Coreal.
Book a working session →
·Compliance · DORA

DORA compliance for telco fintech.

Digital Operational Resilience Act (Regulation (EU) 2022/2554). Enforced from 2025-01-17. Supervised by European Banking Authority + national competent authorities (BaFin, FCA-equivalent in EU member states). Coreal generates the evidence pack automatically on every Minctrl build — see /security-compliance for the full posture.

Enforced
2025-01-17
Authority
European…
Penalties
Up to 2% of annual global turnover
Vertical
TELCO

What this regulation covers.

ICT risk management, incident reporting and third-party oversight for financial entities operating in the EU.

For a telco fintech, the salient angles are: BSS write-path protection (regulator must see read-only on event bus); Subscriber consent for fintech data sharing under GDPR; Group-level vs partner-bank capital allocation. Primary licence: Partner-bank EMI passport (or own EMI for tier-1).

● RELEVANT ARTICLES
  • Art. 5 — ICT risk management framework
  • Art. 16 — Reporting major ICT-related incidents
  • Art. 24 — Threat-led penetration testing (TLPT)
  • Art. 28 — General principles for third-party ICT services
  • Art. 30 — Concentration risk
● EVIDENCE PACK COREAL GENERATES

What lands in the regulator file.

E01ICT risk register (versioned, per-process)
E02Incident timeline with operator + AI-agent actions
E03Decision journal (7-year retention, replayable)
E04Third-party risk inventory (provider gateway contracts)
E05TLPT scope document + penetration-test reports

All items journaled, replayable, 7-year retention.

● READ NEXT
·Questions we hear

Which DORA articles apply to a telco?

Primarily: Art. 5 — ICT risk management framework; Art. 16 — Reporting major ICT-related incidents; Art. 24 — Threat-led penetration testing (TLPT). The full mapping is in the Coreal compliance posture document — see /security-compliance.

What evidence does Coreal generate per audit?

ICT risk register (versioned, per-process); Incident timeline with operator + AI-agent actions; Decision journal (7-year retention, replayable). The Minctrl pipeline produces this artefact set automatically on every build — see /company §05 'How we ship'.

What are the penalties for non-compliance?

Up to 2% of annual global turnover; member-state criminal liability for senior management on wilful non-compliance.

·Working session

Bring the perimeter,
leave with a brief.

Book a working session →Read field notes →
Not ready to book 4 hours?

Read the Wave-1 runbook first.

The full 90-day launch sequence — phases, partner-bank gates, who signs off when. No form to read it.

Read the runbook →

INDICATIVE DATA · Numbers and timelines reflect public regulator filings, vendor documentation and our own delivery experience. Per-engagement values vary with operator profile, BSS vintage and regulatory perimeter. Engage early for a fitted estimate under NDA.