Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Third parties

Register of information (DORA)

The register of information is the inventory that DORA requires every financial entity to maintain of all its contractual arrangements for ICT services provided by third-party providers, at entity, sub-consolidated and consolidated level. For each arrangement it records the provider, the service, the business function it supports and its criticality, the subcontracting chain, the data location and the termination conditions, in the standard templates set by the European supervisory authorities. Competent authorities collect it, and it is the starting point of the EU oversight of critical ICT providers.

Why it is harder than it looks

The register is not a list of vendors; it is a relational dataset with a dozen linked templates: entities, contracts, providers, services, functions, subcontractors. The difficulty is that the data lives in four places (procurement, legal, IT, the business) and that the supervisor validates the file structurally before reading it. Financial entities that built it in spreadsheets in the first year discovered that keeping it current is the actual obligation, not producing it once.

Living data, not an annual export

The register must reflect the current state of the arrangements, which means a new contract, a change of subcontractor or a reclassified function has to land in it when it happens. That only works if the register is a view over the supplier inventory, the contract records and the business function map the organization already maintains for its third-party risk program, so that the same fact is entered once and the export is generated on demand.

What it enables

Beyond the reporting duty, the register is what makes the rest of DORA’s third-party chapter operable: concentration risk can be measured only if the register shows which functions depend on the same provider; exit strategies are needed only for the arrangements it flags as critical or important; the oversight of critical ICT providers is designated from the aggregated registers of the sector. An entity that treats it as the backbone of its supplier data, rather than as a compliance file, gets the analysis for free.

GO DEEPER

The reference guide.

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.