Not being the person personally on the hook when the supervisor asks
Art. 5(1) DORA, Art. 20 NIS2 and Art. 5(2) GDPR put accountability for compliance on the management body — and NIS2 lets member states hold managers personally liable. The protection is not a binder of policies but a record: what was checked, against which article, by whom, when, and what was decided about the gaps. Audomate produces that record as a by-product of the work you do anyway.
Accountability is written into the rules
Art. 5 DORA: the management body “bears the ultimate responsibility”. Art. 20 NIS2: management approves the measures, oversees them and can be held liable. Art. 5(2) GDPR: the controller has to be able to demonstrate compliance.
“We had a policy” is not a defence
The supervisor asks what was assessed, when, and what the board did about the findings. A dated audit trail answers that; a folder of PDFs does not.
The decisions about gaps matter most
Accepting a risk is allowed; being unaware of it is not. Audomate records who accepted what, and with which compensating control.
Readable by the board, ready for the supervisor
One report per regulation: status, open items, decisions, dates. Ten minutes to read; defensible in an inspection.
What the supervisor will ask
- When did you last assess ICT risk / your processing activities / your security measures? Against which requirements?
- What did the assessment show, and what did the board decide about each finding?
- Who was responsible for each remediation action, and when was completion verified?
- How do you know the assessment reflects the current version of the rules?
- Where is the evidence?
What the record in Audomate contains
| Element | How it is produced |
|---|---|
| Assessment date and framework version | Every audit run is stamped with the version of the regulation it checked against |
| Findings with citations | An article and a page for each; ungrounded findings marked “for review”, never asserted |
| Decisions about gaps | Fix, accept with a compensating control, or out of scope — each with a person and a date |
| Remediation trail | Drafts accepted, documents re-audited, requirement re-verified |
| Board report | Generated per regulation; the same document, redacted if needed, for the supervisor |
| Verification page (coming soon) | A public statement of scope, date and validity |
For the person who signs
Whether you are the CEO of a software house, the DPO at a SaaS company or the board member responsible for ICT at an insurer, the question is the same: can you show, as at a given date, that you knew where you stood and acted reasonably? Audomate is built so that the answer is a report you already have, rather than a reconstruction after the letter arrives.
Questions we get most often
Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.
Reach this outcome in four weeks
One regulation, your real documents, a cited gap list and remediation drafts — plus a verified mark if you pass.