The DORA Register of Information.
Where most firms fail — and why.

In the 2024 ESA dry-run exercise, only 6.5% of nearly 1,000 financial firms passed all Register of Information data quality checks. The other 93.5% had errors. Most of them thought they were fine. Here is what the Register actually requires and what keeps going wrong.

DORA Article 28(3)
EBA ITS on Register
15 Templates
100+ Mandatory Fields
Annual Submission

The Register of Information is not a vendor list. It is a structured relational database.

Most financial firms built their first Register in a spreadsheet. That approach produces something that looks like a vendor list — company name, service description, contract value, maybe a contact. It is not what DORA requires and it will fail the EBA data quality checks.

The Register of Information, as defined by the EBA ITS (Implementing Technical Standards) on the Register of Information, is a structured data model spanning 15 interconnected templates. Each template captures a specific category of information, and the templates must link together with referential integrity — meaning each ICT provider record must correctly reference the functions it supports, which must correctly reference the entity's critical or important function classification, which must correctly reference the contractual arrangements, which must include subcontractor disclosure.

The EBA provides XML schema definitions and validation tools. Your Register must pass those validation checks before it can be submitted to your national regulator. The relational structure cannot be replicated in a standard Excel spreadsheet — not because Excel is incapable, but because maintaining relational integrity manually across 15 templates with potentially hundreds of vendor records is practically impossible without structured tooling or expert support.

6.5% of firms passed all data quality checks in the 2024 ESA dry-run
15 interconnected templates in the EBA ITS data model
100+ mandatory fields across the full Register structure
31 Mar annual submission deadline to your national regulator

What the EBA ITS data model actually covers.

The 15 templates are grouped into four functional areas. Every template must link correctly to every other relevant template for the Register to pass validation.

Template 1

Entity maintaining the register

Template 2

Contractual arrangements

Template 3

ICT third-party service providers

Template 4

ICT services

Template 5

Functions supported by ICT services

Template 6

Assessment of ICT services

Template 7

Data stored or processed

Template 8

IT assets managed by ICT third parties

Template 9

Impact assessment of discontinuance

Template 10

Substitutability of ICT third parties

Template 11

Exit strategy information

Template 12

Annual costs and expenses

Template 13

ICT sub-outsourcing arrangements

Template 14

Branches of the entity

Template 15

ICT intra-group service providers

The four most common Register failures — and what they cost.

Missing subcontractor chains (Template 13)

Firms list their direct ICT vendors but not those vendors' own ICT subcontractors. If your cloud provider uses a third-party data centre, or your portfolio management software uses a third-party database provider, those sub-outsourcing arrangements must be disclosed in Template 13. Most firms have no visibility into their vendors' subcontractor chains without specifically asking for it.

Wrong critical function classification (Template 5)

The ITS defines specific criteria for what constitutes a critical or important function. Firms frequently either over-classify (marking everything as critical, which creates disproportionate obligations) or under-classify (marking genuinely critical functions as non-critical to reduce paperwork). Supervisors check these classifications against the firm's actual operations.

Broken relational links between templates

Each template uses entity identifiers that must match across all related templates. A vendor record in Template 3 must use the same unique identifier as the contract record in Template 2 that references it. Manual spreadsheet builds frequently produce identifier mismatches that fail EBA validation without an obvious error message explaining why.

Incomplete contract data (Template 2)

Template 2 requires specific contract data fields that many firms' contracts don't record centrally: exact contract start and end dates, notice period in days, governing law jurisdiction, and — critically — a description of the exit strategy. Many firms discover their contracts don't include an exit strategy at all, which is simultaneously a Template 2 gap and an Article 30 breach.

We build Registers that pass. And keep them passing.

We build your Register from scratch or remediate an existing one against the full EBA ITS data model — 15 templates, relational integrity, XML-ready, submission-grade.

Full vendor mapping

We work through your entire ICT vendor estate — direct providers and their subcontractors — to build a complete picture of every arrangement that must be included in your Register.

Critical function classification

We apply the EBA ITS classification criteria to your specific operations and produce documented rationale for each classification that will withstand supervisory challenge.

Relational integrity validation

Before submission, we run your Register through EBA validation tools to identify and fix any referential integrity failures. You submit once, correctly.

Annual maintenance

We keep your Register current as your vendor estate evolves — new tools, changed providers, terminated arrangements — so each year-end snapshot reflects reality. Learn about ongoing maintenance →

John Smutniak, Managing Partner

John Smutniak

Managing Partner, Regulatory Compliance Practice

With a background in quantitative measurement and financial institution operations, John helps mid-market firms navigate complex regulatory frameworks without the overhead of a Big Four engagement. BS, Massachusetts Institute of Technology.

Free DORA gap review — written summary within 5 business days.

Tell us about your current Register status. We'll come back with an honest assessment of what needs to be fixed and what it will take to get your Register submission-ready.

No obligation, no pressure Written summary within 5 business days Confidential — NDA on request All entity types welcome

Your information is kept strictly confidential.

Thank you — we will be in touch within one business day.

Questions about the Register of Information

What is the DORA Register of Information?

The Register of Information is a mandatory structured inventory of every ICT third-party service provider arrangement your financial institution maintains. Required under DORA Articles 28(3) and the EBA ITS on the Register of Information, it must be submitted to your national regulator annually in a specific XML format covering 15 interconnected data templates.

When does the Register need to be submitted?

The Register must reflect your ICT third-party arrangements as of 31 December each year. It is submitted to your national competent authority by 31 March of the following year. Missing or late submissions are compliance breaches under DORA.

Why do so many firms fail the EBA data quality checks?

The EBA ITS data model requires relational integrity across 15 interconnected templates. A spreadsheet built manually cannot maintain this relational integrity at scale. In the 2024 ESA dry-run, only 6.5% of nearly 1,000 participating firms passed all data quality checks.

What are the most common Register failures?

Missing subcontractor information, incorrect critical function classification, broken relational links between templates, and incomplete contract data — particularly missing exit strategy descriptions and incorrect notice period fields. These four account for the majority of failed submissions.

Can we build the Register of Information in Excel?

You can use Excel for drafting and vendor mapping, but the final submission must be in the EBA XML format. Most firms that built entirely in Excel discovered at submission that their data structure did not translate cleanly to the required XML format, resulting in validation errors.

How often does the Register need to be updated?

The Register must be accurate as of 31 December each year, but it should be treated as a living document updated whenever your ICT vendor estate changes. Firms that treat it as an annual exercise typically discover large gaps when preparing their year-end submission.

← Back to DORA Compliance overview