Choosing a GRC Platform for DORA Compliance

Most firms reach the same conclusion about DORA within a quarter of starting: the obligations are too interconnected to run in spreadsheets. A single ICT incident touches your risk register, your incident-reporting clock, your third-party register and your resilience-testing evidence at once, and a spreadsheet cannot hold those relationships or produce them on demand for a supervisor. That realisation is what sends people looking at GRC platforms — and straight into a crowded, confusing market.

What you are actually buying

A GRC platform for DORA is not a compliance checkbox. It is the system of record that links each obligation to a control, an owner and a piece of evidence, and can reproduce that chain when a regulator asks. The buyers comparing MetricStream, ServiceNow IRM, Archer, LogicGate and OneTrust are usually mid-budget-cycle and unsure which of them actually fits a DORA programme rather than a generic risk framework. The honest answer is that most of them can be made to fit; the cost and the risk live in the configuration, not the logo.

The questions that separate the options

Rather than a feature grid, four questions decide the outcome.

Free · 4 minutes

Do you know what could take the business down — and have you priced it?

Fourteen questions on concentration, third-party dependence, resilience, and incident readiness — the exposures a board is accountable for whether or not it can see them. Banded finding on screen, full sheet by email.

  • Does it model the DORA Register of Information natively, or will you rebuild it? The Register is DORA’s hardest artefact — a linked relational data model, submitted in xBRL-CSV. A platform that treats it as a flat list will cost you every submission cycle.
  • How does it handle the incident-reporting clock? DORA’s major-incident windows are tight. If classification and reporting are manual, the tool has not solved your real exposure.
  • Can it hold evidence, not just policies? A supervisor asks to see a control operating and the date it was last tested. A platform that stores documents but not test results leaves you doing the work by hand.
  • What is the true cost at your scale? Per-user, per-module and per-connector pricing diverge sharply once you add the third-party and resilience-testing modules that DORA actually requires.

Where selections go wrong

The common failure is buying the platform before defining the operating model. A GRC tool encodes how your firm runs risk; if that process is unclear, the implementation becomes a multi-year project that ossifies a bad process in software. The firms that succeed define the obligation-to-control-to-evidence model first, on paper, then choose the platform that fits it with the least customisation. The ones that struggle buy the platform first and let the vendor’s template define their risk process — which is how you end up paying a licence to run someone else’s framework.

The second failure is treating selection as a procurement exercise rather than a technology-and-regulatory one. The person who can read a DORA article and a platform’s data model in the same sitting is the person who should run the selection, because the fit lives precisely at that intersection.

Who this is for

This reading is for:

  • CTOs and heads of risk selecting a GRC or ICT-risk platform under DORA
  • Compliance leads who own the DORA programme but not the tooling budget
  • Boards approving spend on a control platform they will be asked to justify
  • Operational resilience owners tired of managing DORA in spreadsheets

Sixteen Pillars defines the obligation-to-control-to-evidence model first, then runs the platform selection against it, so you buy tooling that fits your firm rather than someone else’s framework. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming