From Excel to a Submission-Ready xBRL-CSV Package

Fund XP provides a comprehensive solution to help financial entities efficiently produce the DORA register of information required by the financial authorities.

Fund XP simplifies this process by streamlining the generation of the register in the required XBRL JSON/CSV ZIP format.

Importantly, the ESA will not provide tools or scripts for generating the register, as was done during the Dry Run exercise. Fund XP offers a reliable solution to ensure that your register is correctly formatted and ready for submission without additional manual effort.

Satisfied Clients
50+
and always more
Jurisdictions
26

How it works?

Utilizing an Excel template, Fund XP integrates advanced functions to ensure seamless data production, validation, and checks. Our solution automates the process of compiling and verifying critical information, drastically reducing manual errors and improving efficiency. As the reporting is yearly and the data remain relatively stable, our aim is to provide a simple, efficient, and cost-effective solution that avoids unnecessary complexity while delivering reliable results. Everything is done locally on your system, ensuring complete control over your data and processes.

The solution is multi-jurisdictional and fully compliant with jurisdictions that require filing in CSV/JSON formats.

DORA Register template

The Register Is a Relational Database Disguised as Fifteen Tables

Most entities approach the Register of Information as fifteen forms to fill in. It isn’t. The four primary keys — the contractual arrangement reference number, the LEI or EUID, the function identifier, and the type of ICT service — tie the templates into a single relational structure. A contract reference that appears in B_02.01 but nowhere in B_02.02 is not an incomplete form; it is a broken join, and the validation engine treats it as such.

This is why the register resists the obvious workflow. You cannot delegate B_05.02 to procurement, B_06.01 to the business lines, and B_07.01 to risk, then merge the results. Every identifier assigned in one tab constrains what is admissible in three others. Teams that discover this at the consolidation stage lose weeks.

The consequence for tooling is straightforward: a template that validates each tab in isolation will pass files the supervisor rejects. Cross-tab referential checks are not a convenience feature. They are the difference between a file that submits and one that comes back.

LEI, EUID, and the Subcontractors Nobody Mapped

The identification rules look simple until you reach the supply chain. Union-established providers need an LEI or an EUID — both where available. Third-country providers need an LEI only. Natural persons acting in a business capacity fall back to alternative codes.

The difficulty is rarely the rule. It is the scope. Every subcontractor underpinning a critical or important function must be identified, ranked, and carried through the chain. For a cloud service with two layers of downstream providers, that means obtaining identifiers from parties your procurement team has never contracted with directly — and, in practice, from parties your direct provider may be reluctant to name.

Entities that start this exercise in the final weeks before submission generally do not finish it.

What is the Dora register of information?

Commission Implementing Regulation (EU) 2024/2956, adopted on 29 November 2024, lays down the implementing technical standards referenced in Article 28(9) of Regulation (EU) 2022/2554 (DORA). Its central function is to establish a set of standard templates for the register of information that financial entities must maintain regarding their use of ICT services from third-party providers.
 
The information collected through this standardized register is designed to serve multiple strategic purposes, as outlined in Recital (1):
 
Internal ICT Risk Management: To provide financial entities with a structured overview of their ICT dependencies for their own risk assessment and management.
Supervision: To enable competent authorities to effectively supervise financial entities’ management of ICT third-party risk.
Oversight of Critical Providers: To supply the Lead Overseer with the necessary information to establish and conduct oversight of designated critical ICT third-party providers.
Designation of Critical Providers: To support the European Supervisory Authorities (EBA, EIOPA, ESMA) in their annual process of designating which ICT third-party service providers are critical to the financial sector.

Free tool

Check your register before you file it

Drop in the xBRL-CSV report package you are about to submit. It is validated in your browser against the fifteen EBA templates — the file is never uploaded — and you get the number of problems it contains.

What key information about ICT services and third-party providers must be included in the register?

The register must include comprehensive details about ICT services and their providers. This encompasses general information on the financial entity maintaining the register, details of entities within the scope of consolidation and their branches, and general and specific information on contractual arrangements with direct ICT third-party service providers. Crucially, it must also include information on the ICT service supply chain, identifying all direct ICT third-party service providers and subcontractors that underpin critical or important functions. Furthermore, details on the identification of functions supported by ICT services, risk assessments of these services (including substitutability and impact of discontinuation), and internal terminology used by financial entities must be provided.

YouTube video

Supported Jurisdictions & Authorities

🇦🇹FMA — Austria
🇧🇪FSMA — Belgium
🇧🇬FSC — Bulgaria
🇭🇷HANFA — Croatia
🇨🇾CySEC — Cyprus
🇨🇿CNB — Czech Republic
🇩🇰Finanstilsynet — Denmark
🇪🇪Finantsinspektsioon — Estonia
🇫🇮FIN-FSA — Finland
🇫🇷ACPR — France
🇩🇪BaFin — Germany
🇬🇷HCMC / BoG — Greece
🇭🇺MNB — Hungary
🇮🇪CBI — Ireland
🇮🇹Banca d'Italia — Italy
🇱🇻FCMC — Latvia
🇱🇹LB — Lithuania
🇱🇺CSSF / CAA — Luxembourg
🇲🇹MFSA — Malta
🇳🇱DNB / AFM — Netherlands
🇵🇱KNF — Poland
🇵🇹Banco de Portugal — Portugal
🇷🇴ASF / BNR — Romania
🇸🇰NBS — Slovakia
🇸🇮ATVP / BS — Slovenia
🇸🇪Finansinspektionen — Sweden

Payconiq Testimonial

DORA ROI Linkedin Payconiq testimonial

PANDOO TESTIMONIAL

PANDOO DORA register solution testimonial

Who is required to maintain this register of information, and at what levels?

The regulation applies to all financial entities under the scope of DORA. For financial entities that are part of a group, the parent undertaking is responsible for determining the scope of consolidation for the register. The framework allows groups to maintain a single, unified register at a consolidated or sub-consolidated level. However, this single register must be structured to allow each individual financial entity within the group to meet its own reporting obligations.

DORA errors : RoI Register Error Message Guidance

Validation messages rarely name the field that is actually wrong. A rejection triggered in one template usually originates in another — a key assigned upstream that no downstream row matches. 

Find more information here : https://fund-xp.lu/uncategorized/dora-errors-roi-register-error-message-guidance/

Luxembourg’s Transposition of DORA

In Luxembourg, DORA is directly applicable from January 2025. The CSSF and CAA are designated as the authorities ensuring compliance with DORA. Specific laws and regulations, such as Circular CSSF 24/847, are already in place to enhance incident reporting and align with DORA’s framework.

What is a direct ICT third-party service provider?

An ICT third-party service provider or ICT intra-group service provider that signed a contractual arrangement with:
(a) a financial entity to provide its ICT services directly to that financial entity;
(b) a financial or a non-financial entity to provide its services to other financial entities within the same group;

What is an ICT service supply chain?

A sequence of contractual arrangements connected with the ICT service being provided by the direct ICT third-party service provider to the financial entity, starting with the direct ICT third-party service provider which has one or multiple other ICT third-party service providers as counterparties (subcontractors);

How does this regulation address the complexities of intra-group ICT service provision and subcontracting?

The regulation specifically accounts for intra-group ICT service providers and subcontracting chains. Financial entities must report information on contractual arrangements with both intra-group service providers and external ICT third-party providers, including subcontractors. A dedicated template (B_02.03) allows for the reconciliation of intra-group contracts with contracts involving external ICT third-party providers when they are part of the same ICT service supply chain. For ICT services supporting critical or important functions, financial entities are required to record all subcontractors that effectively underpin these services. Furthermore, if an intra-group service provider uses subcontractors, at least the first extra-group subcontractor must be recorded, even if their services are not deemed critical or important.

What types of financial entities are covered by this regulation, and what activities are relevant to their reporting?

The regulation applies to a broad range of financial entities, including but not limited to credit institutions, payment institutions, electronic money institutions, investment firms, crypto-asset service providers, central securities depositories, central counterparties, trading venues, insurance and reinsurance undertakings, and credit rating agencies. For each type of entity, a specific list of licensed activities and services is provided in Annex II, which is relevant for the identification of functions (template B_06.01) within their internal organization that are supported by ICT services.

Glossary of Key Terms

  • Board of Supervisors (BoS): The governing body of each European Supervisory Authority (ESA), involved in approving key decisions like the designation of Critical Third-Party Providers (CTPPs).
  • Competent Authority (CA): National authorities responsible for the supervision of Financial Entities (FEs) within a Member State. They cooperate with ESAs in DORA oversight.
  • Critical Third-Party Provider (CTPP): An Information and Communication Technology (ICT) third-party service provider designated as critical by the European Supervisory Authorities (ESAs) due to its systemic impact on the financial sector.
  • Digital Operational Resilience Act (DORA): An EU regulation establishing a comprehensive framework for managing ICT risks in the financial sector, including oversight of CTPPs.
  • European Banking Authority (EBA): One of the three European Supervisory Authorities (ESAs) with oversight responsibilities under DORA, specifically for the banking sector.
  • European Insurance and Occupational Pensions Authority (EIOPA): One of the three European Supervisory Authorities (ESAs) with oversight responsibilities under DORA, specifically for the insurance and occupational pensions sector.
  • European Securities and Markets Authority (ESMA): One of the three European Supervisory Authorities (ESAs) with oversight responsibilities under DORA, specifically for the securities and markets sector.
  • European Supervisory Authorities (ESAs): The EBA, EIOPA, and ESMA, jointly empowered to oversee CTPPs on a pan-European scale under DORA.
  • Financial Entity (FE): An entity within the financial sector that relies on external ICT services.
  • General Investigations: Formal reviews performed by overseers covering one or more risk areas of CTPPs, aimed at gathering information on how CTPPs manage risks.
  • Information and Communication Technology (ICT): Technologies and services related to information processing, storage, and communication.
  • Inspections: A highly intrusive method of oversight involving on-site or off-site examinations of CTPPs’ premises, systems, and data to gain a deep understanding of business operations, risk management, and internal controls.
  • Joint Committee (JC): The most senior cross-sectoral committee across the three ESAs, responsible for adopting relevant decisions regarding CTPPs oversight, including designation.
  • Joint Examination Teams (JETs): Teams composed of staff from ESAs and relevant Competent Authorities (CAs) that assist Lead Overseers (LOs) in conducting DORA oversight activities.
  • Joint Oversight Network (JON): A body set up by the overseers to coordinate the conduct of oversight activities over CTPPs and prepare decisions and acts for submission to the Oversight Forum.
  • Joint Oversight Venture (JOV): An operational structure set up by the three ESAs to maximize synergies and ensure consistency in day-to-day DORA oversight activities through a cross-sectoral integrated approach.
  • Lead Overseer (LO): The specific European Supervisory Authority (ESA) appointed to conduct the oversight activities for a designated CTPP.
  • Ongoing Regular Monitoring: The continuous interaction between overseers and CTPPs, involving systematic collection, analysis, and assessment of information outside of specific investigations or inspections.
  • Oversight Forum (OF): A standing committee of the ESAs dedicated to DORA oversight, carrying out preparatory work for individual acts and collective recommendations, and promoting a consistent approach to ICT third-party risk.
  • Recommendations: Non-binding suggestions issued by overseers to CTPPs addressing identified deficiencies in specific areas of assessment, typically after examinations.
  • Request for Information (RfI): A tool used by overseers to request information from CTPPs, either by “Simple Request” or by “Decision,” without initiating full investigations or inspections.
  • Remediation Plan: A plan provided by a CTPP to the overseers, outlining the actions and measures it intends to take to address findings and comply with issued recommendations.

Useful links

CAA Circular LC25-01 : CAA Circular

CSSF Webpage : CSSF DORA Guide

EIOPA Webpage : EIOPA Website

EBA Webpage : EBA DORA Preparation

EUID : EUID Search