DORA - Register of Information
The Register of Information required by DORA Article 28(3): ICT providers, contractual arrangements, business functions and the xBRL-CSV export.
Register of Information - Overview
Build a DORA Register of Information that survives submission: completeness scoring, CSV import, and validation that catches errors before your NCA does.
ICT Third-Party Providers - Art. 28
Record every ICT third-party provider DORA Article 28 requires, flag critical providers (CTPP), and pull verified company details automatically by LEI lookup.
Contractual Arrangements - Art. 30
Track ICT contracts against DORA Article 30 and run the clause checker to find missing mandatory provisions before an auditor or your regulator finds them.
Business Functions - Art. 3(21)
Decide which functions are critical or important under DORA Article 3(21). That judgement drives the obligations on every provider and contract beneath it.
ICT Provider Risk Assessments - Art. 28(1)
Run the continuous ICT third-party risk assessments DORA Article 28(1) demands, scored by scale and criticality, with the history an inspection will want.
Branches - ITS B_01.03
Report every branch to your NCA using ITS template B_01.03. Get cross-border entity identification right so the rest of your Register of Information validates.
Sub-outsourcing Chains - Art. 31
Map the sub-outsourcing chain behind each ICT provider, as DORA Article 31 requires, and see the supply-chain dependencies sitting beyond your direct contracts.
Concentration Risk Analysis - Art. 31
Spot dangerous reliance on a single ICT provider: DORA Article 31 concentration analysis built from the providers and contracts you have already recorded.
xBRL-CSV Regulatory Export - ITS 2024/2956
Generate the xBRL-CSV filing package your NCA expects under EBA ITS 2024/2956, covering all 15 Register of Information tables from B_01.01 through B_99.01.