Classify an AI system by risk class according to your role as provider, importer or deployer — with the prohibited practices of Article 5, the Annex III categories and the obligations that already apply versus those that come later — and at the same time assess your DORA readiness across the five pillars, with the supervisor that goes with your entity type.
The same AI application produces very different obligations depending on your role. A provider must set up a risk management system, produce technical documentation and demonstrate conformity; a deployer must above all organise human oversight, keep logs and inform affected persons; an importer sits in between. The check lists those obligations by role and risk class, separating what already applies from what starts later.
On the DORA side the question is different: not classification but readiness. The five pillars — ICT risk management, incident reporting, testing, third-party risk and information sharing — are assessed one by one, with the requirement, the follow-up action and the deadline. Two of them carry the flag that they are most often missed in practice. Every report records your answers, the tool version and the dataset vintage, so a reassessment a quarter from now is directly comparable with this one.