Ariadnah
Platform
DORA Understand the responsibilities, common operating gaps, and the path from shared knowledge to evidence. AML & KYC Customer due diligence with the ownership look-through resolved as data. Risk & Control One control catalogue, read through every framework it answers to. Governance & Policies Policies drafted, mapped to requirements clause by clause, and approved in the platform.

Platform

  • Platform overview
  • AI assistant
  • Security & trust
  • Impact & access

Domains and services

  • Register of Information
  • Suppliers & Contracts
  • Asset Management
  • Risk & Control
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • Governance & Policies
  • Incident Management
  • All solutions →

By sector

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services
  • All sectors →
About Pricing Insights Resources Contact
Book a Discovery Call
Home About Platform Solutions Sectors Pricing Insights Resources DORA Guide NIS2 Guide Contact
Book a Discovery Call
Insights

Who Reads the Register?

Dennis Remmelts DORA 1 Apr 2026 3 min read

A DORA Register of Information can pass structural checks and still give a poor account of risk. The harder question is who can tell the difference.

A Register of Information can be technically valid and still give a poor account of risk. Structural checks can show that the fields are populated and the relationships resolve. They cannot show whether the firm made good judgements about criticality, dependencies or where a service would actually break.

That leaves a second question: who can tell the difference?

01

What the EBA report tells us

In February 2026, the European Banking Authority published its follow-up to the 2022 peer review of ICT risk assessment under the Supervisory Review and Evaluation Process. The report is about ICT supervision of credit institutions. It is not an assessment of how well authorities read DORA Registers of Information.

It does, however, describe the supervisory machinery that would make serious use of the register possible: ICT expertise, common methods, horizontal comparison and tools that can work across large datasets.

The EBA records “noticeable progress” in horizontal and thematic analysis, while saying that “full maturity is yet to be achieved”. More in-depth horizontal work was planned from 2026 onward. Authorities are automating incident and register collection at different speeds. One Dutch authority is already using an AI system to assess whether third-party contracts meet DORA requirements.

The direction is clear. The pace is uneven.

02

A valid file can still be a weak register

In 2025, every competent authority collected and aggregated Registers of Information covering EU credit institutions. That created the basis for comparisons across firms and providers. If two hundred institutions depend on the same cloud provider, differences in how that dependency is recorded become visible.

Visible does not always mean understood.

A tidy register may reflect a well-run process. It may also reflect safe answers: one country where the service spans several, uniform criticality where functions differ, or “not applicable” wherever the template asks for judgement. A more candid register can look less orderly because the underlying risk is less orderly.

Both files may clear structural validation. Distinguishing them requires context. The reader needs to know what the provider normally looks like, how comparable firms report it and where the reporting firm has simplified something that matters.

03

Some weaknesses are easier to see

The register is made of fifteen linked templates. Contracts point to entities, providers, services and functions recorded elsewhere. Those links offer a basic test before any deeper comparison begins.

A register maintained through real supplier onboarding, contract review and service ownership tends to hold together because the process keeps the relationships current. A register assembled shortly before filing has to reconstruct them. The weak points usually appear in the difficult fields: subcontracting chains, service locations, critical functions and the identity of the provider behind the contract.

This is not an argument against spreadsheets. The EBA template can support a sound return, particularly for a smaller firm with a manageable number of arrangements. The issue is whether the method preserves the relationships and the judgement behind them after the filing date.

We build software for this work, so our view is not neutral. Still, the distinction matters: format errors are easy to validate; weak reasoning is not.

04

File for the reader who is coming

The EBA report is encouraging. Authorities are building expertise, using more horizontal analysis and investing in tools. It is also frank that the capability is not equally mature everywhere.

For a firm, that should not change the filing standard. A reflective register remains the safer choice even if a flatter, tidier version is easier to explain today. As comparison improves, simplifications that once looked harmless become easier to spot.

The register is ready to be read. The reading is still improving.

05

Primary source

  • EBA/REP/2026/05: Follow-up Peer Review Report on ICT Risk Assessment under the SREP, especially paragraphs 23, 27, 30, 34 and 36.
  • EBA press release, 23 February 2026.

This is an observation about supervisory development, not a conclusion about the quality of any individual authority or register.

Continue with DORA

Put this question in context.

The DORA guide connects this issue to governance, ICT risk, incidents, resilience testing, third-party risk and the Register of Information.

Recommended next Read the DORA compliance guide →
Explore the operating approach Explore Ariadnah solutions Related analysis DORA for Microenterprises: Why size matters for your compliance journey Related analysis Why Excel isn’t enough for DORA reporting: key lessons from the ESA dry run
Manage Consent
We use cookies to keep this site reliable and to understand how it is used. You can accept, deny, or adjust your preferences at any time.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ariadnah

Compliance advisory & technology

Regulatory specialists and technology that help organisations simplify compliance, strengthen operational resilience, and build lasting trust.

ISO/IEC 27001 certified (DNV)

Platform

  • Platform Overview
  • DORA Guide
  • NIS2 Guide
  • Regulatory Library
  • Register of Information
  • Risk & Control
  • Governance & Policies
  • Incident Management
  • Asset Management
  • Suppliers & Contracts
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • AI
  • Security

Sectors

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services

Company

  • About Ariadnah
  • Pricing
  • Our Experts
  • Impact
  • FAQ
  • Insights
  • Contact

Legal

  • General Terms
  • Data & Privacy
  • Cookie Policy
  • Accessibility

© 2026 Ariadnah Solutions B.V.