Einar & Partners
DORA · Regulation (EU) 2022/2554

Check your own setup against DORA, with your own AI assistant

The DORA plugin gives your AI assistant Einar & Partners' DORA knowledge base: the regulation in plain language, how each requirement is built in ServiceNow, and the checks an assessment runs. You bring your evidence. Your assistant measures it against the requirements and reports the gaps, article by article.

Request access

Get your DORA plugin access key

About your setup, not DORA in general

It assesses what you show it: your ServiceNow data, an export or a written description. It asks for evidence before it answers.

Built on ServiceNow practice

The checks follow how DORA is actually implemented in ServiceNow, from the CMDB to incident reporting and the Register of Information.

Your evidence stays with you

Your assistant reads your data where it lives. Your records are never sent to E&P. What we do see

Gaps you can act on

Each finding names the article it comes from and whether it is law or E&P's recommendation.

Coverage

All five DORA pillars

For each pillar: the regulation in plain language, the ServiceNow design, field references and the checks an assessment runs.

Pillar 1Art. 5–16

ICT risk management

Framework, asset identification, protection, detection, response and recovery.

Pillar 2Art. 17–23

Incident reporting

Classifying ICT-related incidents and meeting the reporting deadlines.

Pillar 3Art. 24–27

Resilience testing

The testing programme, and threat-led penetration testing where it applies.

Pillar 4Art. 28–30

Third-party risk

The Register of Information, ICT providers, contracts and concentration risk.

Pillar 5Art. 45

Information sharing

Arrangements for exchanging cyber-threat information and intelligence.

Not covered: the oversight framework for critical ICT third-party providers (Art. 31–44).

Transparency

You always know where a statement comes from

Every statement in the knowledge base is labelled: what the law requires, what Einar & Partners recommends, and how ServiceNow behaves. Your assistant keeps those labels in its answers, so you can tell an obligation from advice.

REGThe initial notification of a major incident is due within 4 hours of classifying it as major, and no later than 24 hours after becoming aware of it.

E&PIn the first 24 hours both clocks run, and the report is due at whichever runs out first. A slow classification decision shortens your filing window.

PLATFORMThe flow that turns incidents into DORA reporting candidates is switched off by default on a new ServiceNow instance. Check it first.

From the knowledge base, Pillar 2: incident reporting
How it works

From request to first assessment

The knowledge base holds nothing about your organisation. An assessment only works when your assistant can see your evidence, so step 4 matters most.

  1. Request access

    Fill in the form. We set up your access, usually within one business day.

  2. Receive your key

    You get one access key and the connection steps. The key is shown once, so store it safely.

  3. Connect your assistant

    Add the knowledge base as a connector in your AI client and enter your key. With Claude, also install the DORA plugin for the guided assessment.

  4. Bring your evidence and ask

    Connect ServiceNow read-only, or share an export or a written description. Then ask, for example, assess our Register of Information.

Read-only ServiceNow connectorBest results. Your assistant follows the relationships between records, as the checks require.
An exportYour Register of Information, incident records or CMDB. Covers most checks, as far as the export goes.
A written descriptionEnough to discuss gaps and plan. Not enough to evidence most checks.
Your data

What happens with your data

Three parties are involved: you, your AI provider and Einar & Partners. This is what each of them sees.

Stays with you

Your evidence

Your ServiceNow records, exports and descriptions stay in your environment. Your assistant reads them there. There is no upload to Einar & Partners, and the knowledge base cannot reach into your systems.

Your AI provider

Your conversation

Your assistant's provider, such as Anthropic, OpenAI, Mistral or Microsoft, processes your conversation and the evidence you share with it, under your agreement with them. Use a client and data settings your organisation has approved. With a self-hosted model, this stays in-house too.

Einar & Partners

Searches and contact details

We receive the searches your assistant sends to the knowledge base and which documents it opens, linked to your account number. We use them to count your allowance and to improve coverage. A search can contain words from your question, so leave names and confidential details out of your questions where you can.

Your contact details from this form are kept separately, for setting up and supporting your access.

Use it

Made to be used, often

The knowledge base is meant to be read and learned from, not kept for the occasional audit. Run an assessment before a submission, ask what a requirement means for your setup, or check one control after a change.

  • ICT risk and compliance teamsAssess a pillar against your own records before your supervisor does.
  • ServiceNow platform ownersSee which fields, relationships and flows each DORA requirement depends on.
  • Internal auditPrepare a review with checks that cite the article behind them.

Your account includes 2,000 searches per month. One question often uses several. The plugin supports your assessment. It does not replace legal advice or your supervisor's view, and statements labelled E&P are our interpretation, not law.