01
The purpose of RT.03
RT.03 is the cornerstone of mapping contractual relationships in your ICT service landscape. It’s designed to create a clear picture of who’s signing what, who’s providing services, and how these services flow within your organization or group.
The ITS divides RT.03 into three essential templates, each serving a specific purpose in untangling this web of relationships.
02
Breaking down RT.03: the three templates
1. RT.03.01 – Who’s signing for receiving ICT services?
This template identifies the entities in your organization signing ICT service contracts. As the ITS states, “the entity signing the contractual arrangement and the entity making use of the ICT services are not necessarily the same.”
Example: In a medium-sized insurance group, the parent company might sign a cloud services contract that’s used by multiple subsidiaries.
2. RT.03.02 – Who are your external ICT service providers?
Here, you list all external ICT service providers signing contracts with your organization. The ITS requires you to identify “all the ICT third-party service providers referred to in template RT.05.01 signing the contractual arrangements referred to in template RT.02.01.”
Example: This could include major cloud providers or software vendors where the signing party and service provider differ. You only map the party signing the contract.
3. RT.03.03 – Who’s providing ICT services within your group?
This template captures intra-group ICT service provision, ensuring these services receive the same scrutiny as external ones.
Example: An internal IT subsidiary providing helpdesk services to other business units.
03
Who needs to pay special attention to RT.03?
- Small, standalone entities: Focus primarily on RT.03.02 for external providers.
- Large or complex organizations: All three templates become crucial. In group structures, the service user and the contract signer may be different entities.
04
Common pitfalls and how to avoid them
- Misidentifying contractual parties: Carefully review which entity is signing the ICT contract, especially in group structures.
- Inconsistencies across templates: Ensure RT.03 aligns with RT.01.02 (entities), RT.02.01 (contracts), and RT.05.01 (providers).
- Overlooking intra-group services: Document internal ICT services thoroughly.
- Failing to update: Keep RT.03 current as your ICT landscape evolves.
05
Conclusion
RT.03 is more than a bureaucratic requirement — it’s a strategic tool for understanding and managing your ICT service landscape. It clarifies who is signing, who is providing, and how ICT services flow across your organization.
But it can be complex. Manually mapping these relationships and ensuring consistency across templates is time-consuming and error-prone.
This is where specialized tooling can help. DORA-compliant tools can automate entry, enforce consistency, and provide user-friendly interfaces for mapping relationships.
Remember: the DORA register isn’t just about compliance — it’s about insight and control. RT.03 plays a critical role in helping financial institutions manage their ICT risks effectively.
Originally published on DORA Solutions Insights.