Auditen
Home / Frameworks / DORA / The register of information
DORA · Art. 28(3)

The register of information

DORA requires financial entities to maintain a detailed, up-to-date register of all contractual arrangements with ICT third-party service providers. This register must categorize services based on their criticality and provide regulators with transparency into the entity's reliance on external technology partners.

What it means

The intent is to give competent authorities a clear map of an organization's ICT supply chain. Rather than a simple vendor list, the register serves as a functional inventory that tracks which providers support specific business processes and whether those functions are deemed "critical or important."

The scope encompasses all ICT third-party service providers, including cloud service providers, software vendors, hardware maintenance firms, and specialized IT consultants. It applies regardless of the size of the contract; if it is an ICT arrangement, it must be recorded.

This is a dynamic operational requirement rather than a one-time project. The register must be maintained in real-time or near-real-time to ensure that regulatory oversight is based on current dependencies and risk profiles.

How to meet it

Evidence an auditor asks for

  • The Register of Information itself, exported from a GRC tool or maintained as a structured database/spreadsheet.
  • The written policy or framework used to determine "criticality" for ICT services.
  • A sample of recent contracts cross-referenced against the register to prove that all active providers are captured.
  • Audit trails or change logs showing when entries were created, modified, or reviewed.

Common pitfalls

  • Treating the requirement as a general "Vendor List," thereby omitting the mandatory mapping to critical business functions.
  • Overlooking "Shadow IT" or small SaaS subscriptions that provide essential functionality but sit outside formal procurement channels.
  • Maintaining a static document that is only updated annually, which fails the requirement for an up-to-date register.