Compliance Assistant
Track, manage, and investigate EU DORA compliance posture using real-time observability and security insights from the Dynatrace Compliance Assistant app.
Critical Disclaimer
The Dynatrace compliance score and all outputs from Compliance Assistant are indicative metrics based on real-time observability data and automated systems. They do not replace comprehensive or formal compliance assessments and do not constitute a legal determination of a company's compliance status under EU DORA or any other regulation.
Never claim that a score, tier, or Compliance Assistant output means an organization is legally compliant or non-compliant with EU DORA. Always present results as operational indicators to support remediation decisions, not as legal or regulatory verdicts.
When to Use This Skill
✅ Use for:
- EU DORA compliance posture, compliance score, compliance snapshot, score tier
- Critical or Important Functions (CIFs): health, KPI monitoring, impact analysis, setup questions
- Incident lifecycle under DORA: unclassified problems, potential major incidents, classified major incidents
- ICT risk inputs: vulnerabilities, security detection findings, misconfigurations (ICT asset configuration results)
- Incident classification under EU DORA: materiality thresholds, duration criteria, economic impact
- DQL queries for
compliance.incidentbizevents, CIF health, or unclassified problems on CIFs - Onboarding, permissions, and settings for Compliance Assistant
❌ Do not use for:
- Regulatory frameworks other than EU DORA — SOC2, PCI-DSS, HIPAA, ISO 27001 are not supported by this app
- Generic Davis problems with no DORA, CIF, or compliance context → use
dt-obs-problems - Generic vulnerability or security finding queries not scoped to compliance or DORA → use application security skills
- Generic "score" queries without "compliance" or "DORA" — Dynatrace has many scores
- Configuring Business Flow or defining business process steps → see Business Flow documentation
- Configuring Security Posture Management rules → see SPM documentation
- General DQL syntax help → use
dt-dql-essentials
Prerequisites
Installation
Install Compliance Assistant from Dynatrace Hub.
Required Permissions
Required Data Sources
Core Concepts
Compliance Framework
Compliance Assistant currently supports EU DORA (Digital Operational Resilience Act) only. It consolidates observability and security insights into a single compliance posture view for this framework. Support for additional frameworks is planned.
Dynatrace Score (Compliance Snapshot)
A real-time, tiered score summarizing current ICT risk posture across potential incidents, security detection findings, vulnerabilities, and misconfigurations. The score tier is determined by the most severe active condition; within a tier, the score is reduced by a penalty for each criterion met.
Score tiers:
Penalty mechanic: Within a tier, score = tier max − (6 × number of criteria met in that tier). For example, Medium tier with 2 criteria met: 79 − 12 = 67.
This score is a high-level operational indicator. It does not confirm regulatory compliance or legal status.
Critical or Important Functions (CIFs)
Under EU DORA, financial entities must identify and monitor business functions that, if disrupted, could significantly impact financial performance or service continuity. In Compliance Assistant, CIFs are configured by linking Business Flow business processes to the DORA framework. Smartscape on Grail provides end-to-end visibility by linking each CIF to its underlying IT components.
Incident Lifecycle
Davis-detected problems affecting CIF business processes move through three states:
EU DORA materiality thresholds monitored:
Classification is always a manual step performed in the Compliance Assistant app. Do not classify incidents on behalf of the user.
Once classified, the generated compliance.incident bizevent can trigger automations via Dynatrace Workflows (e.g., creating a ServiceNow incident or Jira ticket enriched with compliance impact details).
ICT Risk Inputs
DQL Reference
Classified Major Incidents
Fetch compliance.incident bizevents generated when an incident is classified as major. To retrieve a specific incident, filter by problem.event.id.
To fetch all classified incidents:
Key fields (see Semantic Dictionary for the full schema):
Unclassified Problems and Potential Major Incidents on CIFs
Finds Davis problems affecting CIFs that have no matching compliance.incident bizevent — i.e., problems not yet manually classified. The isNull(lookup.event.id) anti-join is the key pattern.
Notes:
- Source is
dt.davis.problems, notbizevents filter isNull(lookup.event.id)identifies problems with no classified incident bizeventin(nodes.bizflow.id, {...})restricts to problems whose Smartscape graph touches a configured CIF (BIZ_FLOWnode)- Replace
{{.cif_id_1}},{{.cif_id_2}}with actual Business Flow entity IDs from the DORA framework settings in Compliance Assistant - For a single CIF, use
| filter nodes.bizflow.id == "{{.cif_id}}"
CIF Health (Business Flow KPIs)
Fetches the latest KPI snapshot per CIF. KPI data is emitted by Business Flow (event.type == "bizflow.kpis"), not by Compliance Assistant directly.
Notes:
- Returns one row per CIF;
fulfillmentanderrorsare the latest sampled KPI values analysisLabeldescribes whatfulfillmentmeans for that flow (e.g., "Successful logins")timeframeandfrequencyreflect the Business Flow's own configured query window- For a single CIF use
| filter bizflow.id == "<id>"; for multiple CIFs extend with additionalor bizflow.id == "<id>"clauses - If data is missing, check the Business Flow monitoring frequency and evaluation timeframe (see FAQ)
Common Workflows
Check the Compliance Score
- Confirm the user is asking about DORA — currently the only supported framework
- Explain the current tier using the score tier table in Core Concepts
- Remind the user the score is an operational indicator, not a legal compliance determination
- If the score is degraded, identify which signal types are contributing (incidents, security detection findings, vulnerabilities, misconfigurations)
- Guide remediation using Improving the Compliance Score
Investigate an Incident
- Confirm whether the user is asking about a classified incident (has a
compliance.incidentbizevent) or an unclassified/potential major problem - For classified incidents: run the classified incidents DQL query, filter by
problem.event.idif a specific incident is referenced - For unclassified/potential major: run the unclassified problems query scoped to the relevant CIF IDs
- Surface the materiality threshold breach status:
compliance.incident.duration_criteria,compliance.incident.economic_impact_criteria,compliance.cifs_impacted.* - Do not classify an incident on behalf of the user — classification is a manual step performed in the Compliance Assistant app
Review CIF Health
- Identify the CIF's Business Flow ID from the DORA framework settings in Compliance Assistant
- Run the CIF health query with the relevant
bizflow.idvalues - Surface
fulfillment,errors, andanalysisLabelper CIF - If data is missing or stale, check the Business Flow monitoring frequency — see FAQ
Improving the Compliance Score
The Dynatrace score reflects current ICT risk posture in real time. To improve it:
- Address incidents promptly — resolve potential major incidents and unclassified problems affecting CIFs
- Remediate security detection findings and vulnerabilities — see Gain insights and How do I fix detected vulnerabilities?
- Fix ICT asset misconfigurations — see Stay compliant with Security Posture Management
- Ensure monitoring coverage — confirm that real-time protection and monitoring are enabled across all CIFs
Improving the score reduces observable ICT risk. It does not constitute formal compliance or legal readiness.
FAQ
How often are CIF insights updated in Compliance Assistant?
CIF KPI insights (fulfillment and errors) are updated based on the configured generation frequency of KPI monitoring in Business Flow. The evaluation timeframe is also defined per business flow configuration.
To ensure reliable KPI evaluation and avoid missing data from long-running processes, set the evaluation timeframe to at least 3–4× the process's average duration. For example, if a CIF's average duration is 5 minutes, set the evaluation window to at least 15–20 minutes.
Why are configured CIFs not updating?
If you have recently edited or added business processes configured as entities and selected them as CIFs in Compliance Assistant, it may take up to the maximum defined monitoring frequency for those business processes to be updated. Adjust the monitoring frequency in the business flow configuration to reduce the delay.


