EU regulation

DORA register of information: what financial entities must keep

DORA requires financial entities to maintain a register of all contractual arrangements with ICT third-party service providers, in a standard format supervisors can collect.

Short answer

Under the EU Digital Operational Resilience Act, which applies from 17 January 2025, financial entities must maintain a register of information covering every contractual arrangement with ICT third-party service providers, flagging those that support critical or important functions, and submit it to their competent authority on request in the prescribed format.

Key takeaways

  • DORA applies from 17 January 2025.
  • The register covers all ICT third-party arrangements, not only critical ones.
  • Arrangements supporting critical or important functions need extra detail.

Timeline

How DORA came into force

  1. Published in the Official Journal
  2. Entered into force
  3. Applies to financial entitiesRegisters of information must be maintained from this date.

Who has to keep the register

All financial entities in DORA's scope, at entity level and, where applicable, at sub-consolidated and consolidated level.

What goes in it

  • Contract references, dates and governing law.
  • The ICT services provided and the functions they support.
  • Subcontractors that effectively underpin critical services.
  • Data location and processing locations.

Sources

  1. Regulation (EU) 2022/2554 (DORA), EUR-Lex