Resources › Guide
What is the DORA Register of Information?
The Register of Information (RoI) is one of the most concrete obligations of the EU's Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554). It is a structured inventory of every contractual arrangement a financial entity has with its third-party ICT service providers, and, crucially, their subcontractors. It must be kept up to date, made available to your supervisor on request, and reported annually.
Who must maintain one?
Virtually every financial entity supervised in the EU: banks, investment firms, asset managers, payment and e-money institutions, crypto-asset service providers, crowdfunding platforms, insurers, and more. Size does not exempt you, small and medium entities are in scope too, which is exactly where a focused tool matters most.
What does it contain?
The register is defined by the ESAs' Implementing Technical Standards (ITS (EU) 2024/2956) as a set of 15 related templates. In practice they capture:
- The entities in scope and the entity maintaining the register;
- Every contractual arrangement for ICT services, and its key terms;
- The ICT third-party providers and the supply chain (subcontractors);
- The functions supported and whether they are critical or important (CIF);
- Standardised identifiers, LEI and EUID, that tie the whole picture together.
Because these templates are interlinked (a criticality assessment propagates to contracts, providers to the supply chain, and so on), a single misclassification can cascade into multiple validation errors.
In what format is it submitted?
Not a free-form spreadsheet: regulators require a machine-readable xBRL-CSV package, metadata plus one CSV per template, named to an exact convention and complying with the ESA taxonomy. Producing this by hand from Excel is where most rejections happen. (See our guide, xBRL-CSV explained simply.)
When and to whom?
The register is reported annually to your national competent authority (in France, the AMF or ACPR, which forward to the ESAs), and must be available for inspection at any time. It is a living document: new provider, amended contract, changed subcontractor, all should be reflected.
Why it's harder than it looks
The three recurring failure points are: invalid or missing LEIs, incomplete critical-function data, and values outside the taxonomy's closed lists. Each is invisible in Excel but fatal at submission. The safe approach is to replay the regulators' checks before you file.
How Obligia helps
Obligia builds the full register across all 15 templates, runs the complete ESA validation catalogue before submission, and exports the official xBRL-CSV package, so you pass on the first try, without a five-figure consulting bill.
Build my register Book a demo ›
This guide is general information, not regulatory advice; responsibility for submission remains with the entity.