DORA and Salesforce

Document your Salesforce org for DORA — and keep it current.

DORA asks EU financial entities to document their ICT assets, how they are configured and how they depend on each other — and to keep that documentation up to date. For the Salesforce org, aprity does the reading: objects, automations, business rules, dependencies and integrations, documented in business language from the metadata, refreshed whenever you re-scan.

Read-only access Metadata purged after each scan EU hosting in France Central
What DORA asks

What does DORA mean for a Salesforce org?

The Digital Operational Resilience Act — Regulation (EU) 2022/2554 — applies from 17 January 2025 (Article 64) to the financial entities listed in its Article 2(1), from credit institutions and payment institutions to investment firms and insurers. Its Article 8 asks those entities to identify, classify and adequately document their ICT-supported business functions and the information and ICT assets supporting them, to map the configuration of those assets and the links and interdependencies between them, and to keep the relevant inventories updated. When sales, service or onboarding runs on Salesforce, the org is one of those assets — and its configuration spans objects, automations and integrations that nobody holds in their head.

Source: Regulation (EU) 2022/2554 on EUR-Lex. This page is not legal advice.

Where aprity contributes

Four obligations, and the part aprity can support.

Each card quotes what the article asks, then says what aprity provides for the Salesforce org — and only that.

Article 8(1)

Identify and document

DORA asks: identify, classify and adequately document all ICT-supported business functions, roles and responsibilities, and the information assets and ICT assets supporting them — reviewed as needed and at least yearly.

aprity provides: the documentation of what the Salesforce org contains: objects and fields, automations, business rules and processes, in business language, with each business rule linked to the component it was read from.

Article 8(4)

Map configuration and interdependencies

DORA asks: map the configuration of the information assets and ICT assets and the links and interdependencies between them.

aprity provides: a dependency graph computed deterministically from the metadata, per-object execution graphs showing what runs on each save event, and impact analysis on any field, object or Apex class.

Articles 8(5) and 28(3)

Know your third-party dependencies

DORA asks: identify and document processes dependent on ICT third-party service providers (Art. 8(5)), and maintain a register of information on all contractual arrangements for ICT services from those providers (Art. 28(3)).

aprity provides: an integration map of the external systems the org calls and is called by, drawn from the Apex code's actual call-sites — an input you can check your register against. The register itself stays yours.

Article 8(6)

Keep inventories updated

DORA asks: maintain the relevant inventories and update them periodically and every time a major change occurs.

aprity provides: a re-scan you launch on demand, up to once a week, and a business-language diff of the business rules added, modified or removed between two scans.

How it works

Documentation built from the metadata, not from memory.

Dependencies and impact are computed deterministically from the metadata — reproducible and verifiable. The AI explains the result in business language; it never decides it.

Read-only extraction

A managed package and a read-only connected app using JWT Bearer authentication read metadata only — never your records. Nothing is written back.

Deterministic graph

Dependencies, impact and the execution graph are computed from the metadata — the same inputs always give the same answer.

Business-language documentation

Objects, rules, automations and integrations are explained in a secure web portal, current with every scan.

Explore the platformSee an example org
aprity as your ICT provider

A tool you will also have to assess — so here is what it does.

Metadata only

Structural metadata only — object definitions, field schemas, automation configuration. aprity does not access or store your business data.

Purged after every scan

Source metadata is deleted once the documentation is produced; only the derived documentation is retained.

EU residency

The data region is chosen at subscription — France Central (EU) or East US — and AI inference is routed exclusively through Microsoft Azure.

Financial-sector terms

ICT-provider assistance, audit rights and exit strategies for customers in the financial sector. aprity holds no ISO 27001, SOC 2 or HDS certification.

See security & trust
Scope

What aprity does not do for DORA.

  • It does not make you DORA compliant. Compliance is the financial entity's responsibility and spans governance, ICT risk management, incident reporting, testing and third-party risk.
  • It is not legal advice. Interpret your obligations with your compliance and legal teams.
  • It covers the Salesforce org only — not your other applications, infrastructure or networks.
  • It does not produce the Article 28(3) register of information. The integration map is an input; the register is yours.

If the same documentation has to serve an ISO 27001 or SOC 2 review, see how it supports a Salesforce org audit, and our guide to preparing a Salesforce org for an ISO 27001 audit. Before changing a component that supports a critical function, run an impact analysis.

Questions

DORA and Salesforce — FAQ

What is DORA?

DORA — the Digital Operational Resilience Act — is Regulation (EU) 2022/2554 of 14 December 2022 on digital operational resilience for the financial sector. It applies from 17 January 2025 to the financial entities listed in its Article 2(1), such as credit institutions, payment institutions, investment firms and insurance and reinsurance undertakings.

What does DORA Article 8 require for a CRM like Salesforce?

Article 8 asks financial entities to identify, classify and adequately document their ICT-supported business functions, roles and responsibilities, and the information assets and ICT assets supporting them; to map the configuration of those assets and the links and interdependencies between them; and to keep the relevant inventories updated periodically and whenever a major change occurs. A Salesforce org that supports business functions is one of those assets, and its configuration is what aprity documents.

Does aprity make us DORA compliant?

No. DORA compliance is the financial entity's responsibility and covers far more than one application — governance, ICT risk management, incident reporting, resilience testing and third-party risk. aprity produces and keeps current the documentation of your Salesforce org, which is one input to that work. Nothing on this page is legal advice.

Does aprity produce the DORA register of information?

No. Article 28(3) requires financial entities to maintain a register of information on all contractual arrangements for ICT services provided by ICT third-party service providers; that register is the entity's own. aprity's integration map shows which external systems your Salesforce org calls and receives calls from, which helps you check that the register covers the providers your CRM actually depends on.

How does aprity keep the documentation current?

You launch a re-scan on demand, up to once a week, and the portal reflects the org as it stands. A business-language diff shows which business rules were added, modified or removed between two scans, which helps you see what changed in the org between two dates.

What does aprity itself access, and where is it hosted?

The connector is read-only and reads metadata only — never the business data in your records. Raw metadata is purged after every scan; only the derived documentation is retained. The data residency region is chosen at subscription, France Central (EU) or East US, and AI inference is routed exclusively through Microsoft Azure. aprity does not hold ISO 27001, SOC 2 or HDS certification.

Document the CRM

Keep your Salesforce documentation as current as your org.

Free 14-day trial on your own org, activated after a quick review — usually within one business day. No credit card. Read-only access, and metadata is purged after every scan.

Keep exploring

Related