave the local engagement environment and are never used to train public models.

04

Professional Indemnity & Governance

Sized E&O and cyber liability coverage with human-in-the-loop controls on every regulatory filing.

Request a DORA Operational Resilience Gap Audit.

We review your current ICT risk framework, vendor registers, and control environment in a 45-minute working call with an ex-bank GM. You receive a written gap assessment within 48 hours.

  • Review of ICT Third-Party Vendor Register readiness
  • Identification of manual control failure risks
  • Clear roadmap for automated examiner evidence trails