The document list BaFin walks in with¶
Most DORA readiness work starts from the regulation and tries to guess what a supervisor will ask for. You do not have to guess. BaFin published the list.
The awkward part is what happens when you lay your existing policy stack next to it.
The list exists, and it is specific¶
BaFin's overview, Documentation requirements for financial entities according to DORA, names the strategies, policies, procedures and registers it expects a financial entity to be able to produce. Not themes. Documents.
That changes the nature of the exercise. "Do we comply with Article 9" is a debate. "Do we have a written cryptographic controls policy, and does it say what Article 9(2) requires" is a question with a yes or a no, and you can answer it in an afternoon.
So I transcribed the whole thing into one table, and against every row put the article that justifies the ask. Chapter II for ICT risk management, Articles 5 to 16, split into strategies, policies, and then procedures, registers and everything else. Chapter III for incident management and reporting. Chapter IV for testing. Chapter V section I for third-party risk.
What the mapping exposes¶
Two failure modes show up almost immediately when people run their own stack against it.
Documents that exist but are anchored to the wrong article. A perfectly good backup policy that cites Article 12 and stops, when the thing being asked for also has to satisfy the recovery-objective language that lives elsewhere. The document is real, the coverage is not.
Documents nobody has, because nothing ever asked for them by name. These are rarely the big ones. It is the ICT third-party strategy, the exit plans, the register entries that were meant to be maintained rather than written once. Things that fall between an owner who thought it was covered and an owner who thought someone else had it.
Neither of those is visible from reading the regulation top to bottom. Both are obvious from a table with a "do we have this" column.
Then you have to write them¶
Finding the gap is the easy half. So the page comes with two things for closing it.
A policy template, which is a copy-paste skeleton: every section named, the article references pre-filled, and the body written as a fill-in-the-blanks version of a real working policy rather than a wireframe. You replace the bracketed placeholders and delete the guidance. It is here: DORA policy template.
And a documentation builder in Excel, which turns the index into a working tool. Pick a document type and a specific document, fill in your details, and it exports a formatted policy, standard, procedure, strategy or guideline. The regulation references and the section structure are already in it.
One caution¶
The index is transcribed from BaFin's overview, and BaFin's overview is a supervisory aid rather than the law. The law is the regulation. Every article reference in the table should be checked against the current text on EUR-Lex before you rely on it in anything that goes to a supervisor, and the page says so in the places where it matters.
It is also a German supervisory document. If your competent authority is somewhere else, the underlying articles are identical and the emphasis may not be.
Clauses corner: DORA documentation requirements →
Regulation (EU) 2022/2554, Chapters II to V, read against the BaFin documentation-requirements overview. Practitioner material, not legal advice.