Solutions — instrument
Your ICT third-party register now has agents in it.
Regulation (EU) 2022/2554, in force since January 2025. An operational resilience regulation rather than an AI one, which is why it reaches agents at all: an agent's tools are ICT third parties, its failures are ICT incidents, and both were written down for humans. RotaGrant touches two of the five pillars directly, and those two are where agents put pressure on a register and a clock that already exist.
Where it contributes
- ICT third-party risk
- An agent's dependency surface is a third-party surface. MCP servers and their tool manifests are inventoried, watched for change, and a description that changes under an agent's feet is recorded as drift rather than absorbed.
- Incident reporting
- The classification and clock machinery is instrument-agnostic. DORA's thresholds and templates differ from Article 73's and are not encoded — but the record an incident report is assembled from is the same record.
Two pillars of five. Business continuity, the ICT risk management framework itself, and threat-led penetration testing are the bulk of DORA and sit outside what an agent governance layer can speak to.
What a clause map would cover
Articles 17–20 on incident management, classification and reporting, against the same classification machinery that already serves Article 73; and Articles 28–30 on ICT third-party risk, where the register of information is an inventory obligation and the agent inventory, model inventory and configuration provenance are the evidence. Article 25's testing requirement is a partial — the adversarial grid is a real test of one component, and it is not threat-led penetration testing under TIBER-EU.
Partial coverage is not an obstacle to writing one. A clause carries a
provenance of platform, hybrid or
customer, and only the first two are scored, so the three
pillars outside this platform would be recorded as yours and excluded from
the reading — exactly as the AI Act map
covers the articles a platform can evidence rather than the whole Act.
Today the EU profile selects eu-ai-act and gdpr,
so a DORA reading is assembled from the evidence rather than scored
against clauses. Clause maps are YAML validated against the evidence
registry at load, which means yours, your counsel's or ours — and none of
those needs a release.
RotaGrant ships no clause map for DORA. The engine takes clause maps as data, so one can be authored — by you, by your counsel, or with us — and it will be scored like any other. What this page will not do is imply a mapping that does not exist, because a readiness percentage against an instrument nobody encoded is a number with no denominator.