While firms have made significant progress in enhancing their ICT risk management and operational resilience frameworks, one of the most challenging aspects of DORA implementation has been compliance with the Register of Information (RoI) requirements. The RoI sits at the heart of DORA's oversight of ICT third-party risk, requiring firms to identify, document and monitor their ICT outsourcing and service-provider relationships in a consistent and structured manner.
The RoI is a regulatory requirement arising from Article 28(3) of Regulation (EU) 2022/2554 (DORA). Under this provision, financial entities are required to maintain and keep up to date a register containing information on all contractual arrangements for ICT services provided by ICT third-party service providers. The register must be maintained at the relevant organisational level and submitted to the competent authority at least annually, while also being made available upon request. The RoI serves as a key regulatory reporting tool, enabling competent authorities to assess firms' ICT dependencies, monitor concentration risks and support the oversight of ICT third-party providers across the financial sector.
The 2027 RoI submission will, for many firms, represent the third annual reporting cycle under DORA. Experience from the 2025 and 2026 submissions has demonstrated that firms frequently encounter data quality, validation and reporting errors. Many of these issues can be mitigated through early preparation and robust data governance.
Given that the RoI requires the completion of more than 90 data fields across multiple reporting templates, firms should seek to identify, collect and validate the majority of required information well in advance of the reporting reference date, thereby reducing the risk of submission errors and last-minute remediation efforts.
2025 cycle
The 2025 reporting cycle marked the first industry-wide collection of RoIs under DORA and revealed a number of recurring challenges for firms. Common issues included incorrect file structures and packaging, particularly failures to prepare submissions in the prescribed xBRL-CSV format and package them correctly for submission. Firms also encountered difficulties complying with the EBA's technical specifications, resulting in reporting files that could not be processed successfully. In addition, many submissions contained incomplete or missing reference data, including the absence of Legal Entity Identifiers (LEIs) and other mandatory provider identifiers.
Although many firms initially succeeded in submitting their Registers, a significant number subsequently received notifications that their submissions had failed EBA validation and were required to resubmit. The Central Bank of Ireland highlighted that many of these validation failures arose from deficiencies within the reporting package itself rather than issues with the Central Bank Portal, underscoring the importance of robust data preparation and quality assurance processes.
2026 cycle
In advance of the 2026 reporting cycle, the Central Bank of Ireland and the European Banking Authority (EBA) introduced enhanced validation and data quality checks, reflecting lessons learned from the inaugural reporting exercise. The Central Bank also strengthened its portal validation rules and feedback mechanisms to enable firms to identify and remediate potential issues earlier in the submission process.
Despite these enhancements, a number of firms continued to encounter reporting challenges. Common deficiencies included the use of generic or placeholder values, incomplete reference data and invalid entries within mandatory fields. Particular issues arose in relation to the identification of ICT third-party service providers and their ultimate parent entities, highlighting the continuing difficulty firms face in sourcing, validating and maintaining the detailed data required for RoI reporting.
The EBA announced on 16 February 2026 that an additional review would be conducted on the content of data submitted as part of the 2026 ROI reporting exercise. This additional review step allowed for additional feedback on the data contained within the register. The additional review step allowed Firms to receive the feedback instantly, update the content and resubmit ahead of the 31 March 2026 reporting deadline. This was intended to prevent the scale of resubmissions that occurred in the 2025 ROI reporting exercise. Despite the enhanced feedback provided, a significant number of firms' ROI submissions continued to fail the EBA's Data Quality (DQ) checks, necessitating resubmissions throughout April and May 2026.
Aggregated annual costs and losses (JC 2024 34)
An additional reporting obligation under DORA is the estimation of aggregated annual costs and losses caused by major ICT-related incidents, as provided for under Article 11(11) of Regulation (EU) 2022/2554. To support consistent implementation across the financial sector, the Joint Committee of the European Supervisory Authorities (EBA, EIOPA and ESMA) has issued guidance on this reporting requirement through JC 2024 34.
However, unlike the annual Register of Information submission, this is not a recurring reporting obligation for all firms. Rather, financial entities, with the exception of microenterprises, are only required to submit this information where requested by their competent authority. In the Irish context, such a submission would therefore be required only upon request from the Central Bank of Ireland as part of its supervisory activities.
How Forvis Mazars can help
As the DORA ROI reporting continues to develop, firms will need to assess the data entered into their registers and ensure that the data entered makes sense before final submission. The 2027 ROI reporting cycle is expected to open on the CBI portal from the 1 March 2027, the deadline for final submissions is expected to be 31 March 2027.
Our prudential risk specialists support a wide range of financial service providers in DORA Register of Information submissions, xBRL CSV conversion and assist Firms in identifying and addressing data quality issues.