DORA Register of Information: templates, build guide and data model
The most demanded artefact under DORA. A master Excel workbook aligned to the ITS on the Register of Information (Commission Implementing Regulation 2024/2956), with a Build Guide PDF, JSON Schema and SQL DDL for GRC import.
What this solves
The Register of Information is the one DORA deliverable with a hard annual date and a machine-readable format. It is not a document you write — it is a dataset you assemble, from contracts, from the CMDB and from people who do not think of themselves as data owners.
The first attempt is nearly always a spreadsheet that looks right and fails validation, because the coded fields take controlled vocabularies and the entities have to reference each other consistently.
What is inside
- Master Excel workbook with 16 RT tabs (RT.01–RT.07)
- Build Guide PDF — 18 pages of practitioner guidance
- JSON Schema (draft 2020-12) for validation
- SQL DDL for GRC / data-warehouse import
- Data-quality framework and validation rules
- Glossary and ITS service-type taxonomy
- Submission workflow checklist
What it covers in the regulation
- Article 28(3) — maintaining a register of information
- ITS (EU) 2024/2956 — register templates and data model
- Articles 29–30 — concentration risk and contractual content
- Annual submission to the competent authority
Who uses it, and when
Whoever has been handed the register — often vendor management, sometimes data or architecture. Used from the first data collection right through to submission.
How to work through it
- Map each ITS template to the system or team that already holds the data.
- Load the data model so relationships between entities, contracts and services are right from the start.
- Fill the coded fields from the controlled vocabularies, not free text.
- Validate before the deadline, not on it.