Registries and DORA
· 2 min
doraregulatory-complianceict-risk-management
Working in business registry software while studying the EU’s regulatory framework DORA makes it useful to see what registries are actually required at each level of the framework — the financial entity, the competent authority, and the European Supervisory Authorities (ESAs).
Under the EU’s Digital Operational Resilience Act (DORA), financial entities, competent authorities, and ESAs are each required to create and maintain various registries and records.
Financial Entities
- Register of Information: financial entities must maintain a register of information on their ICT third-party service providers, subcontractors, and any critical or important functions supported by them.
- Incident Logs: detailed logs of all ICT-related incidents, including their causes, impacts, and measures taken to resolve them.
Competent Authorities
- Register of Critical ICT Third-Party Service Providers: national competent authorities must maintain a register of critical ICT third-party service providers operating within their jurisdiction.
- Register of Exemptions: a record of exemptions granted to financial entities from certain DORA requirements.
European Supervisory Authorities (ESAs)
- Joint Database on ICT Third-Party Service Providers: a joint database of information on ICT third-party service providers operating across the EU.
- Joint Register of Critical or Emerging ICT Third-Party Service Providers: a joint register of providers that pose potential risks to the financial sector.
These registries and records are essential for monitoring and assessing the digital operational resilience of financial entities and ICT third-party service providers, ensuring compliance with DORA requirements, and facilitating information-sharing among relevant authorities.