---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Exploring Digital resilience third-party registers

# Exploring Digital resilience third-party registers {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring Digital resilience third-party registers

The Digital resilience third-party registers application supports financial entities in maintaining comprehensive records of their contractual arrangements with Information and Communication Technology (ICT) third-party service providers.
It helps these entities comply with the European Union's Digital Operational Resilience Act (DORA), which mandates robust ICT security and operational resilience within the financial sector.
This application is integral for tracking ICT third-party risks and enabling regulatory oversight by European Supervisory Authorities (ESA).
Show full answer Show less  

## Key Features

* **Support for DORA Compliance:** Starting with Release 19.1.x, the application works alongside Digital Operational Resilience Management to upload/download DORA tables and maintain detailed ICT third-party registers.
* **Data Management Flexibility:** Users can manage records individually or in bulk via Microsoft Excel templates or through the graphical user interface (GUI), facilitating ease of updates and reporting.
* **Multi-Level Record Keeping:** Registers cover individual entities, sub-consolidated, and consolidated levels, including third parties, contracts, functions, supply chains, and engagements.
* **Role-Based Access:** IRM Professional license users access the registers via the Operational Resilience Workspace, while TPRM license users utilize the TPRM Workspace.
* **Regulatory Package Support:** The application supports the creation and validation of Register of Information (RoI) packages required under DORA, ensuring compliance and data integrity.

## Practical Application for ServiceNow Customers

Financial entities using ServiceNow can leverage this application to:

* Maintain and update comprehensive ICT third-party risk registers aligned with DORA requirements.
* Automate data population from disparate systems to centralize third-party contractual details.
* Perform due diligence, risk assessments, and governance as mandated by DORA for ICT service providers.
* Ensure readiness for regulatory reporting with validated RoI packages.
* Meet EU regulatory standards for operational resilience, including identifying critical third-party providers and managing supply chain risks.

## Why It Matters

Compliance with DORA is mandatory for financial entities under EU supervision, aiming to strengthen ICT security and ensure continuity of critical financial services. This application facilitates adherence to these regulations by providing structured, scalable, and auditable management of third-party ICT risks. It enables financial institutions to maintain operational integrity even during digital disruptions and supports regulators in overseeing the ICT risk landscape effectively.  
The Digital resilience third-party registers application empowers the financial entities to maintain registers of contractual arrangements with Information and Communication Technology (ICT) third-party service providers and comply with Digital Operational Resilience Act (DORA) regulation.

## Applications for DORA compliance {#exploring-digi-resi-third-party-registers__section_sbr_jxs_cdc}

Beginning with Release 19.1.x, the following applications are supported for ICT Third-party Risk Management as part of DORA compliance.

* Digital Operational Resilience Management: This application is used for uploading and downloading of all individual DORA tables.
* Digital Resilience Third-party Information Register: This application is used to download the Digital resilience third-party registers. The application contains the Microsoft Excel template that includes all tabs for reporting purposes. It helps the financial entities to maintain a comprehensive register of their contractual arrangements with ICT Third-party service providers at the individual entity, sub-consolidated, and consolidated levels.

  Customers use Digital resilience third-party registers to create or edit records in bulk or individually. Records can be created for assessments, branches, contracts, functions, legal entities, supply chains, third parties, or third-party engagements using the Microsoft Excel upload and download feature.  
  Note:  
  The IRM Professional license users can access Digital resilience third-party registers in the Operational Resilience Workspace. The TPRM license users can access Digital resilience third-party registers in the TPRM Workspace.  
  The Digital resilience third-party registers application fulfills multiple functions for the entities:
  * Assists the entities in tracking their ICT third-party risks.
  * Empowers the competent authorities in European Union to oversee ICT and third-party risk management within financial entities.
  * Aids European Supervisory Authorities (ESA) in identifying Critical ICT third-party service providers (CTPP) for EU level supervision.
  {#exploring-digi-resi-third-party-registers__ul_d5y_5lb_vcc}
{#exploring-digi-resi-third-party-registers__ul_n1h_nxs_cdc}

## Digital Operational Resilience {#exploring-digi-resi-third-party-registers__section_ksw_zyw_cdc}

Digital Operational Resilience refers to the ability of a financial entity to build, assure, and review its operational integrity and reliability. It ensures that the entity has the full range
of ICT related capabilities that are needed to secure its network and information systems. These systems support the continuous provision of financial services and maintain
their quality, even during disruptions. The continuity can be achieved directly or indirectly with the services provided by the ICT third-party service providers.

## Digital Operational Resilience Act (DORA) {#exploring-digi-resi-third-party-registers__section_txq_b2y_b5b}

Digital Operational Resilience aligns with the Digital Operational Resilience Act (DORA). It is a European Union (EU) regulation that came into effect on 16 January 2023 and it will be applicable from January 17, 2025. It enhances the ICT security of financial entities supervised by the European Supervisory Authorities (ESA)s and protects Europe's financial sector from major digital disruptions.

## Regulatory Technical Standards {#exploring-digi-resi-third-party-registers__section_y4b_bgk_cdc}

DORA Regulation mandates that financial entities incorporate and periodically review a strategy for managing ICT third-party risk within their ICT risk management framework. This strategy must include a policy governing the use of ICT services that support critical or important functions, as provided by third-party ICT service providers.

A financial institution's policy on using third-party ICT service providers plays a crucial role in defining key aspects of its governance, risk management, and internal control frameworks. This policy applies to these
services. Financial entities must perform risk assessments and due diligence before signing contracts with third-party ICT service providers. They must also ensure they can terminate these arrangements if needed and maintain business continuity for critical or important functions. For
instance, an action could be necessary where the service is not optimal, external ICT systems malfunction, or the service is disrupted due to sanctions.

## Pillars for DORA {#exploring-digi-resi-third-party-registers__section_eh3_scy_cdc}

Digital Operational Resilience Act (DORA) comprises the important pillars:

1. ICT Risk Management
2. ICT Incident Reporting
3. Digital Operational Resilience Testing
4. ICT Third-party Risk Management
5. Information and Intelligence Sharing
{#exploring-digi-resi-third-party-registers__ol_cyq_xdy_cdc}  
Note:  
Operational Resilience, Release 19.1.x focuses on the ICT Third-party Risk Management pillar only.

## Processing the records using GUI or Microsoft Excel {#exploring-digi-resi-third-party-registers__section_bqk_4c2_ddc}

Customers can manage the contractual arrangements by processing the records by using the graphical user interface (GUI) or by importing or exporting Microsoft Excel files in the Digital resilience third-party registers application.

For information on processing the records through the graphical user interface (GUI) or by importing or exporting Microsoft Excel files, see [Using Digital resilience third-party registers](https://servicenow-prod.fluidtopics.net/POSWOFZOZdmF6UM3H6elKA "Use the Digital resilience third-party registers application in the Operational Resilience Workspace to create, update, and track records of ICT third-party service providers.").

## Accessing the Digital resilience third-party registers application {#exploring-digi-resi-third-party-registers__section_nkb_g3x_cdc}

Users can access the Digital resilience third-party registers application in the following ways:

* Beginning with Release 19.1.x, customers who already have the Operational Resilience or the TPRM applications can access the Digital resilience third-party registers.
* These customers can download, install, and start using the Digital resilience third-party registers application.
{#exploring-digi-resi-third-party-registers__ul_rrf_dwt_ddc}  
Per DORA regulatory requirements, financial entities must identify all relevant ICT third-party service providers in template B_05.01, including:

* All direct ICT third-party service providers
* All ICT intra-group service providers
* All subcontractors identified in template B_05.02 on the ICT service supply chain
* All ultimate parent undertakings of the ICT third-party service providers referred to in (a), (b), and (c)
{#exploring-digi-resi-third-party-registers__ul_jkd_nw4_djc}

## Digital resilience third-party registers in Operational Resilience Workspace {#exploring-digi-resi-third-party-registers__section_nfz_b1b_2dc}

Upon opening the Operational Resilience Workspace, the menu featuring Digital resilience third-party registers is displayed.

## Digital resilience third-party registers in the TPRM
Workspace {#exploring-digi-resi-third-party-registers__section_b5x_21b_2dc}

For information on Digital resilience third-party registers in the TPRM
Workspace, see [Third-party Risk Management](https://servicenow-prod.fluidtopics.net/XT_s4OKsgYe7JgCQWxggiw "The ServiceNow GRC: Third-party Risk Management (TPRM) application enables you to proactively identify, assess, and mitigate risks that are associated with your third-party relationships. TPRM provides a centralized process for managing your portfolio of third parties, assessing and scoring risk, and performing remediation.").
* **[Use cases for updating the information registers](https://servicenow-prod.fluidtopics.net/P7DFA6OtPAS1G6rrRfEcXQ)**   
  Users with third-party registers and contractual details spread across various systems can automate the process of populating their information registers. This section outlines common scenarios for recording third-party data into Digital resilience third-party registers.
* **[Register of Information (ROI) regulatory packages](https://servicenow-prod.fluidtopics.net/~YzoGEPyUElpZ~_PjCkpsw)**   
  The Register of Information (RoI) is a regulatory reporting requirement under the Digital Operational Resilience Act (DORA) and is supported by the Digital resilience third-party registers application in the Operational Resilience Workspace.
* **[Validation framework for Register of Information in Operational Resilience](https://servicenow-prod.fluidtopics.net/9u~Rmcgc9NPnVEtiwe0SeA)**   
  The validation framework helps to verify that RoI packages meet regulatory requirements defined by the DORA.

