{"id":56829,"date":"2025-03-31T14:55:57","date_gmt":"2025-03-31T12:55:57","guid":{"rendered":"https:\/\/www.usd.de\/?p=56829"},"modified":"2025-03-31T17:39:07","modified_gmt":"2025-03-31T15:39:07","slug":"bafin-workshop-dora-register-of-information","status":"publish","type":"post","link":"https:\/\/www.usd.de\/en\/bafin-workshop-dora-register-of-information\/","title":{"rendered":"Our 3 Key Takeaways from the BaFin Workshop on the DORA Register of Information"},"content":{"rendered":"\n<p><em>Original publication date: March 10, 2025<\/em>.<\/p>\n\n\n\n<p><em>Since the publication of this blog post,&nbsp;<a href=\"https:\/\/www.bafin.de\/DE\/Aufsicht\/DORA\/Informationsregister_und_Anzeigepflichten\/Informationsregister_und_Anzeigepflichten_node.html#:~:text=Finanzunternehmen%20unter%20Aufsicht%20der%20BaFin%20m%C3%BCssen%20die%20Informationsregister,zust%C3%A4ndigen%20Beh%C3%B6rden%20jeweils%20bis%20zum%2031.%20M%C3%A4rz%20statt.\" target=\"_blank\" rel=\"noreferrer noopener\">BaFin has postponed the deadline for submission from April 11 to April 28, 2025<\/a>.<\/em><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p><\/p>\n\n\n\n<p>More than 3,000 participants attended the two-hour online workshop hosted by the German Federal Financial Supervisory Authority (<a href=\"https:\/\/www.bafin.de\/EN\/Homepage\/homepage_node.html\" target=\"_blank\" rel=\"noopener\">BaFin<\/a>) on <strong>submitting the Register of Information (RoI).<\/strong><\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">A Brief Recap: The Register of Information<\/h2>\n\n\n\n<p>Since January 2025, the Digital Operational Resilience Act (<a href=\"https:\/\/www.usd.de\/en\/security-consulting\/dora\/\">DORA<\/a>) has required companies in the financial sector to maintain a Register of Information. This register must contain all contractual agreements regarding the use of information and communication technology (ICT) services between a company and its third-party ICT providers.<\/p>\n\n\n\n<p>The purpose of compiling this information in a standardized overview document is to give the European Supervisory Authorities (ESAs) insight into the contractual relationships and the dependencies of European financial institutions on third-party ICT providers. The goal is to identify potential concentration risks across Europe in order to limit or even prevent them in the future.<\/p>\n\n\n\n<p>DORA mandates that the register must be kept available as of January 17, 2025, and provided to the relevant supervisory authority upon request. In addition to this ongoing availability,<strong> the Register of Information must also be submitted annually to the supervisory authority<\/strong>. The first submission must be made to BaFin by <strong>April 28, 2025 <\/strong>\u2013 or, in the case of significant credit institutions, to the European Central Bank (ECB).<\/p>\n\n\n\n<p>To answer key questions about the submission process, BaFin held a <strong>workshop<\/strong>. Our financial security experts attended on your behalf and identified three key takeaways:<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Excel or No Excel? That Is the Question.<\/h2>\n\n\n\n<p>The ESAs have specified XBRL as the required format for creating the Register of Information. Since this format poses challenges, particularly for small and medium-sized enterprises, BaFin has stepped in to help by providing an Excel template. After submission, BaFin will convert the Excel file into XBRL and forward it to the ESAs.<\/p>\n\n\n\n<p>BaFin\u2019s Excel template is fully aligned with the relevant <a href=\"https:\/\/www.eba.europa.eu\/sites\/default\/files\/2024-01\/30b47816-8d6d-432f-8dbd-b900c4306cf4\/JC%202023%2085%20-%20Final%20report%20on%20draft%20ITS%20on%20Register%20of%20Information%20%281%29.pdf\" data-type=\"link\" data-id=\"https:\/\/www.eba.europa.eu\/sites\/default\/files\/2024-01\/30b47816-8d6d-432f-8dbd-b900c4306cf4\/JC%202023%2085%20-%20Final%20report%20on%20draft%20ITS%20on%20Register%20of%20Information%20%281%29.pdf\" target=\"_blank\" rel=\"noopener\">ITS (Implementing Technical Standards) for the Register of Information<\/a>, following the same numbering and terminology. The template is only available in English.<\/p>\n\n\n\n<p>During the workshop, BaFin pointed out that the Excel template is primarily intended for small and medium-sized enterprises, as it reaches its limits when handling large data volumes.<\/p>\n\n\n\n<p>Additionally, the template is only a beta version and currently available exclusively for Windows. Another key issue raised was that the template includes macro elements, which many IT departments prohibit for security reasons.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Don\u2019t Wait Until April 28 to Upload!<\/h2>\n\n\n\n<p>We've all seen it happen \u2013 deadlines get stretched to the very last minute. However, in this case, an early submission is strongly advised, and here\u2019s why:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>You can only upload your file once you are authorized for the <strong>DORA submission process<\/strong>. Register early \u2013 the BaFin website is already available.<\/li>\n\n\n\n<li>BaFin will activate the upload portal <strong>at the end of March.<\/strong><\/li>\n\n\n\n<li><strong>Submission is only considered complete once BaFin and the ESAs have reviewed and accepted your file.<\/strong> Processing may take a few days.<\/li>\n\n\n\n<li><strong>No automatic notifications<\/strong> will be sent regarding the status of your submission. You will need to proactively check the portal for updates.<\/li>\n<\/ul>\n\n\n\n<p>Our experts urgently recommend: Plan a sufficient buffer between submission and the April 28, 2025 deadline to allow for potential feedback or necessary corrections.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Subcontractors: Where Do You Draw the Line?<\/h2>\n\n\n\n<p>Another key question regarding the Register of Information remains: To what extent should subcontractors be listed?<\/p>\n\n\n\n<p>One thing is clear: If an ICT service provider supports critical or important functions, then all subcontractors that significantly contribute to this service must be listed. In other words: If a disruption at a subcontractor could impact the security or continuity of the ICT service, it must be included in the register.<\/p>\n\n\n\n<p>To provide guidance, BaFin shared the following key questions during the workshop:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Is there a direct and explainable dependency between the ICT service and the subcontractor?<\/li>\n\n\n\n<li>Does the subcontractor ensure the provision of essential parts of the ICT service that support a critical or important function?<\/li>\n\n\n\n<li>Could a disruption at the subcontractor impact the security or continuity of the ICT service?<\/li>\n<\/ul>\n\n\n\n<p>BaFin illustrated this with a concrete example:<\/p>\n\n\n\n<p>If a financial institution lists the core banking system provider as an ICT third-party service provider, then at least the following subcontractors must also be listed:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Cloud provider for the core banking system<\/li>\n\n\n\n<li>Firewall for the core banking system<\/li>\n\n\n\n<li>Load management services<\/li>\n<\/ul>\n\n\n\n<p>Each of these subcontractors meets at least one of the criteria contained in the key questions.<\/p>\n\n\n\n<p>However, the Customer Relationship Management (CRM) system of the core banking system does not need to be listed. It neither represents a critical component of the ICT service nor affects the security or continuity of the core banking system.<\/p>\n\n\n\n<p>Important Note: This example is for illustrative purposes only and, as BaFin repeatedly emphasized, reflects their interpretation of the ITS. However, if the ESAs contradict BaFin\u2019s interpretation, their position will take precedence.<\/p>\n\n\n\n<p>Our experts recommend: Continue to follow the proportionality principle and the risk-based approach that you are already familiar with from previous financial regulations.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p><a id=\"_msocom_1\"><\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><a id=\"_msocom_5\"><\/a><\/p>\n\n\n\n<p>Do you have questions about DORA or need support with implementating it?&nbsp;<a href=\"https:\/\/www.usd.de\/en\/contact-form-security-consulting\/\">Get in touch.<\/a>&nbsp;We are happy to assist you.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original publication date: March 10, 2025. Since the publication of this blog post,&nbsp;BaFin has postponed the deadline for submission from April 11 to April 28, 2025. More than 3,000 participants attended the two-hour online workshop hosted by the German Federal Financial Supervisory Authority (BaFin) on submitting the Register of Information (RoI). A Brief Recap: The [&hellip;]<\/p>\n","protected":false},"author":91,"featured_media":56836,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"off","_et_pb_old_content":"","_et_gb_content_width":"","inline_featured_image":false,"footnotes":""},"categories":[373,410,11],"tags":[5642,5699,5700,10160,12369,9908,10152,12367],"class_list":["post-56829","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-en","category-financial-sector-compliance-en","category-financial-sector-compliance","tag-bafin-en","tag-digital-operational-resilience-act-en","tag-dora-en","tag-esa-en","tag-ict-providers","tag-infosec-in-finance","tag-its-en","tag-register-of-information"],"_links":{"self":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/56829","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/users\/91"}],"replies":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/comments?post=56829"}],"version-history":[{"count":5,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/56829\/revisions"}],"predecessor-version":[{"id":57237,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/56829\/revisions\/57237"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media\/56836"}],"wp:attachment":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media?parent=56829"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/categories?post=56829"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/tags?post=56829"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}