A Register of Information can be technically valid and still give a poor account of risk. Structural checks can show that the fields are populated and the relationships resolve. They cannot show whether the firm made good judgements about criticality, dependencies or where a service would actually break.
That leaves a second question: who can tell the difference?
01
What the EBA report tells us
In February 2026, the European Banking Authority published its follow-up to the 2022 peer review of ICT risk assessment under the Supervisory Review and Evaluation Process. The report is about ICT supervision of credit institutions. It is not an assessment of how well authorities read DORA Registers of Information.
It does, however, describe the supervisory machinery that would make serious use of the register possible: ICT expertise, common methods, horizontal comparison and tools that can work across large datasets.
The EBA records “noticeable progress” in horizontal and thematic analysis, while saying that “full maturity is yet to be achieved”. More in-depth horizontal work was planned from 2026 onward. Authorities are automating incident and register collection at different speeds. One Dutch authority is already using an AI system to assess whether third-party contracts meet DORA requirements.
The direction is clear. The pace is uneven.
02
A valid file can still be a weak register
In 2025, every competent authority collected and aggregated Registers of Information covering EU credit institutions. That created the basis for comparisons across firms and providers. If two hundred institutions depend on the same cloud provider, differences in how that dependency is recorded become visible.
Visible does not always mean understood.
A tidy register may reflect a well-run process. It may also reflect safe answers: one country where the service spans several, uniform criticality where functions differ, or “not applicable” wherever the template asks for judgement. A more candid register can look less orderly because the underlying risk is less orderly.
Both files may clear structural validation. Distinguishing them requires context. The reader needs to know what the provider normally looks like, how comparable firms report it and where the reporting firm has simplified something that matters.
03
Some weaknesses are easier to see
The register is made of fifteen linked templates. Contracts point to entities, providers, services and functions recorded elsewhere. Those links offer a basic test before any deeper comparison begins.
A register maintained through real supplier onboarding, contract review and service ownership tends to hold together because the process keeps the relationships current. A register assembled shortly before filing has to reconstruct them. The weak points usually appear in the difficult fields: subcontracting chains, service locations, critical functions and the identity of the provider behind the contract.
This is not an argument against spreadsheets. The EBA template can support a sound return, particularly for a smaller firm with a manageable number of arrangements. The issue is whether the method preserves the relationships and the judgement behind them after the filing date.
We build software for this work, so our view is not neutral. Still, the distinction matters: format errors are easy to validate; weak reasoning is not.
04
File for the reader who is coming
The EBA report is encouraging. Authorities are building expertise, using more horizontal analysis and investing in tools. It is also frank that the capability is not equally mature everywhere.
For a firm, that should not change the filing standard. A reflective register remains the safer choice even if a flatter, tidier version is easier to explain today. As comparison improves, simplifications that once looked harmless become easier to spot.
The register is ready to be read. The reading is still improving.
05
Primary source
- EBA/REP/2026/05: Follow-up Peer Review Report on ICT Risk Assessment under the SREP, especially paragraphs 23, 27, 30, 34 and 36.
- EBA press release, 23 February 2026.
This is an observation about supervisory development, not a conclusion about the quality of any individual authority or register.