
Preparing and Maintaining the DORA Register of Information
DORA requires financial entities to maintain information on contractual arrangements for ICT services. The register supports internal oversight and must be available for competent authorities in the prescribed templates. It should not be treated as a spreadsheet completed once for a regulatory request.
Published 2026-09-09 | Updated 2026-09-09 | GoalTech Ltd
The register is a controlled data set
Where organisations encounter difficulty
These gaps often reflect weaknesses in third-party governance rather than a formatting problem.
- Different departments hold separate vendor and contract lists.
- Service descriptions do not identify the supported business function.
- Subcontractors and supply chains are incomplete.
- Criticality assessments are undocumented or inconsistent.
- Contract dates, notice periods and data locations are missing.
- Legal entities and group-level arrangements are difficult to reconcile.
A sustainable preparation process
GoalTech helps define data owners, collect contracts and service information, map the records to the applicable templates, validate relationships and establish update controls. The work should also connect with procurement, change management, incident management and exit planning so that the register remains current.
Before each regulatory submission, the organisation should apply validation rules and management sign-off. Responsibility for the accuracy of the register remains with the financial entity.
Ask GoalTech to review or prepare your DORA register of information.