DORA, the EU AI Act, and the
Decision Accounting

DORA, the EU AI Act, and the self-application problem

core-claim
Core claim

DORA and the AI Act both test whether the institution can reconstruct the decision record

The paper argues that financial regulators are asking for inspectable decision reconstruction, not scattered proof that policies, model files, contracts, and incident tickets exist. Decision Accounting answers with a 17-field record that makes each material decision the audit object.

collision
Regulatory collision

Financial AI creates one decision chain across model, ICT, vendor, and business files

The paper’s collision case is financial AI inside ICT-supported business functions. A credit scoring model can be an AI Act issue because it affects access to essential private services, and a DORA issue because it depends on ICT assets, data pipelines, providers, continuity plans, and incident controls.

theorem
Missing System Theorem

Bilateral payoff records cannot prove system welfare when resilience variables are missing

The theorem compares two decisions with identical recorded bilateral payoff matrices. One preserves vendor substitutability, tested recovery capacity, and human override capacity; the other creates single-provider concentration, untested recovery, and degraded override capacity. The payoffs match, but system welfare differs.

missing-system
Missing System Trap

A Hollow Win occurs when private revenue is positive and system welfare turns negative

The paper defines the bad equilibrium as the Missing System Trap: actors optimize over recorded private benefits while system-state variables remain unrecorded, non-owned, or non-auditable. The measurable failure case is a Hollow Win: Πd > 0 while ΔWd < 0.

da-fields
Decision Accounting fields

The Seventeen fields separate evidence, assumptions, outcomes, authority, and welfare

Decision Accounting makes the decision, not the document owner, the unit of record. The fields are identifier, timestamp, who, what, context, alternatives, criteria, evidence, assumptions, stakeholders, prediction, outcome, variance, review, authority, and system welfare.

formula
Master Formula

Field 17 records βΠ minus externalized burden and correction cost

The Master Formula is ΔWd = βdΠd - Ed - Cd. In the paper’s notation, Π is private revenue captured or protected, not profit; β is the conversion factor from private revenue to system welfare; E is externalized burden; and C is compliance, monitoring, and correction cost.

example
Cloud migration case

The same EUR 20M revenue claim flips from system-positive to system-negative when β falls

The paper’s simple cloud-migration example uses a bank expecting to protect EUR 20 million in annual revenue by reducing outage risk and preserving product continuity. With β=0.55, E=6M, and C=2M, ΔW is EUR 3M. When new evidence lowers β to 0.35, ΔW becomes EUR -1M.

dora-map
DORA map

The DORA claim spans governance, ICT risk, incidents, learning, and third-party controls

Proposition 1 says a complete Decision Accounting record satisfies the decision-documentation function of DORA Articles 5, 6, 8, 11, 13, 17, 18, 19, 28, and 30, subject to any required format, template, timing, or supervisory submission duty.

article-12-correction
DORA correction

Article 12 is backup and recovery, while Article 17 is the incident-record rule

The paper corrects a common shortcut: DORA Article 12 is not the main incident-record rule. Article 12 concerns backup policies, procedures, restoration, and recovery methods. Article 17 requires recording ICT-related incidents and significant cyber threats, and documenting and addressing root causes.

ai-act-map
AI Act map

The AI Act record must bind lifecycle risk, technical documentation, transparency, oversight, and deployer use

For high-risk AI systems, Proposition 2 maps Decision Accounting to Articles 9, 11, 13, 14, and 26. The paper treats Article 14 as an authority test: the human in Field 15 must have practical power to override, disregard, reverse, or stop the AI use.

self-app
Self-application

A Decision Accounting scorer becomes high-risk only when it enters an Annex III decision path

The paper resolves the self-application problem with a legal-function distinction. A tool that scores Decision Accounting record quality is not high-risk merely because it audits high-risk AI documentation. Classification changes when its intended purpose or actual use places it inside Article 6 and Annex III decisions about natural persons.

boundary
Policy boundary

Decision Accounting is a control architecture, not immunity from supervision or other law

The paper’s policy implication is narrow. Decision Accounting reduces documentation fragmentation only when the record names the flawed game, records the Missing System Trap, states revenue as Π, and preserves human authority over person-affecting uses.