DORA evidence with Preloop

Operational evidence for ICT-using AI agents

The instrument is Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA). It has applied since 17 January 2025.

DORA is about digital operational resilience for financial entities and their ICT third-party arrangements. Preloop is not a DORA register of information, not a third-party risk platform, and not a substitute for your DORA programme.

Not legal advice

Preloop is not a law firm. Nothing on this site is legal advice. Every regulation reference names the instrument and the article or date so you can check it against EUR-Lex yourself.

Where DORA talks about ICT third parties

The following is what the text says, not a claim that Preloop satisfies it.

  • ICT third-party risk (DORA, including the register of information). Financial entities must manage contractual ICT arrangements and keep a register covering those services. Preloop does not produce that register.
  • Monitoring of ICT services. If AI agents call production tools, move money, or change infrastructure, those actions are ICT-relevant in practice even when the agent is not itself an "ICT third-party service." Preloop can enforce allow / deny / require-approval on those tool calls and keep a session timeline of who approved what.

What Preloop can collect

  • Policy decisions on governed MCP tools (who was allowed to deploy, query a database, or call an internal API).
  • Human approvals with approver, timestamp, and outcome.
  • Model spend and which runtime spent it.
  • Flow execution result.json when you wire a flow to a control you already run (for example a release audit). That is optional; DORA does not require Preloop presets.

Use that as operational evidence inside a DORA programme your legal and risk teams already own. Do not point a supervisor at this page and call it DORA compliance.

Related EU pages

Related resources