Get Demo
↑

DORA Register of Information: Template and How to Complete It

How to structure and maintain the DORA register of information for ICT third-party arrangements — fields, ownership.

Published: September 2026 Compliance · DORA 8–12 min read

The register of information is the living inventory of ICT third-party arrangements that financial entities must maintain and be ready to submit. It is one of the most searched — and most under-owned — DORA artefacts.

Related: DORA hub · Article 30 / third-party risk · CSA.

Design rule: Treat the register as a controlled dataset with clear ownership (procurement + ICT risk + legal), not a one-off spreadsheet export. Align fields to the applicable ITS/reporting templates your competent authority / ESA channel expects — avoid treating a vendor blog schema as an official substitute.

Why Supervisors Care

The register underpins concentration-risk analysis, subcontracting visibility, and Critical ICT Third-Party Provider oversight. Incomplete or stale registers are a common examination finding.

Field Themes to Capture

Operating Cadence

How CyberSilo Helps

Make the Register Supervisable

CSA can host register records alongside third-party assessments and contract artefacts.

Frequently Asked Questions

Is the register only for cloud providers?

No. It covers ICT third-party service arrangements broadly — including non-cloud ICT services that support critical or important functions.

Who owns the register day to day?

Typically joint ownership: ICT risk / CISO for criticality, procurement for commercial data, legal for contract facts, with a single accountable executive.

Can we keep it in a spreadsheet forever?

Spreadsheets fail under version control and multi-entity reporting. Move to a controlled system with audit trail before the next supervisory request.

Hub · For ICT providers · Checklist

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!