The share of accepted DORA information registers rose from 40% in 2025 to 94% in 2026. Gaps remain in policies and procedures, and ICT incident reporting is still below expectations. Dutch licence holders must make local decisions when a supplier or system fails.
Why this matters
A DORA register links each ICT service to a supplier, contract, business function and owner. Those details often sit in separate files. Finance may pay a subsidiary with a different name from the contract. IT may use a product name missing from the supplier ledger. During an outage, staff must match invoices, contracts and service records. The licensed entity remains responsible for group policies and shared services.
Example
A client platform slows down and transactions queue. IT knows the system. Finance recognises the supplier on its invoices, while Legal holds the contract. Compliance must decide whether a DORA report is required. If supplier names or owners differ across the records, management first has to trace the supplier and contract. Client updates, recovery decisions and reporting may then be delayed.
XTROVERSO tips
- Compare the main records. Put the DORA register beside the supplier ledger, current contracts and the list of critical business services. Check legal names, services, invoices and entities.
- Name the responsible people. Give each important ICT service a business owner and a contract owner. Record who can assess an incident and call the supplier.
- Check group documents locally. Test group policies against the Dutch entity’s systems, suppliers, licence and business hours. Record each local gap in the policy file.
- Walk through one disruption. Follow an incident from detection to the management decision and reporting. Note each step that depends on memory, one staff member or a missing contract.
- Show unfinished work clearly. Give management a short list of contract changes, supplier-data corrections, untested escalation routes and accepted risks.
Want to know whether your DORA records will work under pressure? We can help find the gaps
The data, sourcing, and analysis behind this article were conducted by Paolo Maria Pavan. AI was not used to identify sources, build the factual basis, or produce the analytical judgment contained here. AI was used only as a drafting aid. The final English text was personally reviewed, edited, and approved by Paolo Maria Pavan before publication.
References
- Autoriteit Financiële Markten — DORA-update 7
- Autoriteit Financiële Markten — DORA-informatieregister
- De Nederlandsche Bank — Datakwaliteitscontroles informatieregister
- De Nederlandsche Bank — Rapportage van ernstige ICT-incidenten
- De Nederlandsche Bank — Resultaten sectorbrede DORA-uitvraag
- Autoriteit Financiële Markten — Veelgestelde vragen over DORA
- De Nederlandsche Bank — DORA toezicht en regelgeving


