Mapped-only regimes (DORA and EBA)¶
opencomplai gaps --map-to DORA|EBA adds one column per regime to the EU AI Act gap table, and a mapped_regimes block to the JSON output. Each cell is a citation: the DORA chapter or EBA guideline that covers similar subject matter to that EU AI Act article.
What "mapped only" means¶
- It is a pointer, not a verdict. No Met, Partial, Missing or Unverified status is computed for DORA or EBA, and the statuses of the EU AI Act rows are identical with and without
--map-to. - DORA and EBA are not compliance targets.
--target DORAstill exits 2, and no probe, evaluator or control is attached to these rows. - Without
--map-tothe output is byte-identical to before.
The review flag¶
Every row carries confidence: "low" and needs_founder_review: true, plus a source. The identifiers (chapter and article ranges, EBA guideline numbers) were written from general knowledge and have not been checked against the primary texts; confirm them before relying on a row. A row that cannot be defended is left out rather than guessed.
Rows¶
| EU AI Act article | DORA | EBA |
|---|---|---|
| Art. 9 | Chapter II (ICT risk management) | |
| Art. 10 | EBA/GL/2020/06 (loan origination and monitoring) | |
| Art. 12 | Chapter III (ICT-related incident management) | |
| Art. 15 | Chapter IV (resilience testing) | EBA/GL/2019/04 (ICT and security risk management) |
| Art. 17 | Chapter II (ICT risk management) | |
| Art. 24 | Chapter V (ICT third-party risk) | |
| Art. 25 | Chapter V (ICT third-party risk) | EBA/GL/2019/02 (outsourcing arrangements) |
Not covered¶
- Art. 47 and Art. 48: no counterpart identified.
- Serious-incident reporting (Arts 72/73): not in the control catalog, so no DORA incident-reporting row can key on it.
The data lives in mapped_regimes.json, separate from framework_crosswalk.json. This page is not legal advice.