All resources
DORA Register9 min read

The DORA Register of Information: what supervisors actually expect

Every financial entity in scope of DORA maintains a Register of Information covering its contractual arrangements for ICT services, and submits it to its competent authority on request. The templates are prescriptive, the reference data is unforgiving, and most first submissions fail on structure rather than substance.

Marieke de Vries · Head of Regulatory Content

The Register is a relational model, not a table

The implementing technical standards describe a set of linked templates: the entities in scope, the providers, the contractual arrangements, the ICT services supplied under each arrangement, the functions those services support, and the chains of subcontractors that sit behind them.

Because the templates reference each other through identifiers, a provider record that is fine in isolation can still break the submission if the arrangement pointing at it uses a different identifier or if a service references a function that was never registered.

  • Entities in scope, each with its own LEI
  • ICT third-party providers, identified by LEI or an equivalent code
  • Contractual arrangements, including intragroup arrangements
  • ICT services per arrangement, with function and criticality
  • Subcontracting chains supporting critical or important functions

Where registers fail

The recurring problems are mundane. Identifiers are missing or formatted wrongly. Country codes do not match the expected list. Dates are inconsistent between the arrangement and the service. A provider is flagged as supporting a critical function but no function record exists to support that claim.

None of this is difficult, but it is impossible to control by hand once you pass a few dozen providers, because each change in procurement or architecture quietly invalidates part of the file.

Treat the Register as an output, not a document

The organizations that submit cleanly are the ones that stopped maintaining a register file and started maintaining the underlying records: providers, services, contracts, functions and subcontractors. The Register is then generated, validated and exported from that data on demand.

That shift also solves the question every supervisor eventually asks: where did this field come from, who changed it and when. If the register is generated, every value has a traceable source.

See how this works in the product.

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.