New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
DORA · Article 38

General investigations

Summary

The Lead Overseer may conduct investigations of critical ICT third-party service providers, with powers to examine records, obtain copies, summon representatives, interview persons, and request telephone and data traffic records, subject to written authorisation.

lead overseerinvestigationscritical ict provideroversight powers

Read the full official text: https://www.digital-operational-resilience-act.com/Article_38.html

Track DORA article 38 as evidence

eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.

Start free trial