Structured Registers of Information for DORA Compliance

DORA Register of Information

The DORA Register of Information (RoI) must be submitted annually to national supervisors, with the March 2026 BaFin deadline now passed, preparation for the next cycle starts now.

  • 01Complete ICT asset inventory and structured documentation
  • 02Automated register management and continuous updating
  • 03Integrated data governance and quality assurance
  • 04Supervisory-compliant reporting and transparency
11+Years of experience
120+Employees
540+Projects
ISO 27001certified

DORA Register of Information Requirements: What Financial Entities Need to Know

Under DORA Article 28(3), all in-scope financial entities must maintain a complete register of contractual arrangements with ICT third-party service providers and submit it annually to their competent authority. The Register of Information (RoI) must conform to EBA ITS templates, capturing counterparty details, criticality assessments, sub-contractors, and data storage locations.

We provide comprehensive support in building and optimizing the DORA register of information under Article 28. Our approach combines technical expertise with regulatory know-how to develop sustainable and effective documentation systems.

5 phases

Our Approach to the DORA Register of Information

We develop customized DORA registers of information with you that integrate smoothly into your existing IT landscape and ensure sustainable transparency and compliance.

  1. Analysis of existing ICT landscape and identification of all relevant assets

  2. Design of structured register architectures and data models

  3. Implementation of automated capture and update processes

  4. Establishment of comprehensive data governance and quality control

  5. Integration into existing risk management and compliance systems

Sarah Richter

Your contact

Sarah Richter

Head of Information Security, Cyber Security

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

A well-structured register of information is the nervous system of digital operational resilience. Our experience shows that organizations with solid, automated register systems not only meet DORA requirements more efficiently but also sustainably strengthen their ICT governance and risk management capabilities.

5 QUESTIONS, BRIEFLY ANSWERED

Frequently asked questions about DORA Register of Information

What is the DORA information register, and who must maintain it?

The Register of Information is a structured directory of all ICT third-party contracts mandated under Article 28 DORA. Every financial entity within DORA's scope must maintain it, regardless of how many third-party relationships it has; even a small number of contracts doesn't remove the obligation.

What information must the register capture per third-party provider?

Captured fields include the provider name, the type of ICT function provided, its criticality classification, the location of data processing, and details on subcontractors used. The exact format follows the technical implementing standards issued by the European supervisory authorities; the field structure is mandated, not freely chosen.

What software is suited to maintaining the information register?

Suitable solutions directly support the mandated reporting format and automatically reflect contract changes in the register, rather than relying on a manually maintained spreadsheet that quickly goes stale. When choosing one, it's worth checking whether the software exports in formats that directly match supervisory requirements, avoiding manual rework before submission.

How often must the register be updated and submitted to supervisors?

The register must be kept continuously current, not only at fixed points, since it must be available on request from the supervisory authority. Depending on national implementation, periodic submissions to the relevant authority are also required; exact deadlines should be confirmed with the relevant national supervisor, since they can differ.

What happens if the register is incomplete or outdated during a review?

An incomplete register is treated as a breach of third-party risk management obligations and can trigger sanctions and intensified review. Since the register underpins the concentration risk assessment, a gap also indirectly undermines the credibility of the entire ICT third-party risk management program, not just the register itself.

Certificates, partners and more

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance