DORA evidence with Preloop
Operational evidence for ICT-using AI agents
The instrument is Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA). It has applied since 17 January 2025.
DORA is about digital operational resilience for financial entities and their ICT third-party arrangements. Preloop is not a DORA register of information, not a third-party risk platform, and not a substitute for your DORA programme.
Not legal advice
Preloop is not a law firm. Nothing on this site is legal advice. Every regulation reference names the instrument and the article or date so you can check it against EUR-Lex yourself.
Where DORA talks about ICT third parties
The following is what the text says, not a claim that Preloop satisfies it.
- ICT third-party risk (DORA, including the register of information). Financial entities must manage contractual ICT arrangements and keep a register covering those services. Preloop does not produce that register.
- Monitoring of ICT services. If AI agents call production tools, move money, or change infrastructure, those actions are ICT-relevant in practice even when the agent is not itself an "ICT third-party service." Preloop can enforce allow / deny / require-approval on those tool calls and keep a session timeline of who approved what.
What Preloop can collect
- Policy decisions on governed MCP tools (who was allowed to deploy, query a database, or call an internal API).
- Human approvals with approver, timestamp, and outcome.
- Model spend and which runtime spent it.
- Flow execution
result.jsonwhen you wire a flow to a control you already run (for example a release audit). That is optional; DORA does not require Preloop presets.
Use that as operational evidence inside a DORA programme your legal and risk teams already own. Do not point a supervisor at this page and call it DORA compliance.
Related EU pages
- EU AI Act (Reg. (EU) 2024/1689)
- Cyber Resilience Act (Reg. (EU) 2024/2847)
- NIS2 (Dir. (EU) 2022/2555)