DORA Register of Information: Track ICT Provider LEIs for Compliance
EU financial entities must submit a Register of Information listing ICT providers by LEI under DORA. Learn how to track and verify LEI status using the Compliance Tracker tool to ensure your ROI submission is accurate.
The Digital Operational Resilience Act (DORA) came into force on 17 January 2025. Are you ready?
What is DORA and Why Does It Matter?
The Digital Operational Resilience Act (DORA) represents a landmark shift in how the European Union approaches digital risk management in the financial sector. This regulation establishes a comprehensive framework requiring financial entities to ensure they can withstand, respond to, and recover from all types of ICT-related disruptions and threats.
DORA applies to virtually all regulated financial entities in the EU, including:
- Credit institutions and payment service providers
- Investment firms and trading venues
- Insurance and reinsurance undertakings
- Asset managers (UCITS and AIFMs)
- Crypto-asset service providers
- Crowdfunding service providers
The Register of Information (ROI) Requirement
One of DORA's most significant operational requirements is the Register of Information (ROI). Financial entities must maintain and submit a comprehensive register documenting all their ICT third-party service providers and contractual arrangements.
Key ROI Requirements
- ICT Provider Identification: All third-party ICT providers must be identified using their Legal Entity Identifier (LEI)
- Contract Details: Nature of services, criticality assessment, and contractual terms
- Risk Assessment: Concentration risk and substitutability analysis
- Annual Submission: ROI must be submitted to competent authorities annually
Why LEIs Are Critical for DORA Compliance
The LEI serves as the universal identifier for ICT providers in your Register of Information. DORA mandates the use of LEIs because they provide:
- Unambiguous Identification: Each LEI uniquely identifies one legal entity globally
- Standardization: Enables regulators to aggregate and analyze data across the EU financial system
- Relationship Mapping: LEI Level 2 data reveals corporate hierarchies and ultimate parent entities
- Validation: LEI status (active/lapsed) indicates whether provider information is current
The LEI Status Challenge
Here's where many firms encounter difficulties: LEIs must be renewed annually. An ICT provider may have had an active LEI when you onboarded them, but if they haven't renewed it, you're submitting outdated information to regulators.
Common issues include:
- ICT providers allowing their LEI to lapse without notification
- Corporate restructuring invalidating the original LEI
- Providers using subsidiary LEIs instead of ultimate parent entities
- New providers not yet having obtained an LEI
🛠️ Track Your ICT Providers with Our Compliance Tool
Our Supply Chain Compliance Tracker helps you monitor LEI status for all your ICT providers. Get a compliance score showing what percentage of providers have active LEIs—ensuring your ROI submission is accurate.
Using the Compliance Tracker for ROI Preparation
Our Supply Chain Compliance Tracker tool is specifically designed to help financial entities manage and monitor their ICT provider LEIs for DORA compliance.
Step 1: Upload Your ICT Provider List
Start by adding all your ICT third-party service providers to the Compliance Tracker:
- Enter LEI codes manually or use bulk upload
- The system automatically validates each LEI against the GLEIF database
- Invalid or unrecognized LEIs are flagged immediately
Step 2: Monitor LEI Status in Real-Time
The Compliance Tracker continuously monitors the status of each LEI in your portfolio:
- ✓ ACTIVE: LEI is current and valid for regulatory use
- ⚠ PENDING: LEI renewal is in progress
- ✗ LAPSED: LEI has expired and requires renewal before ROI submission
Step 3: Use the Compliance Score
Your Compliance Score provides an instant health check of your ICT provider portfolio:
Step 4: Take Action on Non-Compliant Providers
For ICT providers with lapsed or missing LEIs, you have several options:
- Contact the Provider: Request they renew their LEI before your ROI deadline
- Escalate Internally: Flag to procurement/vendor management teams
- Document the Gap: If renewal isn't possible, document your due diligence efforts
- Consider Alternatives: Evaluate whether providers without valid LEIs should remain in your ecosystem
Step 5: Export for ROI Submission
Once your compliance score reaches 100%, export your verified ICT provider list:
- Download in CSV format compatible with regulatory templates
- All LEI codes validated and current as of export date
- Includes entity names, registration status, and renewal dates
- Audit trail maintained for compliance records
Best Practices for DORA LEI Management
✓ Proactive Monitoring
Don't wait until ROI submission deadlines. Set up regular monitoring cycles (monthly or quarterly) to catch LEI lapses early.
✓ Contractual Requirements
Include LEI maintenance obligations in your ICT provider contracts. Require providers to maintain active LEIs and notify you of any changes.
✓ Relationship Data
Use LEI Level 2 relationship data to understand corporate hierarchies. This helps identify concentration risk if multiple ICT providers share the same ultimate parent.
✓ Document Everything
Maintain records of your LEI validation process. Regulators may ask for evidence of your due diligence in verifying ICT provider information.
DORA Timeline: Key Dates
| Date | Milestone |
|---|---|
| 17 January 2025 | DORA enters into force |
| Q1 2025 | First ROI submissions due to national competent authorities |
| Annually | Ongoing ROI updates and submissions required |
Get Started with LEI Compliance Tracking
Don't let lapsed LEIs jeopardize your DORA compliance. Start using our Supply Chain Compliance Tracker today:
- Create a free account to access the Compliance Tracker
- Add your ICT providers by entering their LEI codes
- Monitor your Compliance Score and take action on any issues
- Export your verified data for ROI submission
Ready to Ensure DORA Compliance?
Learn more about our compliance tracking tools and how they can help you meet DORA requirements.
Need Help with LEI Registration or Renewal?
LEI Worldwide is an official GLEIF LEI Registration Agent. We can help your ICT providers obtain or renew their LEIs quickly.
Visit leiworldwide.com or contact support@lei-worldwide.com