FinTech DORA Data Prep

DORA has applied since January 2025. The data plumbing behind its incident reports is missing at most FinTechs I see.
This DORA is the EU regulation for financial entities, not the DevOps metrics. Its incident-reporting duties read like compliance work and land like data engineering: when a major ICT incident hits, you owe classified, structured reports on tight clocks, built from telemetry you either have or don’t.
The checklist I run with FinTech clients:
- One incident timeline. Detection, classification, escalation, resolution timestamps in a single queryable store, not spread across a ticket tool, Slack and someone’s memory.
- Classification as code. DORA’s thresholds (clients affected, downtime, geographic spread, data losses) computed from your data, so “is this major?” takes minutes, not a meeting.
- Third-party register with data flows. Which providers touch which services and what data, kept current. The register is a table, so treat it like one.
- Report fields fed by queries. If assembling the initial notification means copy-pasting from 5 tools, the clock will win.
Most of this doubles as plain good incident practice. The regulation just removed the option of skipping it.
Could your team classify an incident against DORA’s thresholds tonight, from data alone?
Written by
Thomas Nys
Fractional Data Architect helping startups and scaleups build data platforms that scale.
More about Thomas Nys →