DORA Register of Information: templates, build guide and data model
The most demanded artefact under DORA. A master Excel workbook aligned to the ITS on the Register of Information (Commission Implementing Regulation 2024/2956), with a Build Guide PDF, JSON Schema and SQL DDL for GRC import.
What this solves
The Register of Information is the one DORA deliverable with a hard annual date and a machine-readable format. It is not a document you write: it is a dataset you assemble, from contracts, from the CMDB and from people who do not think of themselves as data owners.
The first attempt is nearly always a spreadsheet that looks right and fails validation, because the coded fields take controlled vocabularies and the entities have to reference each other consistently.
What is inside
- Master Excel workbook with 16 RT tabs (RT.01–RT.07)
- Build Guide PDF — 18 pages of practitioner guidance
- JSON Schema (draft 2020-12) for validation
- SQL DDL for GRC / data-warehouse import
- Data-quality framework and validation rules
- Glossary and ITS service-type taxonomy
- Submission workflow checklist
What it covers in the regulation
- Article 28(3): maintaining a register of information
- ITS (EU) 2024/2956: register templates and data model
- Articles 29–30: concentration risk and contractual content
- Annual submission to the competent authority
Who uses it, and when
Whoever has been handed the register, often vendor management, sometimes data or architecture. Used from the first data collection right through to submission.
How to work through it
- Map each ITS template to the system or team that already holds the data.
- Load the data model so relationships between entities, contracts and services are right from the start.
- Fill the coded fields from the controlled vocabularies, not free text.
- Validate before the deadline, not on it.