Glossary · DORA
Register of Information
The mandatory register of all contractual arrangements with ICT third-party providers that DORA requires financial entities to maintain and report.
Explained in depth: DORA overview
Under DORA Article 28, every financial entity must maintain a register of information covering all its contractual arrangements on the use of ICT services provided by third-party providers, at entity, sub-consolidated, and consolidated level. The register records, per arrangement, details such as the provider, the ICT services delivered, whether they support critical or important functions, subcontracting chains, and contract data, in a standardised template defined by an implementing technical standard. The register is reported to competent authorities (first collections took place in 2025) and feeds the ESAs' designation of critical ICT third-party providers. It must be kept current and be available to the supervisor on request.
Why it matters
Building the register is consistently reported as one of DORA's heaviest lifts: it forces a complete inventory of ICT dependencies, including subcontractors, in a rigid format. It is also a useful by-product: few entities have ever seen their full ICT dependency chain in one place before.
