About the DORA Register of Information (ROI):
Core Concept: The ROI is a fundamental element of the Digital Operational Resilience Act (DORA).
Purpose: It is a mandatory, structured record that financial entities must maintain to demonstrate compliance and operational resilience.
Structure: It is composed of 15 distinct reports that map and connect your organization's ICT supply chain to its associated ICT Services, Contracts, Sub-contracts, and both critical and non-critical Business Functions.
Business Functions as the Anchor: Business functions are the starting point and heart of the entire ROI. Financial entities begin by identifying their core business functions and evaluating their criticality (Critical or Important Functions - CIFs) based on how essential they are to maintaining continuous operations.
Regulatory Objective: While the ROI captures complex interdependencies across your ICT supply chain, this function-first approach ensures regulatory authorities can immediately trace which underlying technologies and vendors support the critical operations required to keep the business running.
Company Information
To ensure the Formalize platform functions correctly and generates accurate content, you must first complete the Company Information section.
To access these fields, navigate to Settings → General Settings → Company Information.
Locate the question: “Is your company going to be the financial entity maintaining and updating the register of information in terms of DORA?” You must select “Yes” as your answer to trigger and display the form.
In the section titled “Identification of the financial entity maintaining the register of information,” please complete all fields. Note that some fields use dropdown menus; ensure you select the option that best reflects your company’s reality.
Next, locate the section titled “Identification of financial entities within the scope of the register of information.” In this section, you must map all entities that fall within the scope of the ROI. This includes providing information about your own company, intra-group suppliers, the ultimate parent entity, and branches (if applicable).
Your own company: The first subsection relates specifically to your company. Complete the required fields here.
Intra-group suppliers (if applicable): If you have an intra-group supplier, click the “Add” button to create a new section. You must create exactly one section per intra-group supplier and fill in the relevant information.
The ultimate parent entity (if applicable): If your company has an Ultimate Parent, click the “Add” button to add a new section, then fill in all relevant information about the Ultimate Parent.
Branches (if applicable): Locate the question asking if the financial entity maintaining the register has branches located outside its home country. If this does not apply to your company, select “No.” If this does apply, select “Yes” and complete all required fields for each branch. You need to complete one section per branch.
To add multiple branches, simply click the “Add” button for each additional branch and fill in the required information.
How to map the relevant Resources
1. How to Map a Supplier
There are four kinds of suppliers that need to be mapped in Formalize: the Direct Supplier (Level 1), the Sub-supplier (Level 2), the Ultimate Parent, and the Intra-group Supplier.
To begin, navigate to the Resources section and select Suppliers. Follow the specific instructions below for the type of supplier you are adding.
Direct Supplier (Level 1) Adding a direct supplier: Click Add Supplier.
Trigger the form: Select “Yes” to the question: “Is this supplier considered an ICT third-party service provider in terms of DORA?”
Complete the required fields: Fill in the form with the required supplier-specific information. All following fields are mandatory because they populate specific columns in the ROI.
Note on Critical Functions: If the supplier supports a critical function, two additional fields will appear. If you do not have the information for the "Date of the last audit" field, leave it blank; it will automatically populate with the date 9999-12-31 upon exporting the report.
Sub-Supplier (Level 2)
Adding a sub-supplier: You can create a sub-supplier directly from the associated direct supplier's record. Open the direct supplier's record and click the "Create sub-supplier" button.
Ultimate Parent
The Ultimate Parent is defined as the "mother company" of your Direct Supplier (Level 1). Typically, for companies within a group structure, the Holding entity serves as the ultimate parent for all other group entities. While not every company has an ultimate parent, those that do must have it mapped.
Adding an ultimate parent: Click Add Supplier. Complete the "Name" field and other required fields, but you must deselect the "Direct supplier" box.
Trigger the form: Select “Yes” to the question: “Is this supplier considered an ICT third-party service provider in terms of DORA?”
Identification details: Only complete the “ICT Supplier identification details” section. You must select LEI as the “Supplier ID Code Type,” as this is the only accepted ID format for the ultimate parent.
Connect to the Direct Supplier: Once filled out and saved, return to your Direct Supplier's record and connect it to this newly created Ultimate Parent.
Intra-group Supplier
An intra-group supplier is a company within a corporate group that provides services to other entities belonging to the same group (often, the Holding company functions as a supplier for other entities).
Adding an intra-group supplier: Create this in the exact same manner as a Direct Supplier by clicking Add Supplier. The only distinction is that you must explicitly indicate the supplier is an intra-group supplier within the "ICT Supplier identification details" section.
2. How to Map a Contract
Adding a contract: Click Add contract.
Trigger the form: Select “Yes” to the question: “Is this contractual arrangement for the provision of ICT Services in terms of DORA?”
Complete required fields: Fill in all subsequent mandatory fields.
Establish relationships: As a second step, once all contracts are created, you must establish connections to sub-contracts where applicable. This ensures that the full contract structure is visible and traceable within the platform.
Mandatory contract connections: In Formalize, the following contract type connections are mandatory:
Parent Contracts: Must be designated as an "overarching/master agreement." They must always have "subsequent contracts" connected to them.
Sub-contracts: Must be designated as an "associated or subsequent agreement." They must always be connected back to an overarching contract using the "Parent contract" connection.
3. How to map a System/ICT Service
Adding a system: Click Add system.
Trigger the form: Select “Yes” to the question: “Is this System/ Service considered an ICT Service in terms of DORA?”
Complete required fields: Fill in the form with specific information about that System/ICT Service. All subsequent fields are mandatory and must be completed.
4. How to map a Business Function
Adding a business function: Click Add business function.
Trigger the form: Select “Yes” to the question: “Is this function supported by an ICT service?”
Complete required fields: All subsequent fields are mandatory and must be completed.
Connections between the Resources
Mandatory Connection Order: To ensure all ROI reports and columns populate correctly, you must connect your mapped resources in Formalize. After all data is correct and all resources are imported, you must connect them in the following exact order to ensure nothing is left out:
First, Systems/ICT services to Suppliers
Second, Contracts to Systems and Suppliers
Third, Business Functions to Contracts, Systems, and Suppliers.
Data Coherence: You must maintain coherence with your connections and data. For example, if a System supports a Business Function, the Contracts and Suppliers previously connected to that System must also be connected to that Business Function.
Connecting Systems and Suppliers
Navigate to Systems: To connect a System with a Supplier, navigate to the Systems section and choose your desired System.
Edit the System: Click the "Options" button, followed by "Edit".
Select the Supplier: In the "Suppliers" field, select the appropriate supplier chain for that System.
Connecting Contracts to Systems and Suppliers
Select the Contract: To connect a System and a Supplier to a contract (or sub-contract), first select your desired contract or sub-contract.
Establish connections: Locate the available connections panel. Select the connections labeled "System" and “Supplier”, click the three-dot menu, and then choose the specific System and Supplier you want to connect.
Critical Constraint: You only connect Level 1 (Direct) suppliers to main contracts and sub-contracts. Sub-suppliers (Level 2) do not connect to any of the other resources.
Connecting Business Functions to Contracts, Systems, and Suppliers
Select the Business Function: When selecting the Business Function you want to connect, locate the available connections panel.
Establish connections: You must select the connections labeled “Systems”, “Contracts”, and “Suppliers”. Click the three-dot menu for each and select the relevant items you wish to connect.
Critical Constraint: Once again, you only connect main Business Functions to Level 1 (Direct) Suppliers.
Dashboard - DORA ROI Data Checks
Access the dashboard: To access the DORA ROI Data Checks dashboard, navigate to the Insights section of the platform and select Statistics.
Review your data: This dashboard performs data checks to ensure you have filled out all needed data for each resource and that all connections are correct. The goal is for the dashboard to be entirely green and display 0 (zeros).
Correct missing data: If you see any widget displaying a number other than 0, click directly on that widget. It will show you exactly where data or connections are missing so you can fill in or correct the relevant items.
Data Reports
Navigate to reports: To export your Register of Information in the correct format, navigate to Reports.
Select all reports: Locate and open the folder called “DORA - Register of Information.” Inside, you will see the 15 reports that form the ROI. To export them, click the top checkbox, which will select all 15 reports at once.
Choose the export format: Locate the “Export as” option. After clicking it, format options will appear: CSV, Excel (XLSX), and DORA Register of Information. You must select DORA Register of Information, as this is the required EU Standard format.
Export and receive: A new window will appear. Fill out the relevant information about your entity and click “Export”. A ZIP file containing your final report will be sent to your email address.
Critical Warning: Do NOT open or extract the ZIP file you receive in your email. Opening the file damages the required EU Standard structure and compromises the report. Keep the ZIP file intact for the validation step.
Formalize Validator
Access the Validator: Formalize provides an online ROI Validator to perform in-depth data checks on your report. Access it via this link: https://formalize.com/en/roi-validator
Upload and review checks: Upload the intact ZIP file to the Validator. The tool will perform several checks per report.
You can expand the checks for each report to see exactly where any errors are located.
View detailed errors: A more detailed inspection of the checks will identify errors within the reports, pinpointing the exact row, column, and cell value. To see a comprehensive table of these errors, click "Show details".
Correction Protocol: Any errors identified by the Validator must be corrected within the Formalize platform itself. Crucially, do not attempt to correct these errors directly in the generated report file.
Common Errors and Formalize Correction Steps
Most errors flagged by the Validator are common. To fix them, return to the Formalize platform, locate the specific resource, and make the correction there.
LEI Check: The LEI provided does not exist. To fix this, locate the specific supplier in Formalize and correct the LEI number to a valid, existing one.
Not empty check: This indicates a field is missing mandatory information. Depending on the report, navigate back to the relevant resource in Formalize and fill in the blank field.
Format check: The format of the ID is incorrect. Find the supplier associated with this ID in Formalize and correct the value according to the proper ID code type.
Constraint check: This check highlights inconsistencies in resource connections. For instance, an issue arises if a critical business function is linked to a resource classified as non-critical. To resolve this, consult the relevant report, locate the conflicting item in Formalize, and thoroughly evaluate all connected resources and data to pinpoint and fix the inconsistency.
Final Step: Once you have corrected all errors in the platform, export the report again and upload the new ZIP file to the Validator. Repeat this process until you achieve a 100% success rate.
We hope this article was helpful!
If you have any additional questions, please reach out to us via chat in the bottom right corner of the page — our team is always happy to assist you further.








































