DORA (Reg (EU) 2022/2554)
article-level, incl. ICT third-party risk (Art. 28)
The whole EU financial-regulation stack at article level — including the technical standards everyone else skips.
Ansvar is a gateway for the AI assistant your team already uses — Claude, Microsoft Copilot, any MCP client. Connect it, and every answer below comes back cited to the provision or marked unresolved.
Financial regulation research, plan access and agent prompts
Financial services is the deepest regulatory corpus behind the gateway. DORA, MiCA, PSD2, MiFID II, CRR/CRD, Solvency II and EMIR are all addressable article by article — and DORA's eleven RTS/ITS technical standards are each a searchable scope, not a footnote. Under the EU layer sit the national regulators' rulebooks for every EU-27 member state plus EFTA and the UK, and the ECB's own legal acts and Banking Supervision material; across the Atlantic, US federal banking (12 CFR) and securities (17 CFR) regulation is served from the eCFR. Ask a question, get the provision; then run the gap analysis that turns it into a supervisor-ready register.
DORA (Reg (EU) 2022/2554)
article-level, incl. ICT third-party risk (Art. 28)
DORA RTS/ITS — 11 technical-standard instruments
ICT-risk, subcontracting, incident reporting, TLPT, register of information — each a searchable scope
MiCA (Reg (EU) 2023/1114) + RTS/ITS
PSD2 (Dir (EU) 2015/2366)
incl. strong customer authentication (Art. 97)
MiFID II / MiFIR · CRR/CRD · Solvency II · EMIR
article-level
National financial rulebooks — EU-27, EFTA and the UK
the national regulators' rulebooks under the EU layer, attributed per provision to the state that issued them (Sweden's Finansinspektionen FFFS among them)
European Central Bank — legal acts, opinions and Banking Supervision material
ECB legal acts in force and opinions on draft EU and national legislation, plus the English-language ECB and Banking Supervision guides, consultations, supervisory sanctions and cyber-resilience and payments-oversight material
EIOPA insurance and Solvency II material
published by the European Insurance and Occupational Pensions Authority under its reuse notice
US federal financial regulation — 12 CFR banking · 17 CFR SEC
served verbatim from the eCFR, incl. the Regulation S-K cyber-disclosure rules
US agency guidance — SEC cyber-disclosure interpretations · FTC data-security guidance
the SEC staff C&DIs on Form 8-K Item 1.05 and Regulation S-K Item 106, and the FTC business guidance on GLBA Safeguards, the Red Flags Rule and breach notification
Horizontal: GDPR · NIS2 · EU AI Act · eIDAS2
NIST SP 800-53r5 — served as full text
the US federal control catalog itself, cited per control; US public domain
Control mapping: ISO 27001 Annex A
requirement mapping + cross-references — the ISO 27001 text itself is available only as the SIS-licensed add-on (/standards)
Case law · agency guidance · preparatory works
inside search on Premium and above
DORA gap analysis
scoped across DORA and its RTS/ITS, with a cited gap register and export
ICT third-party-risk mapping
register of information (Art. 28(3)), exit strategy (Art. 28(8)), subcontracting RTS — assembled from gap analysis + cited document review
NIS2 gap analysis & ISO 27001 control mapping
for financial entities in scope of NIS2
STRIDE threat model
of payment, core-banking or trading systems
DPIA — GDPR Art. 35
for customer-data and payment processing
Document review, paragraph-cited
ICT outsourcing / cloud contracts against DORA, MiFID II and PSD2
Effective-risk CVE rescoring
re-rank ICT-asset vulnerabilities with NVD / CISA KEV / EPSS context for DORA ICT-risk management
STRIDE threat-model workflows run on every plan against a system you describe — 1 run a month on Free, 2 on Solo, 5 on Premium, which also adds the LINDDUN and TARA families, the rendered reports, and case law inside the run. Document-grounded workflows run on Team and Company. Every tier runs the same corpora as cited research inside your own AI client.
Connect the AI client you already use and ask your first cited question — Free, Solo, Premium and Team are self-serve.
Building financial compliance? It works today — we take on a few design partners per sector to tune it to your team.