Critical functions and CIFs
Scope, continuity objectives and function ownership.
DORA operational resilience
AuditReady keeps CIFs, ICT dependencies, incidents, resilience tests, third parties and findings in one operating context, with evidence and ownership attached.
| Item | Owner | Status | Threshold / review |
|---|---|---|---|
| CIF — payment settlement | ICT Risk | Active | 30 Apr 2026 |
| Single cloud provider | Third-party oversight | In review | 22 Apr 2026 |
| Resilience test | Resilience lead | Open finding | 12 Apr 2026 |
| ICT incident — change | IT Operations | To attach | 6 Apr 2026 |
FinSecure demonstrative scenario
Demonstrative organisation
FinSecure Payments S.p.A. — payment institution (demonstrative scenario)
Payments and white-label cards processor, dependent on one cloud provider, with resilience follow-up still open.
Current situation
Payment CIF defined; gaps on resilience testing and a single cloud provider.
What the scenario shows
This is not a real customer. In the demo you can follow a critical function from continuity thresholds to tests, findings and follow-up evidence.
What you can inspect
Opens the DORA demo environment. This is not a guided-demo request.
Scope, continuity objectives and function ownership.
Systems and services linked to the context they support.
Operational register with timeline, impact and supporting evidence.
Outcomes and gaps kept in the CIF cycle.
Contractual and documentary evidence with status and owner.
Follow-up assigned, dated and linked to closure proof.
Ownership on controls, tests and third parties.
Packs for internal review and supervisory requests.
DORA module
The DORA module includes the platform, control catalogue, critical functions, ICT incidents, resilience tests, third-party providers and review preparation. Other frameworks stay on the full price list.
Piattaforma completa più catalogo controlli e contenuti DORA.
€ 690 / month
€ 6.900 / year Annual billing: 10 months paid, 2 months included
We will walk through CIFs, third-party providers, tests and findings in one operating context.
AuditReady does not replace ICT risk, regulatory advice or the organisation’s decisions. It makes DORA work traceable, verifiable and ready for review and supervision.