Skip to main content
    Regulation
    December 11, 20258 min read

    DORA Register of Information: Track ICT Provider LEIs for Compliance

    EU financial entities must submit a Register of Information listing ICT providers by LEI under DORA. Learn how to track and verify LEI status using the Compliance Tracker tool to ensure your ROI submission is accurate.

    The Digital Operational Resilience Act (DORA) came into force on 17 January 2025. Are you ready?

    What is DORA and Why Does It Matter?

    The Digital Operational Resilience Act (DORA) represents a landmark shift in how the European Union approaches digital risk management in the financial sector. This regulation establishes a comprehensive framework requiring financial entities to ensure they can withstand, respond to, and recover from all types of ICT-related disruptions and threats.

    DORA applies to virtually all regulated financial entities in the EU, including:

    • Credit institutions and payment service providers
    • Investment firms and trading venues
    • Insurance and reinsurance undertakings
    • Asset managers (UCITS and AIFMs)
    • Crypto-asset service providers
    • Crowdfunding service providers

    The Register of Information (ROI) Requirement

    One of DORA's most significant operational requirements is the Register of Information (ROI). Financial entities must maintain and submit a comprehensive register documenting all their ICT third-party service providers and contractual arrangements.

    Key ROI Requirements

    • ICT Provider Identification: All third-party ICT providers must be identified using their Legal Entity Identifier (LEI)
    • Contract Details: Nature of services, criticality assessment, and contractual terms
    • Risk Assessment: Concentration risk and substitutability analysis
    • Annual Submission: ROI must be submitted to competent authorities annually

    Why LEIs Are Critical for DORA Compliance

    The LEI serves as the universal identifier for ICT providers in your Register of Information. DORA mandates the use of LEIs because they provide:

    • Unambiguous Identification: Each LEI uniquely identifies one legal entity globally
    • Standardization: Enables regulators to aggregate and analyze data across the EU financial system
    • Relationship Mapping: LEI Level 2 data reveals corporate hierarchies and ultimate parent entities
    • Validation: LEI status (active/lapsed) indicates whether provider information is current

    The LEI Status Challenge

    Here's where many firms encounter difficulties: LEIs must be renewed annually. An ICT provider may have had an active LEI when you onboarded them, but if they haven't renewed it, you're submitting outdated information to regulators.

    Common issues include:

    • ICT providers allowing their LEI to lapse without notification
    • Corporate restructuring invalidating the original LEI
    • Providers using subsidiary LEIs instead of ultimate parent entities
    • New providers not yet having obtained an LEI

    🛠️ Track Your ICT Providers with Our Compliance Tool

    Our Supply Chain Compliance Tracker helps you monitor LEI status for all your ICT providers. Get a compliance score showing what percentage of providers have active LEIs—ensuring your ROI submission is accurate.

    Try Compliance Tracker →

    Using the Compliance Tracker for ROI Preparation

    Our Supply Chain Compliance Tracker tool is specifically designed to help financial entities manage and monitor their ICT provider LEIs for DORA compliance.

    Step 1: Upload Your ICT Provider List

    Start by adding all your ICT third-party service providers to the Compliance Tracker:

    • Enter LEI codes manually or use bulk upload
    • The system automatically validates each LEI against the GLEIF database
    • Invalid or unrecognized LEIs are flagged immediately

    Step 2: Monitor LEI Status in Real-Time

    The Compliance Tracker continuously monitors the status of each LEI in your portfolio:

    • ✓ ACTIVE: LEI is current and valid for regulatory use
    • ⚠ PENDING: LEI renewal is in progress
    • ✗ LAPSED: LEI has expired and requires renewal before ROI submission

    Step 3: Use the Compliance Score

    Your Compliance Score provides an instant health check of your ICT provider portfolio:

    90-100%
    Ready for ROI Submission
    70-89%
    Action Required
    Below 70%
    Critical Issues

    Step 4: Take Action on Non-Compliant Providers

    For ICT providers with lapsed or missing LEIs, you have several options:

    • Contact the Provider: Request they renew their LEI before your ROI deadline
    • Escalate Internally: Flag to procurement/vendor management teams
    • Document the Gap: If renewal isn't possible, document your due diligence efforts
    • Consider Alternatives: Evaluate whether providers without valid LEIs should remain in your ecosystem

    Step 5: Export for ROI Submission

    Once your compliance score reaches 100%, export your verified ICT provider list:

    • Download in CSV format compatible with regulatory templates
    • All LEI codes validated and current as of export date
    • Includes entity names, registration status, and renewal dates
    • Audit trail maintained for compliance records

    Best Practices for DORA LEI Management

    ✓ Proactive Monitoring

    Don't wait until ROI submission deadlines. Set up regular monitoring cycles (monthly or quarterly) to catch LEI lapses early.

    ✓ Contractual Requirements

    Include LEI maintenance obligations in your ICT provider contracts. Require providers to maintain active LEIs and notify you of any changes.

    ✓ Relationship Data

    Use LEI Level 2 relationship data to understand corporate hierarchies. This helps identify concentration risk if multiple ICT providers share the same ultimate parent.

    ✓ Document Everything

    Maintain records of your LEI validation process. Regulators may ask for evidence of your due diligence in verifying ICT provider information.

    DORA Timeline: Key Dates

    Date Milestone
    17 January 2025 DORA enters into force
    Q1 2025 First ROI submissions due to national competent authorities
    Annually Ongoing ROI updates and submissions required

    Get Started with LEI Compliance Tracking

    Don't let lapsed LEIs jeopardize your DORA compliance. Start using our Supply Chain Compliance Tracker today:

    1. Create a free account to access the Compliance Tracker
    2. Add your ICT providers by entering their LEI codes
    3. Monitor your Compliance Score and take action on any issues
    4. Export your verified data for ROI submission

    Ready to Ensure DORA Compliance?

    Learn more about our compliance tracking tools and how they can help you meet DORA requirements.

    Explore Compliance Tracker →

    Need Help with LEI Registration or Renewal?

    LEI Worldwide is an official GLEIF LEI Registration Agent. We can help your ICT providers obtain or renew their LEIs quickly.

    Visit leiworldwide.com or contact support@lei-worldwide.com

    Recommended Articles

    Cookie Consent

    We use essential cookies for site functionality. Analytics cookies help us improve your experience. You can choose to accept or decline optional cookies. Your choice will be remembered.

    Privacy Policy