Register of Information · Implementing Regulation (EU) 2024/2956

A Register of Information, checked before you file it.

Relynt assembles the Register from the records you already keep, in the format the regulation defines, and checks it for the problems that get a filing sent back. Every row traces to the provider, contract or service it came from.

For payment and e-money institutions, investment firms, asset managers and insurers in the EU. Assessments, evidence, contracts and risk sit underneath it.

relynt.io/dashboard

DORA Third-Party Risk Overview

Meridian Bank Europe · updated 9 August 2026

ICT Providers

96

Critical Providers

18

Register errors

3

Register warnings

9

High Risks

7

Missing Evidence

23

Outstanding

  • Register errors blocking filing3
  • Register warnings9
  • Evidence documents missing23
  • Article 30 clauses unresolved11
  • Assessments overdue2

Attention Required

View all
  • Halcyon assessment expires soon

    Annual ICT Risk Assessment 2026 · due 18 Aug

  • Northwind Cloud contract needs review

    Exit strategy clause not documented

  • Payflux evidence expires next month

    SOC 2 Type II report valid until 14 Sep

Built for data a financial entity cannot afford to lose

  • Hosted in the EU, in Frankfurt
  • Encrypted in transit and at rest
  • Tenant isolation enforced in the database
  • Two-factor authentication, enforceable workspace-wide
  • Role-based access
  • Append-only audit trail you can export

The problem

The Register is the deliverable, and it is the hardest part to get right.

It is fifteen linked templates with keys that have to resolve between them and columns that only accept the regulation's own codes. Assembled by hand in a spreadsheet it drifts from operations within weeks, and the problems that stop a filing are structural rather than matters of judgement: an empty key, a label where a code belongs, a reference pointing at nothing.

Vendor information scattered across teams

Procurement, security and compliance each keep their own list of ICT providers and services.

Assessments managed manually

Questionnaires travel by email and spreadsheet, and progress is impossible to track.

Contracts difficult to review consistently

Article 30 requirements are checked differently by each reviewer, with no shared record.

DORA Register difficult to maintain

The Register is rebuilt from scratch each reporting cycle and drifts from operational reality.

Which is why the Register cannot be a document you assemble once a year. It is only right if the providers, services, contracts and evidence underneath it are right on the day you file.

DORA Register of Information

Build and maintain your DORA Register continuously.

Connect providers, ICT services, contracts, critical functions and subcontractors so the Register stays aligned with your operational data.

relynt.io/dora-register

Register of Information

Reporting entity: Meridian Bank Europe · LEI 549300XKZ9Q2P1F4T083

Export

Templates with rows

12 of 15

Errors

3

Warnings

9

Validation issues

  • B_02.02Function identifier is empty. Every key column has to resolve.Error
  • B_05.02Identification code of the recipient of sub-contracted ICT services is empty.Error
  • B_02.01Holds "Payment Services", which is not one of the nineteen permitted service types.Error
  • B_01.01Competent Authority is empty. A supervisor will ask about this.Warning
  • B_02.02Location of the data at rest is empty.Warning
91%Register completeness
3 Errors9 Warnings
  • Halcyon

    Missing contractual arrangement reference.

  • Payflux

    Subcontractor country incomplete.

  • Northwind Cloud

    Exit strategy not documented.

Then filed, not retyped

All fifteen templates of Implementing Regulation (EU) 2024/2956, in xBRL-CSV, with the regulation's own codes and every key checked before you submit.

Explore DORA Register

Platform

One system for the entire ICT third-party risk lifecycle.

Every object is connected, so a change in one place updates the record everywhere it matters.

Step 1

ICT Provider

Step 2

Criticality

Step 3

Assessment

Step 4

Evidence

Step 5

Contract Review

Step 6

Risk

Step 7

Remediation

Step 8

DORA Register

Provider → service → assessment → evidence → contract clause → risk → remediation → Register field. Each link is preserved as an auditable record.

Data lineage

Every row of the Register has a source.

Compliance teams can trace each row back to the provider, contract, ICT service or critical function it was assembled from, with the person and date behind the last change to that record.

  • Trace Register rows to providers, services, contracts and functions
  • See the workspace's own wording beside the code it was mapped to
  • Know who last changed the record behind a row, and when
  • Answer regulator questions without rebuilding the trail

Register field · lineage

Traceable
Template
B_02.02 · column 0160
Field
Location of management of the data
Value
DE
Source
Service · Northwind Cloud Production Hosting
Arrangement
Contract · Northwind Cloud MSA 2026
Last changed
Sarah Martin · 12 July 2026

ICT Providers

Know every ICT provider and what they support.

  • Centralize ICT providers in one inventory
  • Map ICT services to each provider
  • Identify critical and important providers
  • Track countries and data locations
  • Link providers to critical or important functions
  • Assign internal owners
Explore ICT Provider Management
relynt.io/providers

ICT Providers

96 providers · 18 critical

Add ICT Provider
AllCriticalHigh RiskAssessment OverdueMissing Evidence
ProviderICT ServiceCriticalityCountryRisk
Halcyon Cloud ServicesCloud InfrastructureCriticalIrelandHigh
Northwind Cloud IrelandCloud & ProductivityCriticalIrelandMedium
Payflux Payments EuropePayment ProcessingCriticalIrelandHigh
Lumendata NetherlandsData PlatformImportantNetherlandsMedium
Edgeway GermanyNetwork & SecurityImportantGermanyLow
ValteraCore BankingCriticalSwitzerlandMedium

Vendor Assessments

Run vendor assessments without chasing spreadsheets.

  • Send structured DORA questionnaires
  • Give vendors a self-service portal
  • Track progress section by section
  • Request evidence inside the questionnaire
  • Review responses in a single workspace
  • Identify potential gaps before sign-off
Explore Vendor Assessments
relynt.io/assessments/ASM-2041

ASM-2041 · Halcyon Annual ICT Assessment

Under Review

117 questions · 12 sections · vendor submitted 4 August 2026

Section progress

  • Governance & Oversight100%
  • Information Security92%
  • Business Continuity64%
  • Incident Management88%
  • Subcontracting45%

Q 4.3 · Business Continuity

Describe the frequency and scope of your disaster recovery testing.

“DR testing is performed periodically across production regions.”

AI Finding

78% confidence

Disaster recovery testing evidence is missing.

The response describes testing but no test report was attached for the current period. Requires human review before any compliance decision.

Accept & create riskDismissRequest clarification

Reviewed by Sarah Martin · AI suggestions never change compliance status automatically.

AI Review

Let AI do the first review. Keep humans in control.

AI can review assessment responses, detect missing evidence, extract information from documents, analyze contracts and suggest potential risks. Every compliance decision stays with your team.

  • Suggestions are always labelled and reviewable
  • Findings carry a confidence score and a source reference
  • Nothing changes compliance status without human approval
  • AI features can be disabled per workspace
Explore AI Review

AI Finding

78% confidence

Disaster recovery testing evidence is missing.

The response describes testing but no test report was attached for the current period. Requires human review before any compliance decision.

Accept & create riskDismissRequest clarification

Reviewed by Sarah Martin · AI suggestions never change compliance status automatically.

Contract Review

Find DORA contract gaps faster.

Contract Coverage: 78% · 3 clauses need review.

  • Audit rights
  • Incident notification
  • Regulatory access
  • Subcontracting
  • Business continuity
  • Data location
  • Termination
  • Exit strategy
Explore Contract Review
relynt.io/contracts/CTR-1002

CTR-1002 · Northwind Cloud Ireland Ltd

3 clauses need review

DORA Article 30 clause coverage · analysed 7 August 2026

Article 30 clauses

11 unresolved

  • Audit rightsCovered
  • Incident notificationCovered
  • Regulatory accessCovered
  • SubcontractingNeeds Review
  • Business continuityCovered
  • Data locationNeeds Review
  • TerminationCovered
  • Exit strategyMissing

Risk management

Turn findings into action.

  • Create a risk directly from an assessment, evidence or contract finding
  • Assign an owner and set severity
  • Add a mitigation plan and due date
  • Accept a risk with documented rationale
  • Resolve risks and keep the full history
Explore Risk Management
relynt.io/risks

Risk Register

7 high risks · 18 open · linked to assessments, evidence and contracts

IDRiskProviderSeverityStatusOwner
RSK-311DR testing evidence not providedHalcyonHighMitigation PlannedS. Martin
RSK-318Exit strategy absent from contractNorthwind CloudHighOpenT. Weber
RSK-324Subcontractor countries incompletePayfluxMediumIn ReviewL. Dubois
RSK-327Pen test older than 12 monthsLumendataMediumOpenS. Martin
RSK-330No documented incident SLAValteraLowAcceptedM. Rossi

Evidence

Stop chasing expired compliance documents.

SOC 2, ISO 27001, penetration tests, business continuity plans and disaster recovery tests tracked as Valid, Expiring, Expired or Missing.

  • Automated evidence requests to vendors
  • Expiry tracking with early warnings
  • Documents linked to providers, services and risks
  • Review queue for newly submitted evidence
Explore Evidence Management
relynt.io/evidence

Evidence Library

418 documents · 23 missing · 11 expiring within 60 days

Request Evidence
  • SOC 2 Type II

    Halcyon Cloud Services

    Valid
  • ISO 27001

    Northwind Cloud Ireland

    Valid
  • Penetration Test

    Payflux Payments Europe

    Expiring
  • Business Continuity Plan

    Lumendata Netherlands

    Expired
  • Disaster Recovery Test

    Halcyon Cloud Services

    Missing

Supply chain

See beyond your direct ICT providers.

Capture subcontractors, countries, data locations and dependencies associated with each ICT service.

  • Record subcontractors declared during assessments
  • Track country and data location per dependency
  • Flag incomplete supply-chain records for the Register
  • Understand concentration across shared providers
  • Your Organization

    Meridian Bank Europe · Netherlands

  • Halcyon

    ICT Provider · Ireland · Critical

  • ICT Service

    Core hosting for payments platform

  • Subcontractor

    Regional CDN partner · Germany

How it works

From vendor inventory to DORA-ready reporting.

  1. 1

    Import ICT providers

  2. 2

    Classify critical services

  3. 3

    Launch assessments

  4. 4

    Collect evidence

  5. 5

    Review contracts

  6. 6

    Track risks and remediation

  7. 7

    Maintain the DORA Register

Who it is for

Built for regulated financial organizations.

Typically used by compliance, ICT risk, procurement and operational resilience teams. Whether a specific entity falls within DORA scope depends on its own regulatory analysis.

Banks
Fintechs
Payment Institutions
Insurance Companies
Investment Firms
Asset Managers

Why it is different

DORA workflows, not another generic GRC platform.

Generic GRC
Relynt
Generic vendor records
ICT Provider + Service mapping
Generic questionnaires
DORA-focused vendor assessments
Document repository
Evidence connected to provider risk
Manual contract review
AI-assisted contract analysis
Spreadsheet Register
Connected DORA Register
Periodic review
Continuous readiness view

Security

Built for sensitive compliance data.

We label what is available today and what is planned. We do not claim certifications we do not hold.

Encryption in transit and at rest

Available

Role-based access control

Available

Audit logs

Available

Tenant isolation

Available

EU data hosting

Available

Multi-factor authentication

Available

SSO / SAML

Enterprise

Retention and legal hold

Available
View Security

Pricing

Plans that scale with your ICT provider portfolio.

Essential

€149/month

For smaller regulated organizations.

  • Up to 50 ICT providers · 5 users
  • Vendor Qualification Register
  • Assessments, evidence and risk register
  • Article 30 contract gap register
  • DORA Register and Management Body Report
  • Resilience testing programme
Try the demo

Professional

Most Popular

€399/month

For growing compliance and ICT risk teams.

  • Up to 100 ICT providers · 15 users
  • Everything in Essential
  • AI assessment, evidence and contract review
  • Advanced Article 30 gap analysis
  • Testing coverage analytics
  • Priority support
Try the demo

Enterprise

Custom

For groups with multiple legal entities.

  • Custom provider and user limits
  • SSO / SAML sign-in
  • SLA and dedicated support
Try the demo

Compare all plan details

See what your own Register would say.

Check a filing you already have, free and without an account, or open a demo workspace with a worked Register in it. Neither asks for your email.

ICT Provider
Criticality
Assessment
Evidence
Contract Review
DORA Third-Party Risk and Register Software | Relynt