Custom outsourcing register for DORA
Appfront builds registers for financial institutions that need to keep track of their agreements with ICT service providers under DORA. Contracts, providers, subcontractors and the functions they support are held in one place and updated whenever something changes. When DNB or the AFM request the information register, the software produces the file in the required format, checked before it is submitted.
What is a outsourcing register under DORA?
DORA, the EU Digital Operational Resilience Act for the financial sector, requires financial institutions to maintain a register of their agreements with ICT service providers: the information register. Supervisors use these registers, among other things, to determine which ICT service providers are critical to the sector. In the Netherlands, DNB and the AFM request the register, and institutions submit it themselves in the required format.
In practice, the register for the first request is often compiled in a spreadsheet, drawn from contracts, procurement records and conversations with the business. It then goes out of date: a contract is extended, a provider brings in a new subcontractor, a function changes. At the next request the search starts again, and converting the data into the required format introduces errors that only surface at submission.
We build bespoke solutions because institutions differ: how many providers and contracts you have, where that data currently lives, how your functions are organised, and which systems you use for contracts and risk. What exactly you must register and submit follows from DORA, the technical standards and your supervisor's request. If in doubt, check with your compliance team or adviser.
One place
Providers, contracts, subcontractors and the functions they support, kept in one place.
The right format
The information register produced in the format your supervisor requires, and checked first.
Updated
Changes recorded throughout the year, so the next request is not a new search.
How we build your outsourcing register for DORA
We start with your register: how it was produced for the last request, where the data is stored, who maintains it, and what went wrong when it was submitted. If you already have, or are building, the broader DORA processes in software, the register should connect to them. The register then becomes part of your supplier management, rather than an annual project.
Your current register, sources, owners and experience of submitting it.
Service providers, contracts, functions and subcontractors set up.
Checks for missing data, and the file produced in the required format.
Changes throughout the year, and management as the requirements evolve.
What a DORA outsourcing register actually does
The components below appear in almost every information register. Which ones you need depends on your institution.
Service providers
With identification and their group.
Contracts
Agreements with term and services.
Functions
Supported functions, critical or not.
Subcontractors
The chain behind the service provider.
Validation
Missing or incorrect data.
Submission
The register in the required format.
Who we build a DORA outsourcing register for
The software is intended for financial institutions under DORA.
Banks
Many service providers and contracts. The structure is the core.
Insurers
Outsourcing in chains. Subcontractors matter most.
Pension funds
Much is outsourced to operators. Oversight is what's needed.
Smaller institutions
Few people for many requirements. The submission is the core.
Test your idea first: a working prototype in 1 day
With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.
Explore OneDayBuild →Technology and integrations
This page is about the DORA information register. For DORA in its entirety, see our page on DORA compliance software. For ICT risk, see our page on IT risk management software, and for the sector in general, our page on software for the financial sector. You can read about how we work at custom software development.
Why Appfront for your DORA outsourcing register?
A register rebuilt from scratch every year is an annual project prone to errors. We build on something different: everything in one place, the right format, and changes tracked throughout the year.
No annual project
The register is always up to date.
Fewer errors
Validated before submission.
Usable
Also useful for your own risk management.
Security and privacy for a DORA outsourcing register
The register contains confidential data about contracts, service providers and critical functions. Access is set up by role, and every change is logged.
The software runs in a European data centre or in your own environment, with encrypted storage, daily back-ups and two-factor sign-in.
Frequently asked questions about a DORA outsourcing register
Questions financial institutions ask before starting.
It keeps track of your ICT service providers, contracts, subcontractors and the functions they support, records changes, checks for missing or incorrect data, and produces the information register in the format the supervisor requires.
A register that DORA requires for all contractual arrangements with ICT service providers, including the services and the functions they support. Supervisors use it, among other things, to determine which service providers are critical for the sector.
In the Netherlands, DNB and the AFM request the register as at a reference date, and the institution submits it itself in the required format. The software produces and validates that file, so errors don't surface only at submission.
DORA requires more than a register, such as ICT risk management, incident reporting and testing. DORA compliance software covers the whole. This register is the component for arrangements with ICT service providers, and can be built on its own or as part of the whole.
From your contract management, procurement, and the departments that use the services. Where those systems have an interface, we pull the data from them. What is known only to people is collected and maintained through simple questionnaires.
The technical standards and format may change. We build that into the management so the register follows the new requirements and you don't have to start over at the next submission.
Check this first. Many governance, risk and compliance packages have a module for the information register, and that may be enough. Custom development makes sense if your data is scattered, if you want to link the register to your own systems, or if submission currently involves a lot of manual work.
An information register that is always up to date?
Tell us how you currently maintain the register, where the data is kept and what went wrong at the last submission. We'll show you what the register could look like.