Lesson17 min

Building the register of information

What the register really is

It is not a supplier list. It is a set of linked tables, feeding a template defined by the European authorities, describing:

  • the group entities that contract;
  • the contractual arrangements, with their characteristics;
  • the providers, identified by legal entity identifier;
  • the functions supported, with their criticality;
  • the sub-outsourcing chains for critical functions;
  • the links between all these objects.

The real volume far exceeds what most organisations anticipate: dozens of fields, contract- and function-level granularity, and annual submission to the competent authority.

The build method

Step 1 — Inventory the arrangements. All contracts covering the use of ICT services, not just outsourcing in the classic sense. A software licence delivered as a service is an ICT arrangement. So is hosting, email, or an e-signature tool.

Step 2 — Attach to functions. Each arrangement is linked to the functions it supports, via the Article 8 map. Arrangements supporting no critical function remain in the register but with lighter contractual requirements.

Step 3 — Qualify criticality. Does the contract support a critical or important function? That qualification determines whether the enhanced Article 30 requirements apply.

Step 4 — Trace sub-outsourcing. For critical functions, identify the provider's subcontractors. This information comes from the contract — it must be required there — or by questionnaire.

Step 5 — Identify the providers. Each provider must carry its legal entity identifier. That is what lets the authorities aggregate dependencies Europe-wide and identify critical providers.

Article 30: the mandatory clauses

All ICT contracts must contain a baseline: description of services, processing locations, data provisions, access and return on termination, obligations to cooperate with authorities, termination rights, notice periods.

For critical functions these additionally include:

  • quantitative and qualitative service levels, with precise targets;
  • unrestricted access, inspection and audit rights, including on site;
  • the obligation to participate in resilience testing, TLPT included;
  • a documented exit strategy;
  • incident assistance obligations, at no additional or at predefined cost.

Upgrading an existing portfolio typically takes twelve to eighteen months, because it means renegotiating. Prioritisation follows function criticality, not contract value.

The exit strategy

It must be documented before signature and executable without interrupting the critical function. Four elements:

  1. The trigger scenario: failure, termination, degradation, regulatory change;
  2. The fallback solution: another qualified provider, insourcing, degraded mode;
  3. The estimated lead time and resources required;
  4. Data retrieval: format, timeframe, usability verification.

Item 4 is the most frequently deficient. Retrieving an export in an undocumented proprietary format amounts to retrieving nothing. The clause must require a usable format and, ideally, a periodic retrieval test.

Key takeaways

  • The register links contracts, functions and entities: three axes, not a list
  • Sub-outsourcing chains must be traced
  • The register is built once and maintained by process