Ariadnah
Platform
DORA Understand the responsibilities, common operating gaps, and the path from shared knowledge to evidence. AML & KYC Customer due diligence with the ownership look-through resolved as data. Risk & Control One control catalogue, read through every framework it answers to. Governance & Policies Policies drafted, mapped to requirements clause by clause, and approved in the platform.

Platform

  • Platform overview
  • AI assistant
  • Security & trust
  • Impact & access

Domains and services

  • Register of Information
  • Suppliers & Contracts
  • Asset Management
  • Risk & Control
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • Governance & Policies
  • Incident Management
  • All solutions →

By sector

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services
  • All sectors →
About Pricing Insights Resources Contact
Book a Discovery Call
Home About Platform Solutions Sectors Pricing Insights Resources DORA Guide NIS2 Guide Contact
Book a Discovery Call
Insights

Understanding RT.03: mapping ICT contractual relationships under DORA

Ariadnah Solutions DORA 23 Jul 2025 2 min read

01

The purpose of RT.03

RT.03 is the cornerstone of mapping contractual relationships in your ICT service landscape. It’s designed to create a clear picture of who’s signing what, who’s providing services, and how these services flow within your organization or group.

The ITS divides RT.03 into three essential templates, each serving a specific purpose in untangling this web of relationships.

02

Breaking down RT.03: the three templates

1. RT.03.01 – Who’s signing for receiving ICT services?

This template identifies the entities in your organization signing ICT service contracts. As the ITS states, “the entity signing the contractual arrangement and the entity making use of the ICT services are not necessarily the same.”

Example: In a medium-sized insurance group, the parent company might sign a cloud services contract that’s used by multiple subsidiaries.

2. RT.03.02 – Who are your external ICT service providers?

Here, you list all external ICT service providers signing contracts with your organization. The ITS requires you to identify “all the ICT third-party service providers referred to in template RT.05.01 signing the contractual arrangements referred to in template RT.02.01.”

Example: This could include major cloud providers or software vendors where the signing party and service provider differ. You only map the party signing the contract.

3. RT.03.03 – Who’s providing ICT services within your group?

This template captures intra-group ICT service provision, ensuring these services receive the same scrutiny as external ones.

Example: An internal IT subsidiary providing helpdesk services to other business units.

03

Who needs to pay special attention to RT.03?

  • Small, standalone entities: Focus primarily on RT.03.02 for external providers.
  • Large or complex organizations: All three templates become crucial. In group structures, the service user and the contract signer may be different entities.

04

Common pitfalls and how to avoid them

  • Misidentifying contractual parties: Carefully review which entity is signing the ICT contract, especially in group structures.
  • Inconsistencies across templates: Ensure RT.03 aligns with RT.01.02 (entities), RT.02.01 (contracts), and RT.05.01 (providers).
  • Overlooking intra-group services: Document internal ICT services thoroughly.
  • Failing to update: Keep RT.03 current as your ICT landscape evolves.

05

Conclusion

RT.03 is more than a bureaucratic requirement — it’s a strategic tool for understanding and managing your ICT service landscape. It clarifies who is signing, who is providing, and how ICT services flow across your organization.

But it can be complex. Manually mapping these relationships and ensuring consistency across templates is time-consuming and error-prone.

This is where specialized tooling can help. DORA-compliant tools can automate entry, enforce consistency, and provide user-friendly interfaces for mapping relationships.

Remember: the DORA register isn’t just about compliance — it’s about insight and control. RT.03 plays a critical role in helping financial institutions manage their ICT risks effectively.

Yes, keep me informed!

Originally published on DORA Solutions Insights.

Continue with DORA

Put this question in context.

The DORA guide connects this issue to governance, ICT risk, incidents, resilience testing, third-party risk and the Register of Information.

Recommended next Read the DORA compliance guide →
Explore the operating approach See the supplier and contract approach Related analysis The Risk You Didn’t Sign Related analysis DORA Supply-Chain Reporting: When Granularity Creates Noise
Manage Consent
We use cookies to keep this site reliable and to understand how it is used. You can accept, deny, or adjust your preferences at any time.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ariadnah

Compliance advisory & technology

Regulatory specialists and technology that help organisations simplify compliance, strengthen operational resilience, and build lasting trust.

ISO/IEC 27001 certified (DNV)

Platform

  • Platform Overview
  • DORA Guide
  • NIS2 Guide
  • Regulatory Library
  • Register of Information
  • Risk & Control
  • Governance & Policies
  • Incident Management
  • Asset Management
  • Suppliers & Contracts
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • AI
  • Security

Sectors

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services

Company

  • About Ariadnah
  • Pricing
  • Our Experts
  • Impact
  • FAQ
  • Insights
  • Contact

Legal

  • General Terms
  • Data & Privacy
  • Cookie Policy
  • Accessibility

© 2026 Ariadnah Solutions B.V.