The register of information, DORA's most underestimated deliverable
Not a supplier list but a set of linked tables with dozens of fields, contract-level granularity and mandatory annual submission.
The initial confusion
Most organisations approach DORA Article 28 as a documentation formality: "we already have a list of our IT providers." That sentence, heard almost everywhere at the outset, underestimates the work by a factor of three to five.
The register of information is not a list. It is a set of linked tables, feeding a template defined by the European Supervisory Authorities, describing the group entities that contract, the contractual arrangements with their characteristics, the providers identified by legal entity identifier, the functions supported with their criticality, the sub-outsourcing chains for critical functions, and the links between all these objects.
Three scoping traps
The first trap is limiting yourself to "material" outsourcing in the sense of the old banking guidelines. DORA covers all arrangements on ICT services, whatever their importance. A software licence delivered as a service, an e-signature tool, an email service: all of it counts. Criticality sorting comes afterwards and determines whether the enhanced Article 30 requirements apply — it does not condition entry into the register.
The second trap is treating the register as a procurement inventory. The structuring axis is not the contract but the function supported. Without the Article 8 mapping — critical function, ICT assets, third parties — the register cannot be filled correctly, because the function-link field stays empty.
The third trap is ignoring tier 2. For critical functions, the sub-outsourcing chain must be traced. That information is only obtained if the contract requires it, or if the relationship allows you to ask. It cannot be derived from any internal system.
What takes the most time
Across observed projects, the effort splits fairly consistently: roughly one third for the exhaustive inventory of arrangements, one third for linking them to functions, and one third for collecting missing data from providers — legal entity identifiers, processing locations, subcontractors.
It is that last third that surprises, because it depends on third parties with no obligation to answer quickly, receiving the same request from several dozen clients simultaneously.
The only sustainable approach
A register built by annual campaign degrades within six months. The only model that holds is to feed it through the procurement process: no ICT contract is signed without the register fields being populated, and the link to a function is a validation condition.
That means changing an existing process rather than launching a project — politically harder, and infinitely cheaper over time.