
Since 17 January 2025, the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) applies to banks, insurers, investment firms, payment and e-money institutions and many other financial entities. One of its most concrete duties is the register of information: a complete record of the contractual arrangements you have with ICT third-party service providers.
Why the register exists
ICT providers, such as cloud hosting, core banking software or managed security services, are part of how a financial entity operates. If one of them fails, the entity has to keep running. Supervisors want to see which providers you depend on, for which services and how critical those services are. The register gives them that picture, and it gives you the same picture for your own risk management.
What goes in it
DORA (Article 28(3)) requires the register at entity level and, for groups, at sub-consolidated and consolidated level. The detailed templates are set out in implementing technical standards. In practice, for each contractual arrangement you record, among other things:
- the provider, identified where possible by its LEI (Legal Entity Identifier);
- the ICT services it provides;
- whether those services support a critical or important function of your entity;
- the contract details, such as start and end dates and notice periods;
- where data is processed and stored, and whether the provider uses subcontractors.
You report the register to your competent authority when asked, and in some countries on a fixed yearly cycle.
How to start
- List your ICT providers. Start from accounts payable and your IT inventory; most entities find more providers than expected.
- Map services to functions. For each service, note which of your business functions it supports and whether that function is critical or important.
- Collect identifiers and contract data. LEIs, contract dates and locations take time to gather, so start early.
- Assess the critical ones. Security questionnaires, certificates and exit plans matter most for providers that support critical functions.
- Keep it current. A register is only useful when new contracts and changes are added as they happen.
Beyond the register
The register is one part of DORA's third-party risk rules (Articles 28 to 30), next to ICT risk management (Articles 5 to 16), incident reporting (Articles 17 to 23) and resilience testing (Articles 24 to 27). Treat them as one programme: the providers in your register are the same ones that appear in your incident and continuity plans.
CloudSignLab records the DORA fields of your ICT providers, exports the core of the register, and links providers to supplier checks, incidents and continuity plans. See the DORA page.
Start free

