Skip to content

About DORA Validation

DORA Validation is two things: a free diagnostic that checks a Register of Information in your browser, and a paid engagement that builds a register from the ICT contracts an entity already holds. This page describes how both work, what they rest on, and where they stop.

What the validator does

You open a register — an Excel workbook, or a single template as CSV — and it is read and checked in the page you are looking at. The findings name the template, the row, the DPM code the regulator’s feedback will use, the rule that fired, and the published document that rule is grounded in.

There is no account, no upload and no processing queue, because there is no server involved. The file does not travel.

Why “in your browser” is a fact rather than a promise

The validation engine is a separate package with no access to the network, the DOM, or any Node API. That is not a convention: a lint rule bans those imports inside it, and the build fails if one appears.

The site loads no analytics, no tag manager, no advertising pixel and no externally hosted script or font. Its Content-Security-Policy blocks requests to any other origin, so a third-party tracker could not load even if one were added by mistake.

What it is grounded in

The rules are built against the EBA’s published material for Register of Information reporting: the validation-rule list, the filing rules, the reporting-package guidance, the DPM dictionary and the ESA reporting template. Each document is recorded with its version and checksum before anything is built from it.

Every external statement on this site is registered with the source it rests on and the date that source was last checked. Statements that could not be traced to a document are not rendered at all, which is why you will occasionally see a caveat here where a competitor would show a number.

What it does not claim

The validator implements a subset of the published checks, and says so under every result. A clean result means the rules that ran found nothing — not that a submission will be accepted.

Identifier checking is offline. It proves a code is well formed, not that it was ever issued or is still active, and several published checks require exactly that. This is a deliberate consequence of never sending your register anywhere.

It is an independent tool. It is not endorsed by, affiliated with, or approved by any supervisory authority, and nothing here should be read as advice about how a particular authority will treat a particular filing.

How the engagement works

We read the ICT contractual arrangements you already hold, make the classification decisions the register turns on, and hand you the completed register, the record of every decision behind it, and a memo for the people who carry responsibility for the filing. It is priced per contractual arrangement rather than per entity, because the classification work is done once and applied — which is why a second register costs a fraction of the first.

Before it is handed over, the register is put through our own validation. That is the same subset of published checks described above, not a guarantee of acceptance, and the engagement makes no claim beyond it.

A separate, narrower engagement exists for a register that has already been rejected: it starts from the error code you received rather than from your contracts.

Who does this work

Konan H. Kouakou

Operational risk and DORA compliance specialist, working on contract.

DORA Validation is the practice of one person rather than a firm, and this section exists because a compliance tool that names nobody is asking for more trust than it has offered. The work behind it is not primarily software: since 2007 it has been the operations of funds, custodians and asset managers — fund accounting and NAV production for institutional and hedge fund clients, performance and attribution, settlement and middle-office control, and the investment-restriction and data-governance platforms those functions run on.

The second half is the risk side of the same industry: operational risk frameworks and their control testing, key risk indicators and the reporting that hangs off them, vendor and ICT third-party assessment with the due-diligence and concentration questions that go with it, and information systems audit. That is the pairing a Register of Information actually asks for. It is a risk classification of arrangements that live in procurement, legal and vendor-management systems, and it is graded by a supervisor — so it needs someone who has produced fund operations data and someone who has been audited on it, which here is the same person.

What that does not include is legal advice. The judgements this site says are yours to make — criticality, substitutability, whether a function is critical or important — are yours because the responsibility is, not because they are hard.

Professional certifications

Certified Information Systems Auditor (CISA)
ISACA, 2019
Canadian Securities Course (CSC)
Canadian Securities Institute, 2015

Education

Master’s degree, Economics and Management
Université Paris 1 Panthéon-Sorbonne, 2006
Diploma, Advanced Web Development
Dublin Business School, 2009

Working languages. French (native) and English (bilingual professional proficiency), which is why this site exists in both.

Professional profile. Konan H. Kouakou (opens in a new tab). The career history behind those categories, employer by employer, is on the profile rather than on this page.

This is a consulting practice, not a regulated firm. It holds no authorisation from any supervisory authority, does not provide legal advice, and does not file on a client’s behalf. Naming a person and a certification says who did the work; it does not make the work supervised.

Not yet published here

This practice has no registered legal entity, so there is no company name, no registered address and no VAT number to publish, and none appears in this site’s structured data either. There is also no direct email or telephone address here by choice: the contact form is the way to reach us. What is above is what can be checked — a name, two certifications with the bodies that issued them, and two qualifications with their institutions. We would rather name the gap than fill it with something you cannot check, which is the same standard the rest of this site is held to.