Know every ICT provider in your register.

Since 17 January 2025, DORA has asked EU financial entities to assess ICT providers before contracting and to register every arrangement.

Fill Easy returns each provider's registry record: who it is, who runs it and its group.

Operational resilience, down the supply chain.

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) makes ICT third-party risk part of a financial entity's risk management. The entity assesses each provider before contracting and keeps a register of information on all contractual arrangements.

The register identifies each provider and its group. For a provider registered in Asia, that starts at an Asian registry.

At a glance

Law
Regulation (EU) 2022/2554 (DORA), Chapter V
Applies from
17 January 2025
Applies to
EU banks, insurers, investment firms, payment and crypto-asset service providers, and other financial entities
Register
A register of information on every ICT third-party arrangement, provided to supervisors

Data and third-party risk

From due diligence to the register.

The third-party duties where company data is the evidence.
DORA ICT third-party risk: obligations and the evidence Fill Easy returns
ObligationWhat it asksWhat Fill Easy returns
Pre-contract due diligenceAssess the provider before entering the arrangementRegistry extract and statutory documents from the company's home registry, across 60+ jurisdictions; credit reports and litigation searches
Register of informationIdentify each provider and the group it belongs toOwnership traced layer by layer through each registry to the natural persons at the top, with the parent company identified
Concentration riskKnow when several providers belong to the same groupGroup structures traced across registries, so shared owners show up
Ongoing monitoringKeep provider information current through the contractMonitoring and remediation: the book re-checked at source from one Excel file

A summary, not legal advice: the official text governs, and your compliance team decides what your policies require.

Read the source

The official text.

EBA: DORA

The European Supervisory Authorities' technical standards, including the register of information.

Questions about DORA ICT third-party risk

Not covered here? Ask our team

Does Fill Easy make us compliant with DORA ICT third-party risk?

No. The due diligence duty sits with your firm under DORA ICT third-party risk, and your policies decide what is enough. Fill Easy supplies the evidence those policies rely on: records from the government or registry source, each showing where and when it was retrieved.

Can you check our whole provider list at once?

Yes. Send the list as one Excel file with your own references. Each provider is re-checked at its registry and the results come back matched to your rows.

Move your search orders without changing how your team works.