VigieObsThe AI-native context layer for digital operational resilience Most organizations know their systems. Few understand their dependencies.

Critical functions rarely fail alone. They fail through dependencies — ICT services, providers, contracts, infrastructure, data and recovery capabilities.

VigieObs turns dependency risk into resilience decisions.

See what can breakDecide with evidenceProve what changed
AI agents prepare. Humans decide.
VigieObs Resilience GraphILLUSTRATIVE DATA
LIVE MODEL · ALL CRITICAL FUNCTIONS OPERATIONAL
INSPECT
Select any node
MONITORING

01 · See · ICT dependency mapping From scattered documents to one operational model.

Registers, contracts, provider lists, test reports and evidence folders each hold part of the picture. VigieObs connects them into one operational model, so every function can be traced to its dependencies, every dependency to its evidence, and every exposure to a decision.

SpreadsheetsPDF contractsRegistersProvider listsAudit reportsTest documentsEmailsEvidence folders
One operational model
Function ↔ Service ↔ ProviderProvider ↔ Contract ↔ Exit planScenario ↔ Test ↔ EvidenceFinding ↔ Remediation ↔ Decision

Why now · From risk to resilienceThe pressure has moved from systems to decisions.

Leaders are now personally accountable for resilience, for third parties and for AI. They need to show what they decided, on what evidence, and what it changed.

78%of CISOs worry about their personal liability for security incidents, up from 56% a year earlier.Splunk, The CISO Report 2026
41%cannot link their remediation activities to the reduction of risk.Splunk, The CISO Report 2026
96%now oversee AI governance and risk across the enterprise.Splunk, The CISO Report 2026
Non-ICTThe third-party register now extends beyond ICT services, with a two-year transition.EBA/GL/2026/09, 18 September 2026

Sources: Splunk, The CISO Report 2026: From Risk to Resilience in the AI Era (survey of 650 CISOs worldwide, all sectors); European Banking Authority, final report on the guidelines on the sound management of third-party risk.

02 · Understand · Resilience graph for ICT third-party risk Your resilience is a system.

VigieObs maps the relationships that determine whether critical operations can withstand disruption. Select any object to see what it connects to.

03 · Simulate · ICT disruption scenarios and stress testing See what can break.

What happens if a critical provider fails? Don't just document resilience. Simulate it.

1 · Select a critical function
2 · Choose a scenario
DEPENDENCIESREADY
FUNCTION
ICT SERVICES
PROVIDERS
CONTRACTS
Impact
Response
From disruption to decision.
Open impact analysis →

04 · Decide · From risk to decisionTwo shocks. One graph. Every decision on record.

A provider fails, or a rule changes: VigieObs propagates the shock through the same operational model, prepares the options, and keeps the decision, its owner and its effect.

Operational shock

A provider fails.

Services, critical functions and recovery objectives affected, hour by hour, with the fallbacks that hold and the exit plans that are missing.

Payments · RTO 2 h exceeded
Treasury · fallback C-006 activated
Lending · no fallback
Regulatory shock

A rule changes.

Arrangements to amend or to upgrade at renewal, providers and critical functions concerned, controls to redo, effort and time left before application.

12arrangements to review
8amendments likely
23 destimated effort
102 dto application
Decision on record

DEC-01 · Exit plan for C-006

Options, choice, justification, owner and re-examination date, approved by a second reviewer, re-opened automatically when a linked item changes.

Approved · four eyes
C-002 exit strategy · No → Yes
Arrangements without exit plan · 4 → 3
Resilience gained

Prove what each decision changed.

Key indicators tracked over time, and for every approved decision, the state of linked items before and after. The answer to the 41% of CISOs who cannot link remediation to risk reduction.

Critical functions without fallback4 → 3
Arrangements without exit strategy4 → 3
Blocking register anomalies7 → 6
Decisions with a measured effect1 / 1

Illustrative data.

DORA compliance software, rethought Not another compliance dashboard.

VigieObs connects regulatory requirements to operational reality.

Traditional compliance workflow
Requirement↓Control↓Assessment↓Finding

A checklist. The organization behind it stays invisible.

VigieObs
Regulation→Critical function→Dependency→Provider→Contract→Scenario→Test→Evidence→Finding→Remediation→Decision

A living model of how the organization actually operates, and of what it can prove.

05 · Test · Digital operational resilience testing Resilience is not a statement. It's something you test.

VigieObs connects scenarios to the actual functions, dependencies and providers, then tracks the tests, findings and remediation that follow.

PLANCOLLECTTESTCONCLUDEFINDREMEDIATERE-EXAMINESEAL

06 · Prove · Audit trail and evidence management Every decision has a trail.

Every conclusion remains connected to the evidence and operational data behind it.

SOURCE DATA→EVIDENCE→TEST→FINDING→RISK→RECOMMENDATION→DECISION
Finding CST-01MAJOR
No tested exit strategy for the core hosting provider.
C-006P07F01EV-042
Evidence available✓
RemediationRM-018
StatusIn progress
ILLUSTRATIVE DATA

AI for DORA compliance, under human control AI prepares. Humans decide.

Intelligent agents accelerate resilience work without taking control away from the people accountable for the decision.

OBSERVE

Signals, anomalies and changes, from identifiers to new rules.

ANALYZE

Dependencies, exposure and impact across functions and providers.

SIMULATE

Extreme but plausible disruptions on your own model.

PREPARE

Tests, evidence requests, reports and options, with sources cited.

Recommendations are grounded in the VigieObs operational model and remain subject to human validation.

DORA compliance for banks, insurers and financial institutionsWhy financial institutions choose VigieObs.

Built for DORA, designed beyond it. Each framework runs on the same operational model, so the work you do once counts everywhere it applies.

DORARegulation (EU) 2022/2554

Master DORA with evidence behind every figure.

Every deliverable prepared from the data, with the trail behind it.

  • Register of information checked against EBA rules
  • Contracts read against Article 30, sentence by sentence
  • Audit programme, findings and review report
See the register checks
Third partiesEBA/GL/2026/09

One lifecycle for every provider.

ICT under DORA, non-ICT under the EBA guidelines, in one lifecycle.

  • Due diligence and periodic review checklists
  • Minimum contractual clauses, ICT and non-ICT
  • External security ratings tied to critical functions
See a provider failure
NIS2 · Cyber resilienceDirective (EU) 2022/2555

Reuse your DORA work for NIS2.

For entities outside DORA, measures pre-filled from DORA and ISO 27001.

  • Suggestions from DORA, to approve
  • ISO 27001 statement of applicability import
  • Plain-language guide for every measure
Read the FAQ
CPMI-IOSCOMarket infrastructures

Cyber resilience for market infrastructures.

Extreme but plausible scenarios and two-hour resumption, mapped to the CPMI-IOSCO texts.

  • Scenario library on your own dependencies
  • Two-hour recovery benchmark
  • Non-binding texts, tracked to their final version
See the scenarios
AI dependenciesDORA, Articles 28 to 30

Your AI providers are ICT providers.

Which critical functions rely on a model, and what happens if it fails.

  • AI services in the register
  • Concentration on AI providers
  • AI provider failure scenario
Simulate an AI outage

VigieObs supports the people accountable for compliance; it does not certify it. Summaries and mappings are prepared by VigieObs and linked to the official texts.

DORA register of information · EBA submission Your register, checked before the supervisor checks it.

VigieObs checks the register of information continuously as the data changes, detects the anomalies that would get it rejected, and generates the official submission package, validated against the EBA's own rules.

01 · Detect anomalies

Invalid LEIs, duplicates, broken links, missing exit strategies, one provider under several names, EU critical providers.

02 · Read the contracts

Article 30 requirements extracted, every value cited, contradictions with the register flagged.

03 · Submit without rejection

The EBA package, run through its own validation rules: rejections known before you file.

04 · Keep entities accountable

Each anomaly assigned to its owner, with a deadline; corrections reviewed before they land.

REGISTER CHECKS5 BLOCKING · 12 WARNINGS
Invalid LEI: wrong check digits (ISO 17442)Entities · E04 · owner: Insurance subsidiary
No exit strategy for a service supporting a critical functionContracts · C-002 · DORA Art. 28
Identifier C-006 duplicatedContracts · uniqueness
Same LEI as P01: one provider under two namesProviders · P05 · concentration
Provider on the EU critical ICT provider listProviders · P08 · to track
OFFICIAL SUBMISSION PACKAGE · EBA RULESLIKELY REJECTION
5rejections
12quality errors
38warnings
ILLUSTRATIVE DATA

Operational resilience platformOne operational model. Every resilience workflow.

Your register, always ready to file.

Import the entities' files or last year's EBA package; VigieObs rebuilds the four tables with their links, flags every anomaly and assigns it to the entity that owns it.

  • Import from Excel, CSV or the EBA package
  • Anomalies assigned and followed up
  • Official package generated and checked
VigieObs · RegisterILLUSTRATIVE DATA
C-002No exit strategy · critical function
E04Invalid LEI check digits
P05Same LEI as P01: one provider, two names
Package5 rejections · 12 quality errors

Built for the people accountable for resilience.

Chief Risk · Resilience
See where operational exposure actually sits.
Internal Audit
Connect tests, findings, evidence and conclusions.
ICT · Third-party risk
Understand dependencies, providers, contracts and concentration.
CISO · Security
Show the board what each decision changed.

The moat is not the model. It's the operational context.

Generic AI can generate text. VigieObs knows what the text is about, which operational object it refers to, what evidence supports it, what changed, what remains unresolved and what decision follows.

This is where enterprise AI value is moving: governed context graphs that ground agents in reality. VigieObs builds that context for digital operational resilience, from risk to decision.

VigieObs
OPERATIONS
Dependencies
Providers
Contracts
Functions
EVIDENCE
Tests
Findings
Reports
Remediation
DECISIONS
Options and choices
Four-eyes approvals
Measured effects
Audit trail
Resilience context graph · versioned texts · deterministic propagation

From risk to resilience to decision.

See.

Understand your dependencies, and what breaks when a provider fails or a rule changes.

Decide.

Choose with the evidence in front of you, approve with four eyes, re-examine when reality changes.

Prove.

Show what each decision changed, with a trail an inspector can follow.

For investorsBuilding the context layer for digital operational resilience.

DORA is the entry point: mandatory, recurring and audited. The engine underneath is a governed context graph that every resilience framework, and every AI agent, can rely on.

Why now

DORA has applied since January 2025, with an annual register of information and supervision now in its control phase. The EBA's new third-party guidelines extend the register to non-ICT services. Leaders carry personal accountability for resilience, third parties and AI.

Product

One operational model for DORA, the EBA third-party guidelines, NIS2, CPMI-IOSCO and AI dependencies, with ISO 27001 imports. Two shocks in one graph, decisions on record, and measured resilience gained.

Moat

The operational context: functions, providers, contracts, versioned texts, evidence, decisions and their effects, linked and kept current. Propagation is deterministic and auditable; AI prepares, humans decide.

Business model

Annual subscription per group, scaled by entities; licences for audit and advisory firms per engagement; additional frameworks as packs on the same engine.

Roadmap

Regulatory change impact from official sources; a context server so agents such as Claude or Copilot ground their answers in VigieObs; a dedicated AI governance product line once validated with clients.

Stage

A working product covering DORA, the EBA third-party guidelines, NIS2, CPMI-IOSCO and AI dependencies. Now opening design-partner pilots with financial institutions.

Request the investor deck

DORA compliance FAQQuestions financial institutions ask about DORA.

What is DORA?

DORA, the Digital Operational Resilience Act (Regulation (EU) 2022/2554), sets common rules for ICT risk management, ICT-related incident reporting, digital operational resilience testing and ICT third-party risk for financial entities in the European Union. It has applied since 17 January 2025.

What is the DORA register of information?

It is the register of all contractual arrangements with ICT third-party service providers that financial entities must maintain at entity, sub-consolidated and consolidated level. Its templates are set by Implementing Regulation (EU) 2024/2956, and it is submitted to the competent authority, which passes it on to the European Supervisory Authorities.

How do I avoid a rejected register of information submission?

Check the register before filing against the EBA reporting format and validation rules: identifiers such as LEI codes, mandatory fields, references between templates, code lists and file structure. VigieObs runs these checks continuously and generates the submission package so that rejections, quality errors and warnings are known in advance.

What are the DORA Article 30 contractual requirements?

Article 30 of DORA lists the key provisions that contracts with ICT third-party service providers must contain, such as service descriptions, data locations, service levels, audit and access rights, termination rights and, for critical or important functions, exit strategies. VigieObs reads contracts, extracts these provisions and cites the exact clause.

What is the ICT risk management framework review report?

Financial entities must review their ICT risk management framework at least yearly and after major incidents or supervisory findings, and document the review in a report. Its content is set by Article 27 of Delegated Regulation (EU) 2024/1774. VigieObs prepares the report from the review file and seals it.

How does VigieObs map ICT third-party dependencies and concentration risk?

VigieObs links critical or important functions to ICT services, providers and contracts in one resilience graph. It shows which functions depend on a single provider, where several providers belong to the same group, and what happens to recovery objectives when a provider fails.

How does VigieObs measure the impact of a regulatory change?

Official texts are versioned. When a paragraph changes, VigieObs propagates the change through everything that depends on it: arrangements and providers, critical functions, audit tests, findings, review report sections and register data. It shows which contracts need an amendment before the application date or can be upgraded at renewal, and estimates the effort with assumptions you can adjust.

How does VigieObs record decisions and measure their effect?

Each decision is an object: options, choice, justification, owner and re-examination date, linked to the providers, arrangements, functions or texts concerned and approved by a second reviewer. VigieObs then tracks key indicators over time and shows what changed on the linked items after the decision.

Does VigieObs certify DORA compliance?

No. VigieObs supports the people accountable for compliance: it prepares, checks and traces the work, and every conclusion remains a human decision. Compliance is assessed by the financial entity, its auditors and its supervisors.

How is AI used in VigieObs?

AI reads contracts, pre-assesses audit tests and drafts reports, always citing the evidence it relies on. Sensitive data is masked before any request, every exchange is logged, and nothing is applied without human validation.

See what can break · Know what matters · Prove you're ready

Know your resilience before the incident tests it.

Build a living view of your critical functions, providers, evidence and decisions, and prove what each decision changed.

See VigieObs in actionRequest a resilience assessment

ContactTalk to us.

A demonstration on your own questions, a pilot, a partnership for your audit engagements, or an investor conversation: tell us what you need and we will come back to you within two business days.

ClientsDemonstration, pilot, resilience assessment
Audit firmsLicences per engagement, partnership
InvestorsInvestor deck and product roadmap