Where the provider-held columns are
Template B_05.01 describes each ICT third-party service provider in twelve columns, and B_05.02 describes the supply chain beneath them in seven more. That is nineteen columns about entities you do not control. They ask for the provider's legal name and its identification code, the type of that code, its country, its person type, the currency and total of what you spend with it annually, and the identifier of its ultimate parent undertaking.
Some of that you know. You know what you pay them. You probably know their legal name and country. The ultimate parent is where it starts to slip: a provider three acquisitions deep does not volunteer its ultimate parent's LEI, and the EBA has a rule, v8855_m, which makes that column mandatory as soon as the rest of the row is populated.
B_05.02 is harder still. It records the chain of subcontractors as ranked links: rank one is the provider, a direct subcontractor is rank two, its own supplier is rank three. Each link needs an identification code and a code type. These are your provider's suppliers. There is no route to that information except asking.
- B_05.01: twelve columns describing each provider, including its ultimate parent's identifier
- B_05.02: seven columns describing the chain beneath it, ranked
- The parent identifier becomes mandatory the moment anything else in the row is filled
And six more about where the service actually runs
Template B_02.02 links an arrangement to a service, and six of its eighteen columns describe facts about that service which only the provider knows with certainty. The country the service is provided from. Whether data is stored at all. The country the data sits in at rest. The country it is managed from when it is being processed. The sensitivity of what is stored. The country whose law governs the arrangement.
It is tempting to fill these from the contract or from a data processing agreement, and for the governing law that works. For the rest it often does not. A cloud provider's contractual data residency commitment and the country its support engineers operate from are different facts, and the register asks for the second one. A provider that has never been asked this question precisely will answer it imprecisely.
This is also where the closed lists bite. The location columns take country codes from a list that includes a value meaning not applicable, for a service that genuinely stores nothing. Anything else has to resolve to a real country.
Why this changes the shape of the work
If a quarter of the register is held by third parties, then the register is not a reporting exercise with a deadline. It is a data collection exercise with a deadline, and data collection from external parties runs on their timetable rather than yours.
Two consequences follow. The first is that the work starts earlier than people expect. If the answer to where is customer data managed from has to come back from twelve providers, and some of them will route the question through legal, the realistic elapsed time is weeks. The second is that the asking should be systematic. A one-off email thread per provider produces answers in twelve different formats, none of which map to a closed list.
It also changes what completeness means. A register that is ninety per cent complete because the provider-held columns are empty is not ninety per cent finished. Those columns include keys, and a row missing a key fails entirely rather than partially.
- Ask the questions in the register's own vocabulary, so the answers arrive as codes rather than prose
- Start with the providers supporting a critical or important function, where the columns are mandatory and the scrutiny is heaviest
- Record what a provider refuses to disclose as refused rather than leaving it blank; the two mean different things to a supervisor
The fourth party you will not be told about
The most uncomfortable column is B_05.02's identification code for the recipient of sub-contracted services. Providers frequently decline to name their own suppliers, citing commercial confidentiality, and a register that leaves the column blank is a register with a failing row.
There is no clever technical answer to this. What there is, is a choice about how to represent it. A blank cell says nothing. A cell that records the relationship as undisclosed says that you asked and were refused, which is a materially different position in front of a supervisor and a materially different position in a contract renewal.
Concentration risk lives in exactly this layer. Three providers that look independent can share one underlying infrastructure supplier, and the register is the instrument that makes that visible. It only works if the layer beneath the providers gets filled in.