DORA - Register of Information

The Register of Information required by DORA Article 28(3): ICT providers, contractual arrangements, business functions and the xBRL-CSV export.

Register of Information - Overview

Build a DORA Register of Information that survives submission: completeness scoring, CSV import, and validation that catches errors before your NCA does.

11 min

ICT Third-Party Providers - Art. 28

Record every ICT third-party provider DORA Article 28 requires, flag critical providers (CTPP), and pull verified company details automatically by LEI lookup.

11 min

Contractual Arrangements - Art. 30

Track ICT contracts against DORA Article 30 and run the clause checker to find missing mandatory provisions before an auditor or your regulator finds them.

9 min

Business Functions - Art. 3(21)

Decide which functions are critical or important under DORA Article 3(21). That judgement drives the obligations on every provider and contract beneath it.

8 min

ICT Provider Risk Assessments - Art. 28(1)

Run the continuous ICT third-party risk assessments DORA Article 28(1) demands, scored by scale and criticality, with the history an inspection will want.

9 min

Branches - ITS B_01.03

Report every branch to your NCA using ITS template B_01.03. Get cross-border entity identification right so the rest of your Register of Information validates.

6 min

Sub-outsourcing Chains - Art. 31

Map the sub-outsourcing chain behind each ICT provider, as DORA Article 31 requires, and see the supply-chain dependencies sitting beyond your direct contracts.

8 min

Concentration Risk Analysis - Art. 31

Spot dangerous reliance on a single ICT provider: DORA Article 31 concentration analysis built from the providers and contracts you have already recorded.

8 min

xBRL-CSV Regulatory Export - ITS 2024/2956

Generate the xBRL-CSV filing package your NCA expects under EBA ITS 2024/2956, covering all 15 Register of Information tables from B_01.01 through B_99.01.

8 min