Regulation

What DORA expects from your third-party ICT register

The register of information, contractual clauses, exit plans and testing evidence supervisors look at first — and the fields teams usually miss.

10 July 2026 · 8 min read

The register is the centre of gravity

DORA turns the third-party inventory from an internal convenience into a supervisory deliverable. The register of information has a prescribed structure, has to be maintained at entity and group level, and must reconcile with the contracts it describes. If your vendor list lives in procurement and your risk assessments live elsewhere, reconciliation becomes the whole project.

Fields teams routinely miss

Beyond the obvious vendor name and service description, these are the details that hold up submissions:

  • Whether the service supports a critical or important function, with the reasoning.
  • Subcontracting chains, including the fourth parties your provider relies on.
  • Data location and processing jurisdictions per service.
  • Substitutability assessment and the identified alternative provider.
  • Contract references, notice periods and termination rights as structured fields.

Contracts have to carry specific clauses

Audit and access rights, incident notification timelines, exit assistance obligations and subcontracting consent all need to be present in the paper, not assumed. A clause library with approved language and deviation flagging makes remediation of a legacy contract estate tractable; without one, every renewal is a bespoke legal review.

Exit planning is tested, not just documented

A credible exit plan names the alternative provider, estimates the transition period, identifies the data and configuration you would need, and has been walked through by the people who would execute it. Supervisors increasingly ask when the plan was last exercised, which puts continuity testing and third-party oversight in the same programme.

Make it one dataset

Register, contract terms, diligence results, incident history and testing evidence describe the same relationship. Held in one platform they produce the submission and the board report from the same source. Held apart, they produce a quarterly reconciliation exercise nobody enjoys.

Run this in a platform, not a spreadsheet.

See how compliance, risk, policy, third-party oversight and ESG reporting work on one control library.