DORA Compliance: Inside a Fireblocks Pooled Audit
An internal auditor from Boerse Stuttgart Digital explains how a Fireblocks-hosted pooled audit helped meet DORA's third-party ICT requirements. Instead of every customer auditing Fireblocks one by one, the pooled audit community joined forces on a single common audit: shared scope, shared evidence, shared result. In this conversation, the pooled audit coordinator walks through how the community set the scope, why a pooled audit covers customer-specific requirements that a standard SOC 2 might miss, and how Fireblocks supported the process with subject matter experts, documentation, and on-site coordination. If you're a CASP, treasury team, or compliance lead working through your DORA obligations for critical or important ICT providers, this breaks down what a pooled audit actually looks like in practice.
Chapters:
0:00 Meet the pooled audit coordinator
0:51 What a pooled audit is, in plain terms
1:40 Why DORA requires auditing critical ICT providers
2:11 Pooled audit vs. a standard SOC 2
2:54 How Fireblocks supported the audit
4:00 The scoping-driven approach
5:20 Scope, ownership, and shared results
Learn more about the Fireblocks Cyber & Operational Resilience (COR) Compliance Package: https://www.fireblocks.com/fireblocks-cyber-operational-resilience-cor-compliance-package
Have DORA obligations to validate against a third-party ICT provider? Explore the COR package or contact the Fireblocks team using the link above.
#DORA #DigitalAssets #Compliance #CryptoCustody #Fireblocks