Breakdown · DORA
DORA: the register of information and what banks demand
DORA requires EU financial entities to keep a register of all their ICT contracts. What that register contains and what banks now ask of their ICT suppliers.
By Sentrix · Published 2026-09-20
Since DORA started to apply, an ICT service provider with a European bank, insurer or asset manager among its customers receives a new request: to fill in, or help fill in, rows of a standardized register. Legal identifier, head office, supported functions, subcontractors, data processing locations. This register is not one more questionnaire, it is a regulatory document the customer must be able to submit to its authority.
What the texts say
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector, or DORA, has applied since 17 January 2025 under its Article 64. Its Article 28, paragraph 3, provides that all financial entities maintain a register of information in relation to all contractual arrangements on the use of ICT services provided by third-party providers, and that competent authorities may request the full register or specified sections. Paragraph 4 requires, before any contract, an assessment: criticality of the service, required supervisory approvals, concentration risk, due diligence on the provider, conflicts of interest. For critical or important functions, the entity must ensure that the provider applies the highest information security standards.
Article 30 lists the mandatory contractual provisions: full description of services and processing locations, service levels with quantitative and qualitative targets, guarantees on data availability, integrity and confidentiality, return of data in case of insolvency, assistance in case of ICT incident, cooperation with authorities, termination rights and notice periods, continuity plans, access, inspection and audit rights, exit strategies and transition periods. Article 31 provides for the designation of critical third-party providers according to the financial sector's reliance, with a voluntary opt-in mechanism.
Commission Implementing Regulation (EU) 2024/2956 of 29 November 2024 sets the standard templates of the register. According to its text, the fields cover the identification of the entity (LEI, name, country, type), the contractual arrangements (reference, type, costs, duration), the providers (identification code, headquarters), the supported functions and their criticality with recovery objectives, the ICT service supply chain with the rank of subcontractors, the location of data storage and processing, and assessment elements such as sensitivity, reliance level and notice periods. ESMA states that a dry run of register submissions was completed on 17 December 2024, and the Commission has since adopted Delegated Regulation (EU) 2025/532, published on 2 July 2025, on the elements to assess when subcontracting ICT services.
Why it matters
A supplier does not complete its customer's register, but it supplies the material. Each field of the template corresponds to information that only the provider holds reliably: its identifier, the chain of its own subcontractors and their rank, the countries where data is stored and processed, the notice periods it accepts. When that information arrives late, incomplete or changes without notice, it is the customer that ends up with a wrong register in front of its authority.
The second effect is contractual. The Article 30 clauses (audit, exit, incident assistance, data return) are not negotiated case by case; they are mandatory for the customer. A supplier that refuses them is not "firm", it is ineligible.
The third effect concerns subcontracting. With Delegated Regulation 2025/532, the customer must assess what its supplier subcontracts, to whom, and down to which rank. A supplier that does not know its own chain cannot answer.
What we think at Sentrix
A supplier serving the European financial sector should keep, at home, the equivalent of the register rows that concern it, before it is asked for them.
- Prepare a register sheet per service with the fields of Regulation 2024/2956: identifier, headquarters, service description, supported customer functions when known, storage and processing locations, subcontractors and their rank, notice period.
- Keep the subcontracting chain current in your own supplier register, with the data location of each subcontractor. For ISO 27001:2022, these are controls 5.19 to 5.22; the third-party risk module of the Sentrix platform is meant for this.
- Adopt a clause set aligned with Article 30: measurable service levels, incident assistance, audit right, assisted exit with a transition period. Accept them once, with legal advice, rather than contract by contract.
- Notify changes: new subcontractor, new processing region, change of ownership. An unannounced change makes the customer's register inaccurate.
- Link security evidence to the sheet: ISO 27001 certificate, SOC 2 report, test results, continuity plan. These are the documents the pre-contractual assessment of Article 28, paragraph 4, calls for.
- Follow the delegated and implementing acts on the Commission's page and through our regulatory watch, because the framework keeps being completed.
The next step
Take your best-selling service to the financial sector and try to fill in, alone, the fields of the register template. Each field you cannot complete without searching is a question your customer will ask you. Our DORA page describes the regulation, and we answer through the contact page.
Sources
- EUR-Lex, Regulation (EU) 2022/2554 (DORA), Articles 28, 30, 31 and 64
- EUR-Lex, Commission Implementing Regulation (EU) 2024/2956: standard templates for the register of information
- ESMA, Digital Operational Resilience Act (DORA)
- European Commission, Digital Operational Resilience Regulation (delegated and implementing acts)
Frequently asked questions
- What is the register of information required by DORA?
- Article 28, paragraph 3, of Regulation (EU) 2022/2554 requires all financial entities to maintain a register of information covering all contractual arrangements on the use of ICT services provided by third-party providers. Implementing Regulation (EU) 2024/2956 sets the standard templates: identification of the entity and the provider, contracts, supported functions and their criticality, subcontracting chain, data locations, notice periods. Authorities may request all or part of it.
- Why does a European bank ask for my LEI and my list of subcontractors?
- Because the templates of Implementing Regulation 2024/2956 require them: the register identifies each provider by a code, locates its headquarters, describes the supply chain of the service with the rank of each subcontractor, and locates data storage and processing. Without those fields, the customer cannot complete its register or submit it to its authority. A supplier that does not provide them blocks its own customer.
- Can a supplier outside the EU be designated a critical provider?
- Yes, the designation provided for in Article 31 rests on the financial sector's reliance on the provider, not on where it is established. ESMA published on 14 May 2025 a document on the designation of critical providers and the next steps of the oversight framework of Articles 31 to 44. For most suppliers, however, the subject remains contractual: answering the register, accepting the Article 30 clauses and delivering the evidence requested.
Let's talk about your compliance program.
Last updated: 2026-09-20
