Insights · Cluster: Regulation & AI Governance

DORA and Your SDLC: The 5 Things Auditors Really Check

Valentin Mazareanu
Valentin Mazareanu Chief Information Security and Compliance Officer · LinkedIn · 3 min read · July 2026

DORA (the Digital Operational Resilience Act) has changed the way software development is assessed. During audits, the discussion rarely focuses on the wording of the regulation itself. Instead, auditors want to understand whether the Software Development Life Cycle (SDLC) consistently produces software that is governed, secure, traceable, and resilient. The difference between a mature organization and one that simply claims compliance is almost always found in the evidence generated throughout the development process.

Here are five areas that consistently receive the most attention during DORA-focused audits.

  1. Every Change Has a Clear Business Purpose. Auditors expect every production change to have a clear, documented business justification. A release should be traceable back to a defined requirement, an approved decision, and an understood impact on the business. If a team cannot explain why a change was introduced or who approved it, confidence in the entire change-management process quickly decreases. The focus is not the ticketing tool being used, but whether the organization can demonstrate governance over software changes from request to deployment.
  2. Security Is Part of Development, Not Just Testing. One of the biggest shifts under DORA is the expectation that security is embedded throughout the SDLC rather than added before release. Auditors look for evidence that secure development practices, code reviews, automated testing, and vulnerability management are integrated into everyday engineering activities. Organizations that treat security as a continuous development responsibility generally provide far stronger audit evidence than those relying solely on final-stage security testing.
  3. Every Release Can Be Fully Traced. Traceability is one of the strongest indicators of a mature software delivery process. Auditors frequently select a production release and ask the organization to demonstrate its complete journey — from business requirement through development, testing, approval, deployment, and operational monitoring. If that story can only be reconstructed from emails and meeting notes, it often reveals weaknesses in governance. Strong SDLC processes make this information readily available through integrated development and delivery tools.
  4. Emergency Changes Remain Exceptional. Auditors recognize that urgent production fixes are sometimes unavoidable; their concern is whether emergency changes remain controlled or gradually become the organization's standard delivery model. Frequent emergency deployments often indicate deeper issues with planning, testing, or release management. Mature organizations demonstrate that urgent changes follow defined approval paths and are reviewed afterwards to prevent similar situations from recurring.
  5. Compliance Evidence Is Generated Automatically. Perhaps the clearest sign of SDLC maturity is how audit evidence is produced. Organizations with well-designed development processes generate approvals, testing records, deployment logs, and security results automatically as part of normal work, rather than collecting documentation just before an audit. From an auditor's perspective, automated evidence is more reliable, easier to verify, and far more convincing than documentation assembled retrospectively.

Final Thoughts

DORA is not simply asking organizations to document secure software development; it expects them to demonstrate that governance, security, and resilience are embedded in the way software is built and delivered.

The most successful audits are rarely those with the largest set of policies, but those where the SDLC itself continuously produces the evidence needed to prove that effective controls are operating every day.
THE 5, ON YOUR SDLC

See where your evidence stands

Our Audit Readiness Checklist: AI in the SDLC turns these five checks into a self-assessment — before an examiner does.

Get the Audit Readiness Checklist
READ NEXT

From Regulation to Architecture: Designing Human Oversight for AI Systems

Read →
READ NEXT

AI in Regulated Software Delivery: DORA, EU AI Act, ISO & FINMA - The Complete Guide

Read →

Walk these questions through for your system?

30 minutes with the author or one of our senior engineers.

Book a conversation