Audnexa
SecurityModulesPricingFAQ
plPolski enEnglish daDansk deDeutsch svSvenska fiSuomi nlNederlands
Book a security presentation
SecurityModulesPricingFAQ For audit firms +48 12 200 27 10 Book a security presentation

← All articles

DORA Register of Information — ICT providers, reporting to the supervisor and common mistakes

Author: Adam Wojak · Founder & Managing Director, Virtline (ISO/IEC 27001) · Updated: July 4, 2026

In short: The Register of Information is DORA’s register of all contractual arrangements for the use of ICT services (Article 28(3) of Regulation (EU) 2022/2554). Financial entities maintain the register and report it to the competent authority, which forwards the data to the European Supervisory Authorities (the ESAs). The first collection took place in the spring of 2025.

What is the Register of Information?

The Register of Information is a structured register of all of a financial entity’s contractual arrangements for the use of ICT services provided by third-party providers — indicating which arrangements support critical or important functions. The obligation follows from Article 28(3) of DORA (Regulation (EU) 2022/2554).

The register is the backbone of DORA’s third-party risk management: without an accurate register, neither the entity itself, nor the auditor, nor the supervisor can assess the dependence on ICT providers.

Who reports, and to whom?

The financial entity maintains the register on an ongoing basis and reports it to the competent authority — in Denmark, for example, Finanstilsynet. The authorities forward the registers to the European Supervisory Authorities (the ESAs: EBA, EIOPA and ESMA), which use them, among other things, to designate critical third-party providers of ICT services placed under EU oversight.

The first collection of registers took place in the spring of 2025, and reporting is then repeated on a fixed cadence in line with the supervisor’s instructions. The register must also be available to the supervisor on request.

What data must the register contain about ICT providers?

  • identification of the provider (including the LEI code where relevant),
  • a description of the ICT services provided and their category,
  • which functions the services support, and whether they are critical or important,
  • contract data: term, termination conditions and exit strategy,
  • subcontracting chains for critical or important functions,
  • locations for the provision of the service and for data processing.

How to prepare

  • build a complete inventory of all ICT contracts — not only the obvious IT agreements,
  • classify which contracts support critical or important functions,
  • obtain missing master data about the providers (including LEI codes),
  • establish a process for ongoing maintenance, so the register does not become outdated,
  • validate data quality and format before the register is reported to the supervisor.

Common mistakes

  • the register is treated as a one-off task instead of an ongoing process,
  • incomplete coverage — only classic IT providers are included, not all ICT services,
  • no link between the individual contract and the critical function it supports,
  • gaps in the subcontracting chain for critical functions,
  • no evidence behind the criticality classification — it cannot be defended before the supervisor.

How Audnexa supports work on the register

Audnexa supports the third-party part of a DORA audit: review of the register and the underlying contracts with references to evidence and a full audit trail, consolidated into a review-ready report draft for the board. In offline mode (Bank Mode), the material stays in the client’s infrastructure, and a human approves every report.

A mature tool, shaped by several years of audit practice at Virtline (ISO/IEC 27001). It replaces neither an auditor’s opinion nor legal advice.

Frequently asked questions

What is the Register of Information under DORA?

A register of all of a financial entity’s contractual arrangements for the use of ICT services, indicating critical or important functions. The obligation follows from Article 28(3) of Regulation (EU) 2022/2554.

Who has to report the register to the supervisor?

Financial entities under supervision — including banks, insurers, investment firms and payment institutions. The competent authority (in Denmark, Finanstilsynet) forwards the registers to the ESAs.

How often must the register be reported?

The register must be maintained on an ongoing basis and reported in line with the supervisor’s instructions — the first collection took place in the spring of 2025, and reporting is then repeated on a fixed cadence. It must also be available on request.

What do the ESAs use the registers for?

EBA, EIOPA and ESMA use the collected registers to map concentration risk in the sector and to designate critical third-party providers of ICT services, which are placed under EU oversight.

Can work on the register be done without moving data out of the house?

Yes. With an on-premise tool in offline mode (such as Audnexa’s Bank Mode), contract data and audit material stay in the entity’s own infrastructure, with no outbound traffic by default.

Sources

  • EUR-Lex — DORA Regulation (EU) 2022/2554
  • Finanstilsynet (Danish FSA)
  • EBA — Digital Operational Resilience

Related tools

  • DORA audit tool — gap analysis
  • Audnexa for banks and financial institutions

Book a security presentation

Related articles

  • NIS2 audit — who is covered, what the obligations are, and how to prepare
  • Which tools support NIS2, DORA and banking compliance audits? Selection criteria
  • DORA audit — ICT requirements, third-party risk and how to prepare

This content is informational and does not constitute a legal opinion, an auditor’s opinion or a formal compliance decision.

← All articles

Audnexa

Auditable AI workspace for IT security and compliance reporting at regulated institutions.

Audnexa is a product of Virtline Sp. z o.o.

Product

Security Deployment Modules Pricing Trust Center

Company

Knowledge For audit firms Contact LinkedIn +48 12 200 27 10 biuro@virtline.com

Legal

Privacy policy DPA Terms security@virtline.com

Audnexa supports the work of auditors and compliance teams. It does not constitute a legal opinion, an auditor’s opinion, or a formal compliance decision.

© 2026 Virtline Sp. z o.o. All rights reserved. ul. Wadowicka 8A, 30-415 Kraków · NIP 6751499701

We use cookies for traffic analytics (GA4). Statistics load only after your consent. Privacy policy