A Register of Information, checked before you file it.
Relynt assembles the Register from the records you already keep, in the format the regulation defines, and checks it for the problems that get a filing sent back. Every row traces to the provider, contract or service it came from.
For payment and e-money institutions, investment firms, asset managers and insurers in the EU. Assessments, evidence, contracts and risk sit underneath it.
DORA Third-Party Risk Overview
Meridian Bank Europe · updated 9 August 2026
ICT Providers
96
Critical Providers
18
Register errors
3
Register warnings
9
High Risks
7
Missing Evidence
23
Outstanding
- Register errors blocking filing3
- Register warnings9
- Evidence documents missing23
- Article 30 clauses unresolved11
- Assessments overdue2
Attention Required
View allHalcyon assessment expires soon
Annual ICT Risk Assessment 2026 · due 18 Aug
Northwind Cloud contract needs review
Exit strategy clause not documented
Payflux evidence expires next month
SOC 2 Type II report valid until 14 Sep
Built for data a financial entity cannot afford to lose
- Hosted in the EU, in Frankfurt
- Encrypted in transit and at rest
- Tenant isolation enforced in the database
- Two-factor authentication, enforceable workspace-wide
- Role-based access
- Append-only audit trail you can export
The problem
The Register is the deliverable, and it is the hardest part to get right.
It is fifteen linked templates with keys that have to resolve between them and columns that only accept the regulation's own codes. Assembled by hand in a spreadsheet it drifts from operations within weeks, and the problems that stop a filing are structural rather than matters of judgement: an empty key, a label where a code belongs, a reference pointing at nothing.
Vendor information scattered across teams
Procurement, security and compliance each keep their own list of ICT providers and services.
Assessments managed manually
Questionnaires travel by email and spreadsheet, and progress is impossible to track.
Contracts difficult to review consistently
Article 30 requirements are checked differently by each reviewer, with no shared record.
DORA Register difficult to maintain
The Register is rebuilt from scratch each reporting cycle and drifts from operational reality.
Which is why the Register cannot be a document you assemble once a year. It is only right if the providers, services, contracts and evidence underneath it are right on the day you file.
DORA Register of Information
Build and maintain your DORA Register continuously.
Connect providers, ICT services, contracts, critical functions and subcontractors so the Register stays aligned with your operational data.
Register of Information
Reporting entity: Meridian Bank Europe · LEI 549300XKZ9Q2P1F4T083
Templates with rows
12 of 15
Errors
3
Warnings
9
Validation issues
- B_02.02Function identifier is empty. Every key column has to resolve.Error
- B_05.02Identification code of the recipient of sub-contracted ICT services is empty.Error
- B_02.01Holds "Payment Services", which is not one of the nineteen permitted service types.Error
- B_01.01Competent Authority is empty. A supervisor will ask about this.Warning
- B_02.02Location of the data at rest is empty.Warning
Halcyon
Missing contractual arrangement reference.
Payflux
Subcontractor country incomplete.
Northwind Cloud
Exit strategy not documented.
Then filed, not retyped
All fifteen templates of Implementing Regulation (EU) 2024/2956, in xBRL-CSV, with the regulation's own codes and every key checked before you submit.
Platform
One system for the entire ICT third-party risk lifecycle.
Every object is connected, so a change in one place updates the record everywhere it matters.
ICT Provider
Criticality
Assessment
Evidence
Contract Review
Risk
Remediation
DORA Register
Provider → service → assessment → evidence → contract clause → risk → remediation → Register field. Each link is preserved as an auditable record.
Data lineage
Every row of the Register has a source.
Compliance teams can trace each row back to the provider, contract, ICT service or critical function it was assembled from, with the person and date behind the last change to that record.
- Trace Register rows to providers, services, contracts and functions
- See the workspace's own wording beside the code it was mapped to
- Know who last changed the record behind a row, and when
- Answer regulator questions without rebuilding the trail
Register field · lineage
Traceable- Template
- B_02.02 · column 0160
- Field
- Location of management of the data
- Value
- DE
- Source
- Service · Northwind Cloud Production Hosting
- Arrangement
- Contract · Northwind Cloud MSA 2026
- Last changed
- Sarah Martin · 12 July 2026
ICT Providers
Know every ICT provider and what they support.
- Centralize ICT providers in one inventory
- Map ICT services to each provider
- Identify critical and important providers
- Track countries and data locations
- Link providers to critical or important functions
- Assign internal owners
ICT Providers
96 providers · 18 critical
| Provider | ICT Service | Criticality | Country | Risk |
|---|---|---|---|---|
| Halcyon Cloud Services | Cloud Infrastructure | Critical | Ireland | High |
| Northwind Cloud Ireland | Cloud & Productivity | Critical | Ireland | Medium |
| Payflux Payments Europe | Payment Processing | Critical | Ireland | High |
| Lumendata Netherlands | Data Platform | Important | Netherlands | Medium |
| Edgeway Germany | Network & Security | Important | Germany | Low |
| Valtera | Core Banking | Critical | Switzerland | Medium |
Vendor Assessments
Run vendor assessments without chasing spreadsheets.
- Send structured DORA questionnaires
- Give vendors a self-service portal
- Track progress section by section
- Request evidence inside the questionnaire
- Review responses in a single workspace
- Identify potential gaps before sign-off
ASM-2041 · Halcyon Annual ICT Assessment
Under Review117 questions · 12 sections · vendor submitted 4 August 2026
Section progress
- Governance & Oversight100%
- Information Security92%
- Business Continuity64%
- Incident Management88%
- Subcontracting45%
Q 4.3 · Business Continuity
Describe the frequency and scope of your disaster recovery testing.
“DR testing is performed periodically across production regions.”
AI Finding
78% confidenceDisaster recovery testing evidence is missing.
The response describes testing but no test report was attached for the current period. Requires human review before any compliance decision.
Reviewed by Sarah Martin · AI suggestions never change compliance status automatically.
AI Review
Let AI do the first review. Keep humans in control.
AI can review assessment responses, detect missing evidence, extract information from documents, analyze contracts and suggest potential risks. Every compliance decision stays with your team.
- Suggestions are always labelled and reviewable
- Findings carry a confidence score and a source reference
- Nothing changes compliance status without human approval
- AI features can be disabled per workspace
AI Finding
78% confidenceDisaster recovery testing evidence is missing.
The response describes testing but no test report was attached for the current period. Requires human review before any compliance decision.
Reviewed by Sarah Martin · AI suggestions never change compliance status automatically.
Contract Review
Find DORA contract gaps faster.
Contract Coverage: 78% · 3 clauses need review.
- Audit rights
- Incident notification
- Regulatory access
- Subcontracting
- Business continuity
- Data location
- Termination
- Exit strategy
CTR-1002 · Northwind Cloud Ireland Ltd
3 clauses need reviewDORA Article 30 clause coverage · analysed 7 August 2026
Article 30 clauses
11 unresolved
- Audit rightsCovered
- Incident notificationCovered
- Regulatory accessCovered
- SubcontractingNeeds Review
- Business continuityCovered
- Data locationNeeds Review
- TerminationCovered
- Exit strategyMissing
Risk management
Turn findings into action.
- Create a risk directly from an assessment, evidence or contract finding
- Assign an owner and set severity
- Add a mitigation plan and due date
- Accept a risk with documented rationale
- Resolve risks and keep the full history
Risk Register
7 high risks · 18 open · linked to assessments, evidence and contracts
| ID | Risk | Provider | Severity | Status | Owner |
|---|---|---|---|---|---|
| RSK-311 | DR testing evidence not provided | Halcyon | High | Mitigation Planned | S. Martin |
| RSK-318 | Exit strategy absent from contract | Northwind Cloud | High | Open | T. Weber |
| RSK-324 | Subcontractor countries incomplete | Payflux | Medium | In Review | L. Dubois |
| RSK-327 | Pen test older than 12 months | Lumendata | Medium | Open | S. Martin |
| RSK-330 | No documented incident SLA | Valtera | Low | Accepted | M. Rossi |
Evidence
Stop chasing expired compliance documents.
SOC 2, ISO 27001, penetration tests, business continuity plans and disaster recovery tests tracked as Valid, Expiring, Expired or Missing.
- Automated evidence requests to vendors
- Expiry tracking with early warnings
- Documents linked to providers, services and risks
- Review queue for newly submitted evidence
Evidence Library
418 documents · 23 missing · 11 expiring within 60 days
- Expires 30 Nov 2026Valid
SOC 2 Type II
Halcyon Cloud Services
- Expires 21 Mar 2027Valid
ISO 27001
Northwind Cloud Ireland
- Expires 14 Sep 2026Expiring
Penetration Test
Payflux Payments Europe
- Expired 2 Jun 2026Expired
Business Continuity Plan
Lumendata Netherlands
- Requested 4 Aug 2026Missing
Disaster Recovery Test
Halcyon Cloud Services
Supply chain
See beyond your direct ICT providers.
Capture subcontractors, countries, data locations and dependencies associated with each ICT service.
- Record subcontractors declared during assessments
- Track country and data location per dependency
- Flag incomplete supply-chain records for the Register
- Understand concentration across shared providers
Your Organization
Meridian Bank Europe · Netherlands
Halcyon
ICT Provider · Ireland · Critical
ICT Service
Core hosting for payments platform
Subcontractor
Regional CDN partner · Germany
How it works
From vendor inventory to DORA-ready reporting.
- 1
Import ICT providers
- 2
Classify critical services
- 3
Launch assessments
- 4
Collect evidence
- 5
Review contracts
- 6
Track risks and remediation
- 7
Maintain the DORA Register
Who it is for
Built for regulated financial organizations.
Typically used by compliance, ICT risk, procurement and operational resilience teams. Whether a specific entity falls within DORA scope depends on its own regulatory analysis.
Why it is different
DORA workflows, not another generic GRC platform.
Security
Built for sensitive compliance data.
We label what is available today and what is planned. We do not claim certifications we do not hold.
Encryption in transit and at rest
AvailableRole-based access control
AvailableAudit logs
AvailableTenant isolation
AvailableEU data hosting
AvailableMulti-factor authentication
AvailableSSO / SAML
EnterpriseRetention and legal hold
AvailablePricing
Plans that scale with your ICT provider portfolio.
Essential
€149/month
For smaller regulated organizations.
- Up to 50 ICT providers · 5 users
- Vendor Qualification Register
- Assessments, evidence and risk register
- Article 30 contract gap register
- DORA Register and Management Body Report
- Resilience testing programme
Professional
Most Popular€399/month
For growing compliance and ICT risk teams.
- Up to 100 ICT providers · 15 users
- Everything in Essential
- AI assessment, evidence and contract review
- Advanced Article 30 gap analysis
- Testing coverage analytics
- Priority support
Enterprise
Custom
For groups with multiple legal entities.
- Custom provider and user limits
- SSO / SAML sign-in
- SLA and dedicated support
See what your own Register would say.
Check a filing you already have, free and without an account, or open a demo workspace with a worked Register in it. Neither asks for your email.