Back to Blog

Case Study

Case Study: From Bottleneck to Solved for DORA Vendor Review

A Danish GP implemented specialized AI agents to automate vendor contract review for DORA compliance, reducing several weeks of manual work to a single day while establishing a repeatable, auditable process.

Alexander Rønfeldt• Operations Lead
November 12, 2025
5 min read

A Danish General Partner (GP) implemented specialized AI agents to automate vendor contract review for DORA compliance, reducing several weeks of manual work to a single day while establishing a repeatable, auditable process.

The Challenge

DORA compliance requires financial institutions to verify that every vendor contract includes specific Information and Communication Technology (ICT) requirements. The GP faced several obstacles:

  • Different requirements applied based on vendor criticality tiers (1, 2, or 3)
  • Contracts often spanned multiple documents including master agreements, addenda, and Data Protection Agreements
  • Requirements needed consistent interpretation across all vendors
  • Findings had to be actionable and auditable

The initial plan to assign an analyst for manual review proved impractical when estimates showed the work would require several weeks.

The Solution: 15 Specialized AI Agents

Rather than manual review, the organization built a system of 15 LLM-powered agents, each focused on a specific task:

Agents 1-13: Requirement Specialists Each agent evaluated contracts against one specific DORA requirement (for example, Agent #4 verified data access and recovery provisions).

Agent 14: The Synthesizer Consolidated outputs from all specialist agents into unified compliance assessments per vendor.

Agent 15: The Communicator Drafted vendor-facing emails translating technical findings into clear amendment requests.

How Agents Evaluated Contracts

Each agent provided binary, transparent feedback with specific textual references:

Example - Requirement Met: Agents confirmed when contracts included explicit commitments on data access, recovery, and export upon termination or insolvency.

Example - Requirement Unmet: Agents flagged when provisions existed but lacked specific protections, such as missing data integrity commitments.

Key Implementation Insights

Vendor Tiering Matters Tailoring requirements to vendor criticality ensured appropriate focus levels for different provider categories.

Independence Enables Flexibility Individual agents could be updated independently when regulatory guidance evolved, avoiding complete system rebuilds.

Context Is Crucial Agents evaluated entire document sets rather than isolated files, recognizing that compliance clauses often appear across multiple documents.

Practical Takeaways for DORA Implementation

  • Define precisely what DORA requirements mean within your specific organization before automating
  • Build systems within existing tools to minimize training and accelerate adoption
  • Design modular, updatable systems accommodating evolving regulatory interpretation
  • Maintain human oversight for remediation priorities and vendor negotiations

Beyond DORA

This agent-based architecture extends to other compliance evaluations including annual audit reviews (SOC 2, ISO standards) and risk assessment documentation reviews.

Conclusion

The approach transformed an overwhelming process into a structured, repeatable, auditable system demonstrating how specialized AI agents can address discrete, well-defined compliance requirements across multiple documents and scenarios.


Interested in how FundFrame approaches compliance and operational efficiency? Contact us to discuss your specific needs.

Bring the ideas in this post to your own portfolio.

Book Demo