Ariadnah
Platform
DORA Understand the responsibilities, common operating gaps, and the path from shared knowledge to evidence. AML & KYC Customer due diligence with the ownership look-through resolved as data. Risk & Control One control catalogue, read through every framework it answers to. Governance & Policies Policies drafted, mapped to requirements clause by clause, and approved in the platform.

Platform

  • Platform overview
  • AI assistant
  • Security & trust
  • Impact & access

Domains and services

  • Register of Information
  • Suppliers & Contracts
  • Asset Management
  • Risk & Control
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • Governance & Policies
  • Incident Management
  • All solutions →

By sector

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services
  • All sectors →
About Pricing Insights Resources Contact
Book a Discovery Call
Home About Platform Solutions Sectors Pricing Insights Resources DORA Guide NIS2 Guide Contact
Book a Discovery Call
Insights

Referential integrity

Ariadnah Solutions DORA 23 Jul 2025 3 min read

Many organizations are using Excel to set up and manage their DORA Register of Information (RoI) but Excel simply isn’t built for this task.

The problem lies in the complexity of relational data. DORA expects strict links between entities, contracts, services, and providers. Excel offers none of the built-in safeguards to maintain this structure.

01

Excel’s fundamental limitations

The DORA register consists of interlinked tables for example, contracts must link to service providers, and business functions must link to ICT services. In this structure, referential integrity is critical. If one row refers to a vendor, that vendor must exist elsewhere in the register and stay consistent.

With Excel, it’s all too easy to:

  • Reference non-existent vendors
  • Paste data in the wrong sheet
  • Forget to update linked rows after a change

These mistakes introduce hidden errors and compliance risks.

02

The importance of referential integrity

Under DORA, the RoI includes multiple templates, each representing a specific domain (e.g., contracts, functions, providers). These tables must link precisely.

If a contract points to a provider ID, that provider must exist and match the expected format. In a recent ESA pilot, most institutions failed validation because of issues like:

  • Missing or mismatched IDs
  • Invalid entity codes
  • Incomplete fields

Only a small minority passed the validation phase without serious corrections.

03

Why Excel isn’t a relational database

Excel is a spreadsheet, not a database. It doesn’t enforce the logic required for relational models. Here’s why that’s a problem:

  • No built-in referential checks: Excel can’t guarantee that IDs used across sheets are valid or unique
  • Data redundancy: The same info is often copied into multiple tabs, which go out of sync
  • No automated rules: Excel relies on user diligence, and humans make mistakes

A single broken link or deleted row can cascade into compliance errors.

04

Human error and growing complexity

As your register grows and more users contribute, the chance of error increases. Manual updates, edits across tabs, and duplicated data mean even the most organized Excel file will drift from accuracy over time.

05

Ongoing maintenance: the hidden pitfall

Even if you build a clean Excel file to start, maintenance is where things fall apart:

  • New contracts must be added in multiple places
  • A single forgotten update can break internal links
  • Inconsistencies may only be discovered at the time of audit or regulatory submission

This introduces compliance risk and undermines the trustworthiness of your data.

06

Avoiding a false sense of security

Because Excel feels familiar, it creates the illusion of control. But under the surface, you’re working without guardrails. Excel doesn’t stop you from making errors, and you may not spot them until it’s too late.

07

Conclusion

The DORA Register of Information demands relational integrity and high data quality.

Excel lacks the tools to enforce that structure. While it may be useful for early drafts, it’s not a viable solution for ongoing compliance.

To meet DORA's standards and reduce risk:

  • Use tools that are purpose-built for relational data
  • Automate integrity checks and updates
  • Eliminate manual processes wherever possible

08

Stay informed

Want more insights on DORA best practices and tooling?

  • Get practical tips for setting up your RoI
  • Receive invites to webinars and peer discussions
  • Access early demos of new tools

Originally published on DORA Solutions Insights.

Continue with DORA

Put this question in context.

The DORA guide connects this issue to governance, ICT risk, incidents, resilience testing, third-party risk and the Register of Information.

Recommended next Read the DORA compliance guide →
Explore the operating approach See the regulatory reporting approach Related analysis One Contract, How Many Countries? Related analysis How to report intra-group ICT service providers in your register of information
Manage Consent
We use cookies to keep this site reliable and to understand how it is used. You can accept, deny, or adjust your preferences at any time.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ariadnah

Compliance advisory & technology

Regulatory specialists and technology that help organisations simplify compliance, strengthen operational resilience, and build lasting trust.

ISO/IEC 27001 certified (DNV)

Platform

  • Platform Overview
  • DORA Guide
  • NIS2 Guide
  • Regulatory Library
  • Register of Information
  • Risk & Control
  • Governance & Policies
  • Incident Management
  • Asset Management
  • Suppliers & Contracts
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • AI
  • Security

Sectors

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services

Company

  • About Ariadnah
  • Pricing
  • Our Experts
  • Impact
  • FAQ
  • Insights
  • Contact

Legal

  • General Terms
  • Data & Privacy
  • Cookie Policy
  • Accessibility

© 2026 Ariadnah Solutions B.V.