What is DORA?
DORA, the Digital Operational Resilience Act (Regulation (EU) 2022/2554), sets common rules for ICT risk management, ICT-related incident reporting, digital operational resilience testing and ICT third-party risk for financial entities in the European Union. It has applied since 17 January 2025.
What is the DORA register of information?
It is the register of all contractual arrangements with ICT third-party service providers that financial entities must maintain at entity, sub-consolidated and consolidated level. Its templates are set by Implementing Regulation (EU) 2024/2956, and it is submitted to the competent authority, which passes it on to the European Supervisory Authorities.
How do I avoid a rejected register of information submission?
Check the register before filing against the EBA reporting format and validation rules: identifiers such as LEI codes, mandatory fields, references between templates, code lists and file structure. VigieObs runs these checks continuously and generates the submission package so that rejections, quality errors and warnings are known in advance.
What are the DORA Article 30 contractual requirements?
Article 30 of DORA lists the key provisions that contracts with ICT third-party service providers must contain, such as service descriptions, data locations, service levels, audit and access rights, termination rights and, for critical or important functions, exit strategies. VigieObs reads contracts, extracts these provisions and cites the exact clause.
What is the ICT risk management framework review report?
Financial entities must review their ICT risk management framework at least yearly and after major incidents or supervisory findings, and document the review in a report. Its content is set by Article 27 of Delegated Regulation (EU) 2024/1774. VigieObs prepares the report from the review file and seals it.
How does VigieObs map ICT third-party dependencies and concentration risk?
VigieObs links critical or important functions to ICT services, providers and contracts in one resilience graph. It shows which functions depend on a single provider, where several providers belong to the same group, and what happens to recovery objectives when a provider fails.
How does VigieObs measure the impact of a regulatory change?
Official texts are versioned. When a paragraph changes, VigieObs propagates the change through everything that depends on it: arrangements and providers, critical functions, audit tests, findings, review report sections and register data. It shows which contracts need an amendment before the application date or can be upgraded at renewal, and estimates the effort with assumptions you can adjust.
How does VigieObs record decisions and measure their effect?
Each decision is an object: options, choice, justification, owner and re-examination date, linked to the providers, arrangements, functions or texts concerned and approved by a second reviewer. VigieObs then tracks key indicators over time and shows what changed on the linked items after the decision.
Does VigieObs certify DORA compliance?
No. VigieObs supports the people accountable for compliance: it prepares, checks and traces the work, and every conclusion remains a human decision. Compliance is assessed by the financial entity, its auditors and its supervisors.
How is AI used in VigieObs?
AI reads contracts, pre-assesses audit tests and drafts reports, always citing the evidence it relies on. Sensitive data is masked before any request, every exchange is logged, and nothing is applied without human validation.