All resources
Operations8 min read

Building a DORA-ready vendor onboarding process

Every missing field in a Register was once an onboarding step nobody owned. Fixing the intake process is cheaper than reconstructing data from procurement emails eighteen months later.

Marieke de Vries · Head of Regulatory Content

Capture identity and structure at intake

Legal name, registration number, LEI, country of incorporation, provider type and the group structure should be collected before anything else. These are the fields the Register needs and the ones nobody can supply later without contacting the vendor again.

Describe the service, not the software

Register entries are about ICT services: what is provided, which business function consumes it, what data it processes, where it is hosted and from which countries it is delivered. A product name is not enough to answer a supervisor.

Sequence the gates

A workable order puts classification before assessment depth, assessment before contract negotiation, and contract review before signature, with the Register entry created automatically from what was collected.

  • Intake: identity, service description, data and locations
  • Classification: function criticality and inherited service criticality
  • Assessment: depth matched to classification, evidence inline
  • Contract: clause review against the required set
  • Register: entry generated and validated, owner assigned

See how this works in the product.

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.