Ariadnah
Platform
DORA Understand the responsibilities, common operating gaps, and the path from shared knowledge to evidence. AML & KYC Customer due diligence with the ownership look-through resolved as data. Risk & Control One control catalogue, read through every framework it answers to. Governance & Policies Policies drafted, mapped to requirements clause by clause, and approved in the platform.

Platform

  • Platform overview
  • AI assistant
  • Security & trust
  • Impact & access

Domains and services

  • Register of Information
  • Suppliers & Contracts
  • Asset Management
  • Risk & Control
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • Governance & Policies
  • Incident Management
  • All solutions →

By sector

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services
  • All sectors →
About Pricing Insights Resources Contact
Book a Discovery Call
Home About Platform Solutions Sectors Pricing Insights Resources DORA Guide NIS2 Guide Contact
Book a Discovery Call
Insights

DORA Asset Management: What regulators expect

Ariadnah Solutions DORA 17 Jul 2025 3 min read

01

Core requirement: Know what you have

DORA requires you to create and maintain a comprehensive inventory of all your digital assets. This isn’t optional – it’s a fundamental regulatory expectation that forms the foundation of your ICT risk management.

02

Two types of assets you must track

  • Information assets Any collection of information worth protecting (e.g., customer data, financial records, business intelligence, etc.).
  • ICT assets All your technology hardware and software (e.g., servers, computers, applications, network equipment, etc.).

03

What you must do: The four-step process

  1. Identify and classify everything
    • Document all business functions and who’s responsible for them
    • Map every information and ICT asset that supports these functions
    • Include any hardware or software you use, even if it’s owned by a third party
  2. Record for each ICT asset the required information
    • Unique identifier (asset tag, serial number, etc.)
    • Physical or logical location
    • Classification level (e.g., confidential, internal, public for information assets; non-critical, normal, critical, etc. for ICT assets)
    • Asset owner (who’s responsible)
    • Business recovery requirements (how quickly it needs to be restored)
    • External network exposure (including internet-facing)
    • Support end dates from vendors or service providers
  3. Document how assets connect and what depends on what:
    • Business functions the asset supports
    • Dependencies with other assets and business functions
  4. Establish criteria to determine which assets are most critical by evaluating:
    • ICT risk level of the business functions they support
    • Impact of loss – what happens if confidentiality, integrity, or availability is compromised

04

Ongoing responsibilities

  • Annual reviews: Review and update inventories of business functions and assets at least yearly
  • Change management: Update inventories whenever you make major changes to your ICT environment
  • Continuous monitoring: Keep inventories current as your technology landscape evolves

05

Policy and procedure requirements

  1. Must prescribe:
    • How you’ll monitor and manage the entire lifecycle of ICT assets
    • Record-keeping requirements for all the details listed in the above four-step process
    • Record-keeping requirements for information necessary to perform ICT risk assessments on legacy systems (micro-enterprises exempted)
  2. Must specify criteria for criticality assessment of all information and ICT assets supporting business functions, considering:
    • ICT risk related to business functions and their dependencies on assets
    • Impact analysis of losing confidentiality, integrity, and availability of assets on business processes and activities

06

Bottom line for compliance

DORA expects you to have complete visibility into your digital environment. You cannot manage what you don’t know you have. The regulation requires systematic identification, classification, documentation, and ongoing management of all assets that support your business operations.

07

Key takeaway

Asset management under DORA isn’t just about creating a list – it’s about building a living inventory that enables effective ICT risk management and demonstrates regulatory compliance through clear documentation and regular updates.

08

From requirements to reality

Understanding what regulators expect is only the first step. The real challenge lies in translating these requirements into practical, day-to-day processes that work for your organization without overwhelming your resources.

Many financial institutions find themselves asking: “We know what we need to do, but how do we actually implement this systematically without breaking our budget or consuming all our time?”

The gap between regulatory requirements and practical implementation often feels overwhelming, especially for small and medium institutions with limited IT resources. You need a clear, step-by-step approach that transforms these abstract requirements into concrete actions.

Ready to turn requirements into action?

Whether you’re looking to implement DORA asset management with existing resources or seeking a more automated approach, you have proven paths forward:

  • Read the step-by-step implementation guide Learn how to build compliant asset management using spreadsheets and existing tools – perfect for organizations wanting to start immediately with minimal investment.
  • Discover DORA Pro Platform Explore how automated asset discovery, dependency mapping, and regulatory reporting can transform compliance from a burden into a strategic advantage.

Sources used for this article:

  • DORA regulation (2022/2554) article 8. Identification
  • RTS on ICT risk management (2024/1774) article 4 ICT asset management policy
  • RTS on ICT risk management (2024/1774) article 5 ICT asset management procedure

Originally published on DORA Solutions Insights.

Continue with DORA

Put this question in context.

The DORA guide connects this issue to governance, ICT risk, incidents, resilience testing, third-party risk and the Register of Information.

Recommended next Read the DORA compliance guide →
Explore the operating approach Explore Ariadnah solutions Related analysis Who Reads the Register? Related analysis DORA for Microenterprises: Why size matters for your compliance journey
Manage Consent
We use cookies to keep this site reliable and to understand how it is used. You can accept, deny, or adjust your preferences at any time.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ariadnah

Compliance advisory & technology

Regulatory specialists and technology that help organisations simplify compliance, strengthen operational resilience, and build lasting trust.

ISO/IEC 27001 certified (DNV)

Platform

  • Platform Overview
  • DORA Guide
  • NIS2 Guide
  • Regulatory Library
  • Register of Information
  • Risk & Control
  • Governance & Policies
  • Incident Management
  • Asset Management
  • Suppliers & Contracts
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • AI
  • Security

Sectors

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services

Company

  • About Ariadnah
  • Pricing
  • Our Experts
  • Impact
  • FAQ
  • Insights
  • Contact

Legal

  • General Terms
  • Data & Privacy
  • Cookie Policy
  • Accessibility

© 2026 Ariadnah Solutions B.V.