SOURCE 0 - YOUR OWN AUDIT TRAIL CANNOT PROVE YOUR DILIGENCE
Article 6 of DORA requires financial entities to review and internally audit their ICT risk framework at least once a year. But the "independence" the Regulation demands is segregation within the entity, not independence from it — leaving the only record of diligence in the hands of the party whose diligence is in question.

