Ariadnah
Platform
DORA Understand the responsibilities, common operating gaps, and the path from shared knowledge to evidence. AML & KYC Customer due diligence with the ownership look-through resolved as data. Risk & Control One control catalogue, read through every framework it answers to. Governance & Policies Policies drafted, mapped to requirements clause by clause, and approved in the platform.

Platform

  • Platform overview
  • AI assistant
  • Security & trust
  • Impact & access

Domains and services

  • Register of Information
  • Suppliers & Contracts
  • Asset Management
  • Risk & Control
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • Governance & Policies
  • Incident Management
  • All solutions →

By sector

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services
  • All sectors →
About Pricing Insights Resources Contact
Book a Discovery Call
Home About Platform Solutions Sectors Pricing Insights Resources DORA Guide NIS2 Guide Contact
Book a Discovery Call
Insights

Financial data in the DORA register: what to report and how to collect it

Ariadnah Solutions DORA 23 Jul 2025 3 min read

If you're grappling with the Digital Operational Resilience Act (DORA) register, you've probably wondered about the financial data requirements. What exactly do you need to report? And how can you make this data collection work smoothly? This article breaks down the specific reporting requirements, explains why they matter, and offers practical advice to help you navigate this compliance step.

01

Importance of financial data in DORA

The financial data required in the DORA register is critical for understanding your organization’s dependencies on ICT service providers and ensuring regulatory compliance. Accurately reporting this data not only meets obligations but also helps your organization gain insights into its ICT dependencies, manage outsourcing risks, and make informed strategic decisions.

The DORA register requires detailed financial information related to ICT service providers. Here’s a step-by-step guide to gathering and organizing this data effectively.

02

Step 1: The contract perspective – RT.02.01

The first step is to take the contract perspective. This is based on template RT.02.01, which focuses on individual contractual arrangements. According to the Implementing Technical Standards (Annex I, Part 2), you need to report:

  • Annual expense or estimated cost of the contract for the past year (RT.02.01.0050)
  • Currency of the amount reported (RT.02.01.0040)

When preparing the register, this means you need a breakdown of annual spend on ICT providers at the contract level. You can search the contract or sales order for pricing or ask a finance colleague for an overview of annual ICT service provider spend, broken down per contract.

Be mindful of the broad definition of an ICT service provider. To avoid missing any, conduct an inventory of in-scope ICT service providers first.

If you have multiple contracts with the same provider, refer to these ITS instructions:

  • Total cost alignment: All related arrangements must sum to the total cost of the overarching contract.
  • Zero-cost overarching arrangements: If the top-level contract has no cost, report cost at the level of each associated document.
  • Unspecified sub-arrangement costs: If you can’t break it down, report total cost under the main contract.
  • Costs at multiple levels: Avoid duplication by reporting cost only once per contract structure.

In practice, most contracts are standalone arrangements. Associated documents like DPAs or addenda are usually not treated as separate contracts.

03

Step 2: The ICT provider perspective – RT.05.01

The second step is to take the ICT provider perspective, based on template RT.05.01. It gives a consolidated view of annual spend per ICT third-party service provider. You must report:

  • Total annual expense or estimated cost per provider (RT.05.01.0070)
  • Currency of the amount reported (RT.05.01.0060)

This is essentially the sum of contract-level expenses from RT.02.01 per provider. It applies only to external third-party providers — not intra-group ones.

Ensure that totals reconcile between RT.05.01 and RT.02.01. Identify all relevant contracts per provider.

04

Common pitfalls and how to avoid them

  • Inconsistency between views: Reconcile contract-level and provider-level expenses to avoid discrepancies.
  • Wrong reporting period: Use the actual or estimated annual cost for the past year.
  • Failing to update: This is not a one-time task. Annual updates are required to keep financial data current.

05

Conclusion and benefits

Financial data in your DORA register isn’t just about compliance — it’s a tool for understanding ICT risk and strategic decision-making. Accurate financial reporting gives clarity into your digital supply chain.

Although gathering and maintaining this data can be challenging, especially across templates, tools designed for DORA compliance can automate data collection, ensure consistency, and simplify your reporting process.

If you want to take the pain out of building and maintaining the DORA register and accelerate your progress:

Reach out for a demo of our prebuilt DORA register

Originally published on DORA Solutions Insights.

Continue with DORA

Put this question in context.

The DORA guide connects this issue to governance, ICT risk, incidents, resilience testing, third-party risk and the Register of Information.

Recommended next Read the DORA compliance guide →
Explore the operating approach See the asset and dependency approach Related analysis How to Map ICT Services to Business Functions: A Complete Yet Proportionate Approach Related analysis illustrative example: business functions of a venture capital fund manager
Manage Consent
We use cookies to keep this site reliable and to understand how it is used. You can accept, deny, or adjust your preferences at any time.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ariadnah

Compliance advisory & technology

Regulatory specialists and technology that help organisations simplify compliance, strengthen operational resilience, and build lasting trust.

ISO/IEC 27001 certified (DNV)

Platform

  • Platform Overview
  • DORA Guide
  • NIS2 Guide
  • Regulatory Library
  • Register of Information
  • Risk & Control
  • Governance & Policies
  • Incident Management
  • Asset Management
  • Suppliers & Contracts
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • AI
  • Security

Sectors

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services

Company

  • About Ariadnah
  • Pricing
  • Our Experts
  • Impact
  • FAQ
  • Insights
  • Contact

Legal

  • General Terms
  • Data & Privacy
  • Cookie Policy
  • Accessibility

© 2026 Ariadnah Solutions B.V.