Legal coverage
Every applicable requirement is mapped to a controlled policy, plan, register or evidence pack.
A practical implementation map for a small and non-interconnected investment firm preparing for authorisation in Iceland.
Each route opens the relevant part of the guide with the useful view or filters already selected.
A policy can be approved while the underlying control is absent. Readiness must be assessed across separate layers.
Every applicable requirement is mapped to a controlled policy, plan, register or evidence pack.
The relevant D01–D14 deliverables are drafted, reviewed and appropriately approved.
The operational measures described on paper exist in the firm’s actual ICT environment.
Current evidence shows the controls operate and resilience tests demonstrate they work.
Article 12 IFR determines whether the investment firm falls within the Article 16 simplified framework. DORA’s separate microenterprise definition may affect particular requirements, but does not decide Article 16 status.
Confirm permissionsInvestment services, client assets, execution and operational model.
Test Article 12 IFRDocument every quantitative and qualitative SNI condition.
Test microenterprise statusFewer than 10 employees and relevant EUR 2m financial threshold.
Record proportionalityConnect each simplification to scale, risk and complexity.
Answer six questions to identify the likely framework, conditional issues, priority deliverables and fact-finding needed. Nothing is saved.
Corrected legal mapping, supervisory position and proportionate implementation destination.
| Source | Requirement | Correct legal reference | Pre-licence | Primary deliverable |
|---|
| ID | Legal requirement | Applicability | Readiness gate | Primary location |
|---|
Granular controls, consolidated into a proportionate and filterable implementation package.
Each detail panel includes prerequisites, required inputs, decisions, validation, templates and what implementation looks like beyond approval.
Editable policies, procedures, registers, workpapers and training materials—organised around the same D01–D14 architecture used throughout the matrix.
Annexes A and B are mandatory operational tools; Annex C is conditional, Annex D is contextual and Annex E is optional. The legal-detail explorer, master matrix, D14 register and downloads now use the corrected references.
Read release notes ↗A template is not evidence of implementation. Yellow or bracketed fields require completion. Actual systems, providers, controls, tests, incidents, audit results and evidence must be supplied and independently validated where appropriate.
Use these master files to scope the engagement, collect facts and prove complete requirements coverage.
Each pack explains what the file does, what it contains and what must still be populated, implemented or validated.
The pre-licence gate should demonstrate a credible operating model—not a stack of aspirational policies.
If it means “not normally submitted with the application,” it may be reasonable. If it means the control does not need to exist until after authorisation, that is unsafe for core operating-model controls.
A legal-led, technically validated workplan for a greenfield investment firm.
Management retains responsibility. Legal can own the mapping and narrative; technical controls require validation by the firm’s IT or security specialist.
Applicability, compliance matrix, governance, contracts, licensing narrative and decision records.
Strategy, risk tolerance, roles, resources, major risk acceptance and oversight.
Registers, monitoring, reporting, vendor oversight, training and action closure.
Configuration, identity, logging, patching, backup, restoration, testing and technical evidence.
Standard SaaS terms may not be negotiable. The file should distinguish protection obtained, standard assurance relied upon and risk formally accepted.
The corrected baseline for the simplified framework and adjacent obligations.
For Article 16 firms, Articles 5–15 DORA and Title II (Articles 2–27) of Delegated Regulation 2024/1774 do not supply the simplified ICT risk-management framework. Incident management, testing and ICT third-party obligations continue separately under DORA.