Regulatory Readiness Scorecard

A fourteen-question assessment against DORANIS2, the EU AI Act and MiCA. You get the banded finding and a domain-by-domain readout on screen. The full findings sheet, with article references, comes by email.

Most readiness questionnaires ask whether you have a policy. That is the wrong question. A supervisor does not ask whether a policy exists — they ask you to produce the evidence that it operated, and they ask on a clock. This assessment is built around what has to be demonstrable rather than what has to be written down. It is the same principle behind compliance evidence that is generated, not assembled: the record either falls out of the control as it runs, or it does not exist when someone asks.

Some answers are scored. Some are knockouts: a missing register of information or an untested incident reporting path is a finding in its own right, and no amount of strength elsewhere offsets it. Those are called out separately, with the article they sit under. If you want to see what those obligations look like in practice, the readouts on DORA incident reportingthreat-led penetration testing and MiCA CASP operational resilience under Article 68 cover the ground this scorecard tests.

It takes about four minutes. When you are done, the sheet that arrives is written against your answers — and if you would rather have the whole estate assessed properly, that is what a Technology Control Assessment does.

Who this is for

  • Compliance officers, COOs and technology leads in firms inside DORA, NIS2, MiCA or the AI Act
  • Crypto-asset service providers, funds and fund services, payment institutions, iGaming operators and maritime groups
  • Anyone who has been asked by a board or an auditor to say where the firm stands and does not have a clean answer

How this is scored

Questions are grouped into five domains: accountability, ICT third-party risk, incident detection and reporting, resilience testing, and evidence. Each domain is scored independently, so a strong overall percentage does not hide a single domain sitting at zero.

  • Material gaps — obligations with no demonstrable control behind them. Parts of the file would not survive a supervisory request this quarter.
  • Partially covered — the structure is there, the documented trail is not. This is where most firms land.
  • Substantially covered — nothing structural. The value is in independent challenge, not remediation.

Any knockout finding places the result in the bottom band regardless of the total. That is deliberate. A register that does not exist cannot be averaged away.

What happens after

You get the findings sheet by email. If the result is in the bottom band, it includes what a two-week gap assessment would cover and what it would cost. If it is in the top band, it includes nothing to buy — a firm that is already covered does not need selling to, and saying so is more useful than pretending otherwise.

Related reading