DORA Register of Information — ICT providers, reporting to the supervisor and common mistakes
What is the Register of Information?
The Register of Information is a structured register of all of a financial entity’s contractual arrangements for the use of ICT services provided by third-party providers — indicating which arrangements support critical or important functions. The obligation follows from Article 28(3) of DORA (Regulation (EU) 2022/2554).
The register is the backbone of DORA’s third-party risk management: without an accurate register, neither the entity itself, nor the auditor, nor the supervisor can assess the dependence on ICT providers.
Who reports, and to whom?
The financial entity maintains the register on an ongoing basis and reports it to the competent authority — in Denmark, for example, Finanstilsynet. The authorities forward the registers to the European Supervisory Authorities (the ESAs: EBA, EIOPA and ESMA), which use them, among other things, to designate critical third-party providers of ICT services placed under EU oversight.
The first collection of registers took place in the spring of 2025, and reporting is then repeated on a fixed cadence in line with the supervisor’s instructions. The register must also be available to the supervisor on request.
What data must the register contain about ICT providers?
- identification of the provider (including the LEI code where relevant),
- a description of the ICT services provided and their category,
- which functions the services support, and whether they are critical or important,
- contract data: term, termination conditions and exit strategy,
- subcontracting chains for critical or important functions,
- locations for the provision of the service and for data processing.
How to prepare
- build a complete inventory of all ICT contracts — not only the obvious IT agreements,
- classify which contracts support critical or important functions,
- obtain missing master data about the providers (including LEI codes),
- establish a process for ongoing maintenance, so the register does not become outdated,
- validate data quality and format before the register is reported to the supervisor.
Common mistakes
- the register is treated as a one-off task instead of an ongoing process,
- incomplete coverage — only classic IT providers are included, not all ICT services,
- no link between the individual contract and the critical function it supports,
- gaps in the subcontracting chain for critical functions,
- no evidence behind the criticality classification — it cannot be defended before the supervisor.
How Audnexa supports work on the register
Audnexa supports the third-party part of a DORA audit: review of the register and the underlying contracts with references to evidence and a full audit trail, consolidated into a review-ready report draft for the board. In offline mode (Bank Mode), the material stays in the client’s infrastructure, and a human approves every report.
A mature tool, shaped by several years of audit practice at Virtline (ISO/IEC 27001). It replaces neither an auditor’s opinion nor legal advice.
Frequently asked questions
What is the Register of Information under DORA?
A register of all of a financial entity’s contractual arrangements for the use of ICT services, indicating critical or important functions. The obligation follows from Article 28(3) of Regulation (EU) 2022/2554.
Who has to report the register to the supervisor?
Financial entities under supervision — including banks, insurers, investment firms and payment institutions. The competent authority (in Denmark, Finanstilsynet) forwards the registers to the ESAs.
How often must the register be reported?
The register must be maintained on an ongoing basis and reported in line with the supervisor’s instructions — the first collection took place in the spring of 2025, and reporting is then repeated on a fixed cadence. It must also be available on request.
What do the ESAs use the registers for?
EBA, EIOPA and ESMA use the collected registers to map concentration risk in the sector and to designate critical third-party providers of ICT services, which are placed under EU oversight.
Can work on the register be done without moving data out of the house?
Yes. With an on-premise tool in offline mode (such as Audnexa’s Bank Mode), contract data and audit material stay in the entity’s own infrastructure, with no outbound traffic by default.
Sources
This content is informational and does not constitute a legal opinion, an auditor’s opinion or a formal compliance decision.