The DORA Register of Information.
Where most firms fail — and why.
In the 2024 ESA dry-run exercise, only 6.5% of nearly 1,000 financial firms passed all Register of Information data quality checks. The other 93.5% had errors. Most of them thought they were fine. Here is what the Register actually requires and what keeps going wrong.
The Register of Information is not a vendor list. It is a structured relational database.
Most financial firms built their first Register in a spreadsheet. That approach produces something that looks like a vendor list — company name, service description, contract value, maybe a contact. It is not what DORA requires and it will fail the EBA data quality checks.
The Register of Information, as defined by the EBA ITS (Implementing Technical Standards) on the Register of Information, is a structured data model spanning 15 interconnected templates. Each template captures a specific category of information, and the templates must link together with referential integrity — meaning each ICT provider record must correctly reference the functions it supports, which must correctly reference the entity's critical or important function classification, which must correctly reference the contractual arrangements, which must include subcontractor disclosure.
The EBA provides XML schema definitions and validation tools. Your Register must pass those validation checks before it can be submitted to your national regulator. The relational structure cannot be replicated in a standard Excel spreadsheet — not because Excel is incapable, but because maintaining relational integrity manually across 15 templates with potentially hundreds of vendor records is practically impossible without structured tooling or expert support.
What the EBA ITS data model actually covers.
The 15 templates are grouped into four functional areas. Every template must link correctly to every other relevant template for the Register to pass validation.
Entity maintaining the register
Contractual arrangements
ICT third-party service providers
ICT services
Functions supported by ICT services
Assessment of ICT services
Data stored or processed
IT assets managed by ICT third parties
Impact assessment of discontinuance
Substitutability of ICT third parties
Exit strategy information
Annual costs and expenses
ICT sub-outsourcing arrangements
Branches of the entity
ICT intra-group service providers
The four most common Register failures — and what they cost.
Missing subcontractor chains (Template 13)
Firms list their direct ICT vendors but not those vendors' own ICT subcontractors. If your cloud provider uses a third-party data centre, or your portfolio management software uses a third-party database provider, those sub-outsourcing arrangements must be disclosed in Template 13. Most firms have no visibility into their vendors' subcontractor chains without specifically asking for it.
Wrong critical function classification (Template 5)
The ITS defines specific criteria for what constitutes a critical or important function. Firms frequently either over-classify (marking everything as critical, which creates disproportionate obligations) or under-classify (marking genuinely critical functions as non-critical to reduce paperwork). Supervisors check these classifications against the firm's actual operations.
Broken relational links between templates
Each template uses entity identifiers that must match across all related templates. A vendor record in Template 3 must use the same unique identifier as the contract record in Template 2 that references it. Manual spreadsheet builds frequently produce identifier mismatches that fail EBA validation without an obvious error message explaining why.
Incomplete contract data (Template 2)
Template 2 requires specific contract data fields that many firms' contracts don't record centrally: exact contract start and end dates, notice period in days, governing law jurisdiction, and — critically — a description of the exit strategy. Many firms discover their contracts don't include an exit strategy at all, which is simultaneously a Template 2 gap and an Article 30 breach.
We build Registers that pass. And keep them passing.
We build your Register from scratch or remediate an existing one against the full EBA ITS data model — 15 templates, relational integrity, XML-ready, submission-grade.
Full vendor mapping
We work through your entire ICT vendor estate — direct providers and their subcontractors — to build a complete picture of every arrangement that must be included in your Register.
Critical function classification
We apply the EBA ITS classification criteria to your specific operations and produce documented rationale for each classification that will withstand supervisory challenge.
Relational integrity validation
Before submission, we run your Register through EBA validation tools to identify and fix any referential integrity failures. You submit once, correctly.
Annual maintenance
We keep your Register current as your vendor estate evolves — new tools, changed providers, terminated arrangements — so each year-end snapshot reflects reality. Learn about ongoing maintenance →
John Smutniak
Managing Partner, Regulatory Compliance PracticeWith a background in quantitative measurement and financial institution operations, John helps mid-market firms navigate complex regulatory frameworks without the overhead of a Big Four engagement. BS, Massachusetts Institute of Technology.
Free DORA gap review — written summary within 5 business days.
Tell us about your current Register status. We'll come back with an honest assessment of what needs to be fixed and what it will take to get your Register submission-ready.
Questions about the Register of Information
What is the DORA Register of Information?
The Register of Information is a mandatory structured inventory of every ICT third-party service provider arrangement your financial institution maintains. Required under DORA Articles 28(3) and the EBA ITS on the Register of Information, it must be submitted to your national regulator annually in a specific XML format covering 15 interconnected data templates.
When does the Register need to be submitted?
The Register must reflect your ICT third-party arrangements as of 31 December each year. It is submitted to your national competent authority by 31 March of the following year. Missing or late submissions are compliance breaches under DORA.
Why do so many firms fail the EBA data quality checks?
The EBA ITS data model requires relational integrity across 15 interconnected templates. A spreadsheet built manually cannot maintain this relational integrity at scale. In the 2024 ESA dry-run, only 6.5% of nearly 1,000 participating firms passed all data quality checks.
What are the most common Register failures?
Missing subcontractor information, incorrect critical function classification, broken relational links between templates, and incomplete contract data — particularly missing exit strategy descriptions and incorrect notice period fields. These four account for the majority of failed submissions.
Can we build the Register of Information in Excel?
You can use Excel for drafting and vendor mapping, but the final submission must be in the EBA XML format. Most firms that built entirely in Excel discovered at submission that their data structure did not translate cleanly to the required XML format, resulting in validation errors.
How often does the Register need to be updated?
The Register must be accurate as of 31 December each year, but it should be treated as a living document updated whenever your ICT vendor estate changes. Firms that treat it as an annual exercise typically discover large gaps when preparing their year-end submission.