Archer DORA-Aligned Register of Information

The Archer DORA-Aligned Register of Information (RoI) offering streamlines the process of capturing and managing the data required for DORA RoI reporting. It leverages existing data already available within Archer and enables organizations to collect any additional information necessary for compliance. The solution ensures data integrity and accuracy through built-in validation mechanisms, which are especially important given the complexity of the reporting requirements.

Important: The information in this publication is provided "as is". Archer makes no representations or warranties of any kind with respect to the information in this publication, and specifically disclaims implied warranties of merchantability or fitness for a particular purpose. Client is solely responsible for ensuring that the installation of the application is performed in a secure manner. Archer recommends clients perform a full security evaluation prior to implementation.

Archer Exchange: With the Archer Exchange, the Archer team and our trusted partners have created a broad selection of supplemental, value-added offerings to help you get your unique risk management program on the right path, right from the start. You can leverage the Archer Exchange offerings to expand the use of Archer solutions into new business processes and address specific industry, geographic, regulatory, or technical requirements. The Archer Exchange features a fast and agile development cycle, enabling quick delivery of new and updated offerings for trending issues and connections to innovative technologies.

Release notes

Release date

Platform release

Notes

November 2024.11
  • Rearchitect offering to properly align with reporting of DORA registers of information, reporting on Entities, Third Parties, and their contractual arrangements.

  • Enhanced flexibility to revise ROI scope throughout the year, streamlining preparation for reporting and significantly reducing the time required to compile and submit reports.

  • Added automation capabilities to streamline scoping processes, including automatic record creation and auto-scoping.

  • Added functionality to exclude scoped items from external reporting while still maintaining internal visibility and tracking within Archer.

  • Introduced point-in-time snapshot functionality to capture the register as it exists at the time the snapshot was created, enabling accurate historical data preservation and time-based analysis.

  • Implemented DORA validation checks and reporting, ensuring registers meet compliance requirements by verifying data integrity before submission and providing visibility into validation results.

  • Designate ROI records for regulatory reporting and track related communications and outcomes to support compliance and audit readiness.

  • Support for NGRX Custom Objects to ensure proper rendering and interactions with custom objects created within the iframe.

February 2025 2024.09 Initial release

Overview

The Digital Operational Resilience Act (DORA) is a regulatory framework introduced by the European Union to ensure the operational resilience of financial institutions and critical infrastructures in the face of digital disruptions, such as cyber-attacks or IT failures. This regulation also affects non-European companies doing business in Europe. As part of DORA, financial entities must maintain and report specific operational data to ensure compliance and improve resilience.

Financial institutions are under mounting pressure from a growing array of cyber threats, IT system failures, and vulnerabilities within third-party ecosystems—factors that pose serious risks to both their operations and the broader financial system. The introduction of the Digital Operational Resilience Act (DORA) has raised the bar, requiring organizations to demonstrate their ability to withstand, respond to, and recover from digital disruptions. This regulation enforces rigorous standards for monitoring and reporting operational resilience data.

Despite these requirements, many institutions continue to rely on fragmented tools and manual processes to manage their ICT assets and interdependencies. This fragmented approach often results in inefficiencies, oversight gaps, and heightened exposure to risk. Archer DORA-Aligned Register of Information offers a centralized, automated solution designed to meet regulatory expectations and streamline compliance efforts.Non-compliance with DORA can lead to regulatory sanctions, reputational harm, and increased operational vulnerabilities. To mitigate these risks, organizations must implement robust frameworks for managing ICT risks, overseeing third-party relationships, and demonstrating compliance—all while ensuring business continuity and maintaining customer trust.

The register of information (RoI) established for the application of Regulation (EU) 2022/2554 (DORA) requires financial entities to report information pertaining to various parties involved in the use and provision of Information and Communication Technology (ICT) services to ensure compliance and improve resilience.

How Archer Handles the DORA Register of Information

This offering guides organizations through a structured, repeatable process to build and maintain the Register of Information with the following:

  • Identify ROI Scope: Define the boundaries of the register, including entities, ICT services, and serfvice providers that fall under DORA’s requirements.

  • Scope Validation: Archer validates, organizes, and formats the data into DORA’s Excel template, ensuring accuracy, completeness, and consistency.

  • Prepare for ROI Reporting: Generate a CSV package formatted for reporting, enabling easy submission to regulators or internal governance teams.

  • Document ROI Reporting: Document the reporting process within Archer for audit readiness, traceability, and historical reference.

The Archer DORA-Aligned Register of Information helps financial entities comply with the Digital Operational Resilience Act (DORA) regulation introduced by the European Union. It applies to financial entities such as banks, insurers, investment firms, and their critical third-party ICT (Information and Communication Technology) service providers in Europe or doing business with entities in Europe. This offering captures all required data for the DORA Register of Information and prepares it for regulator-ready reporting.

This offering organizes all required data into a readable, structured format and performs checks to prevent errors that could complicate submission. It also automatically generates the reporting package in the format mandated by DORA. Additionally, it can document communications with regulators and track outcomes, supporting a complete and auditable reporting process.

Features & benefits

Archer DORA-Aligned Register of Information enables organizations to achieve the following goals.

  • Scope Definition: Streamlines RoI reporting by auto-generating and identifying the required scope.

  • Comprehensive Data Capture: Leverages existing Archer data and collects additional information needed for DORA compliance.

  • Built-in Validation: Ensures data integrity and accuracy through automated checks, minimizing submission errors.

  • Structured Reporting Output: Organizes complex data into DORA’s required Excel format and exports in XBRL-CSV Zip for submission.

  • Regulatory Communication Tracking: Documents and tracks interactions with regulators to support auditability and compliance.

The benefits of using Archer DORA-Aligned Register of Information includes the following.

  • Provides a structured approach to assessing third-party risks, ensuring proactive management of potential vulnerabilities

  • Ensures vendors meet required cybersecurity and resilience standards, reducing the risk of non-compliance

  • Ensures compliance with DORA and other regulatory frameworks that require transparency in third-party risk management

  • Helps identify vendors handling critical or sensitive data, allowing for targeted security assessments and penetration testing

User guide

Complete a Register of Information

Administrator guide

Prerequisites (on-demand application (ODA) & system requirements)

The following table lists the components and prerequisites for the offering.

Components

Prerequisites

Archer solution area

Third Party Management

Archer use case

Third Party Engagements

Archer applications

Third Party Profile, Subcontractors, Contracts, Master Service Agreement, Company

Uses custom objects

Yes. Custom objects provided for both classic and New User Experience in SaaS.

Requires Archer license

Additional licensing fees apply for Archer DORA-Aligned Register of Information. Please contact Archer Sales Representative for more information and pricing.

Archer Platform requirements

Archer Platform Release 2024.11 and later

Supported Archer environments

  • On-Premise

  • SaaS

Compatible use cases & applications

For information on Archer use cases, see the Archer Solutions Help.

Related applications

The following table lists the related applications.

 

Application

Use case

Primary Purpose of the relationship

Company

Third Party Catalog

This is referenced to report Entities

Contracts

Third Party Catalog, Third Party Engagements

This is referenced to report Contractual Arranagements

Master Service Agreements

Third Party Engagements

This is referenced to report Contractual Arranagements

Products and Services

Third Party Engagements

This is referenced to report Functions

Business Processes

Third Party Engagements

This is referenced to report Functions

 

Regulatory Communications

Privacy Program Management

Track any communications with regulator

Subcontractors

Third Party Engagements

This is referenced to report ICT Service Providers

Third Party Profile

Third Party Catalog, Third Party Engagements

This is referenced to report ICT Service Providers

 

 

Impacted use cases

The following use cases were impacted for Archer DORA-Aligned Register of Information.

  • Third Party Catalog

  • Third Party Engagements

Additional resources

The following additional resources are available.

Components

Architecture diagram

The following diagram shows the architecture.

Applications

The following table describes the applications for Archer DORA-Aligned Register of Information.

Application

Description

Register of Information

The Register of Information (RoI) maintains comprehensive and up-to-date details of all contractual arrangements, ICT service providers, and functions as required under the Digital Operational Resilience Act (DORA). It serves as a central repository that enables financial entities to:

  • Monitor dependencies on ICT third-party service providers

  • Assess the criticality of ICT services

  • Support regulatory reporting and oversight activities

Entities

The Entities application is used to record and maintain

  • Financial entities

  • Any non-financial entities within the group which need to be reported

  • Any operational third-parties

  • any branches which are outside the country for the entities listed above

Contractual Arrangements

The Contractual Arrangements application is used to record and maintain details of:

  • All contracts between financial entity and direct third party service provider

  • All intra-group contracts between the financial entity and another entity within the same group.

  • All overarching or master agreements

  • ICT Supply Chains

  • ICT Service provided by the service provider and assessment

ICT Service Providers

The ICT Service Providers application is used to record and maintain details of:

  • All direct ICT third-party service providers

  • All ICT intra-group service providers

  • All subcontractors related to the contractual arrangement within the ICT service supply chain

  • All ultimate parent undertakings of the ICT third-party service providers listed above

Functions

The Functions application is used to record and maintain all processes or services supported by the contractual agreements. Each financial entity, including entities within the same group, maintains its own internal taxonomy of functions based on its specific business model and organisational structure. To enable clear monitoring and distinction between financial functions and ICT services, financial entities must designate relevant functions using a Function Identifier at both individual and group levels.

ROI Snapshot

The ROI Snapshot is a point-in-time copy of the Register of Information (ROI) record. It replicates the DORA Register of Information template and provides a static view of data at the time the snapshot was created.

Personas and access roles

Organizations should configure permissions and access roles following their requirements.

Install Archer DORA-Aligned Register of Information

Complete the following tasks to install Archer DORA-Aligned Register of Information.

  1. Prepare for the installation.

    1. Obtain the installation package.

    2. Read and understand the "Packaging Data" Archer Platform Help.

  2. Install the package.

  3. Set up data feeds.

  4. Configure custom objects.

  5. Test the installation. Test the application according to your company standards and procedures, to ensure that the use case works with your existing processes.

Install the package

Installing a package requires that you import the package file, map the objects in the package to objects in the target instance, and then install the package.

Set up data feeds

Configure Custom Objects

Extract the Archer_DORA_Aligned_ROI_CustomObject_Bundle_v1.zip to obtain all the custom codes. Open the folder with the name of the application you are configuring.

Important: All custom objects are dependent on field names, therefore, we strongly recommend not modifying any field name that is referenced in custom code, as such changes will require corresponding code updates.

Important: Do not make any modifications within the ROI Snapshot application, including changes to field names, section names, or field placements. Any changes may cause the associated custom code to malfunction.

Certification environment

Date tested: November 2025

Product Name

Release Information

Operating System

Archer

2024.11

Virtual Appliance