---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Use digital resilience third-party registers

# Using digital resilience third-party registers {#ariaid-title1}

* Release version: Australia
* 
* Updated May 15, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 13 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Using Digital Resilience Third-party Registers

The Digital Resilience Third-party Information Register application, available in the Vendor Management Workspace starting with Release 19.1.x, supports compliance with the EU Digital Operational Resilience Act (DORA).
It enables financial entities to create, update, and maintain comprehensive registers of contractual arrangements and digital resilience information related to ICT third-party service providers.
This application facilitates tracking ICT third-party risks and supports oversight by European Supervisory Authorities (ESA).
Show full answer Show less  
Users with the IRM Professional license access the application via the Operational Resilience Workspace, while TPRM license users access it in the TPRM Workspace. The application includes Microsoft Excel templates for bulk upload and download of records, streamlining management and reporting.

## Key Features

* **Record Management:** Create and update records for assessments, branches, contracts, functions, legal entities, supply chains, third parties, and third-party engagements either individually or in bulk using Excel upload/download.
* **Legal Entities and Branches:** Manage essential regulatory data such as Legal Entity Identifier (LEI), registration details, and entity hierarchies. Branch details include location, ownership, and business units for reporting.
* **Functions and Third Parties:** Document specific ICT services, their criticality, and third-party provider details including service types, registration country, and financial data.
* **Engagements and Contracts:** Track and link contractual arrangements between legal entities, branches, functions, and third parties, capturing comprehensive details required for DORA compliance like service provider reliance, data sensitivity, and contract terms.
* **Supply Chains:** Capture ICT service supply chain information with automatic rank-based record updates linked to contractual arrangements.
* **Assessments:** Conduct and document annual reviews of contracts and third parties, including identifying ICT third-party service providers and contractual references.
* **Bulk Data Handling:** TPR administrators can perform bulk record creation and updates using Excel upload/download requests, enhancing data management efficiency.
* **Register of Information (RoI) Packages:** Generate regulator-ready, DORA-compliant CSV report packages that include metadata and structured reports for automated validation by third-party risk managers. Supports currency conversion and expense aggregation for standardized reporting.
* **Validation Framework:** Automated validation of RoI packages with detailed error reporting and downloadable Excel templates to facilitate issue resolution and ensure regulatory accuracy.

## Practical Benefits and Compliance

This application empowers financial entities to:

* Maintain accurate and up-to-date digital resilience information aligned with DORA requirements.
* Efficiently manage third-party ICT risk and contractual data at entity, branch, and consolidated levels.
* Support regulatory reporting and oversight through automated, regulator-ready export packages and validation tools.
* Ensure operational continuity by effectively monitoring ICT third-party service providers and their engagements.

By using this application, ServiceNow customers can confidently meet EU regulatory mandates, reduce manual data handling, and streamline third-party risk management processes.

## Next Steps for ServiceNow Customers

* Activate the Digital Resilience Third-party Information Register application in the appropriate workspace based on your license.
* Set up and maintain required records sequentially, including legal entities, branches, functions, third parties, engagements, contracts, supply chains, and assessments.
* Utilize Excel upload/download features for bulk data operations, ensuring currency and expense data accuracy for reliable reporting.
* Generate and validate Register of Information packages ahead of regulatory submissions using provided tools and templates.
* Refer to ServiceNow documentation for detailed guidance on configuration, role assignments, and compliance best practices.  
Use the Digital Resilience Third-party Information Register application in the Vendor Management Workspace to create, update, and track assessments, branches, legal entities, and so on, and maintain registers of contractual arrangements with ICT third-party service providers.

## Digital resilience third-party registers {#tprm-dora__section_xwl_rx3_vcc}

Beginning with Release 19.1.x, the Digital Resilience Third-party Information Register application is supported for DORA compliance in the Vendor Management Workspace.

The Digital Resilience Third-party Information Register application is used to download the Digital resilience third-party registers. The application contains the Microsoft Excel template that includes all tabs for reporting purposes. It helps the financial entities to maintain a comprehensive register of their contractual arrangements with ICT
Third-party service providers at the individual entity, sub-consolidated, and consolidated levels.

You can use Digital resilience third-party registers to create or edit the records in bulk or individually for assessments, branches, contracts, functions, legal entities, supply chains, third parties, or third-party
engagements using the Microsoft Excel upload and download feature.  
Note:  
The IRM Professional license users can access Digital resilience third-party registers in the Operational Resilience Workspace. The TPRM license users can access Digital resilience third-party registers in the TPRM Workspace.  
The Digital resilience third-party registers application fulfills multiple functions for the entities:

* Assists the entities in tracking their ICT third-party risks.
* Empowers the competent authorities in European Union to oversee ICT and third-party risk management within financial entities.
* Aids European Supervisory Authorities (ESA) in identifying Critical ICT third-party service providers (CTPP) for EU level supervision.
{#tprm-dora__ul_d5y_5lb_vcc}  
The following applications are used in the background for the Digital resilience third-party registers application:

* Digital Resilience Third-party Information Register: This application is used to download the Digital resilience third-party registers application. It contains the Microsoft Excel template including all tabs for reporting purposes.
* Digital Operational Resilience Management: This application is used for uploading and downloading of all individual DORA tables. It's automatically installed when the Digital Resilience Third-party Information Register is activated.
{#tprm-dora__ul_n1h_nxs_cdc}
For more information on configuring Digital resilience third-party registers and its possible use cases, see [Configuring Digital resilience third-party registers](https://servicenow-prod.fluidtopics.net/c8OW~hfm7_Yy65BumRXN5A "Set up Digital resilience third-party registers in the Operational Resilience Workspace to manage the records of ICT third-party service providers.") and [Use cases for updating the information registers](https://servicenow-prod.fluidtopics.net/P7DFA6OtPAS1G6rrRfEcXQ "Users with third-party registers and contractual details spread across various systems can automate the process of populating their information registers. This section outlines common scenarios for recording third-party data into Digital resilience third-party registers.").

## Digital Operational Resilience {#tprm-dora__section_r15_stc_hdc}

Digital Operational Resilience refers to the ability of a financial entity to build, assure, and review its operational integrity and reliability. It ensures that the entity has the full range of ICT related capabilities that are needed to secure its network and information systems. These systems support the continuous provision of financial services and maintain their quality, even
during disruptions. The continuity can be achieved directly or indirectly with the services provided by the ICT third-party service providers.

## Digital Operational Resilience Act {#tprm-dora__section_wbm_vwv_2dc}

Digital Operational Resilience aligns with the Digital Operational Resilience Act (DORA). It's a European Union (EU) regulation that came into effect on 16 January 2023 and it will be applicable from January 17, 2025. It enhances the ICT security of financial entities supervised by the European Supervisory Authorities (ESA)s and protects Europe's financial sector from major digital disruptions.

For more information on DORA and the Digital Resilience Third-party Information Register application, see <https://www.eba.europa.eu/activities/direct-supervision-and-oversight/digital-operational-resilience-act> and [Exploring Digital resilience third-party registers](https://servicenow-prod.fluidtopics.net/HXPuN6bxtn09KaENE75ivA "The Digital resilience third-party registers application empowers the financial entities to maintain registers of contractual arrangements with Information and Communication Technology (ICT) third-party service providers and comply with Digital Operational Resilience Act (DORA) regulation.").

## Creating records for Digital resilience third-party registers {#tprm-dora__section_wjv_qx3_vcc}

Third-party risk (TPR) assessors \[sn_vdr_risk_asmt.vendor_assessor\] and TPR managers \[sn_vdr_risk_asmt.vendor_manager\] can create and update these records by navigating to the Digital resilience third-party registers in the Vendor Management Workspace. You must create or update these records in a specific sequence. For more information on this sequence, see [Creating and reviewing the records](https://servicenow-prod.fluidtopics.net/xhLMInx_h5AuIqCWAQ2HTA "The Operational Resilience administrators and managers can access the Digital Resilience Choices records in an instance. Create or update records such as legal entities, branches, functions, and contracts in a specific order into the Digital resilience third-party registers application. Those specifics are outlined in this section.").  
Note:  
TPR assessors and TPR managers can delete Third party, Third-party engagement, and Contract records. TPR administrators \[sn_vdr_risk_asmt.vendor_risk_admin\] can delete all record types by navigating to each individual record and selecting Delete.

The following example shows how records appear in the Digital resilience third-party registers in the Vendor Management Workspace.  

<br />

The following records can be manually created and updated.

Legal entities

:   You can create a legal entity record, by navigating to the Digital resilience third-party registers in the Vendor Management Workspace. Here, you can view existing legal entities and enhance their digital resilience information to comply with DORA regulations. After installing the Digital Resilience Third-party Information Register application, a Legal Entities related list is added for existing companies that aren't already defined as a third party,
    enabling you to add their details. The Legal Entity record includes essential fields for regulatory reporting, such as the Legal Entity Identifier (LEI), name, country of registration, and entity type. These
    fields are offered as choice lists within the system. The system acknowledges the entity hierarchy, with no additional details required for ultimate parents, while subsidiaries must specify their parent entity.
    The date of registration for each legal entity is also noted. Additionally, specific details like the last update, integration date, removal status, deletion date, currency used, and total asset value are
    documented for each entity, as required by regulators for entities engaging with external third parties for outsourced technical services. Regulators mandate these specific details for legal entities engaging
    with external third parties for outsourced technical services.

    Note:  
    Existing third parties aren't shown in the Legal entities list. Company records can only be defined as a Third party or Legal entity. For companies and legal entities, the Vendor option is set to False. (The check box isn't selected.)

    For more information see, [Create a legal entity and enhance digital resilience data](https://servicenow-prod.fluidtopics.net/rDZyh6rTOYkEWfS4cXWr_w "Create a legal entity record in Digital resilience third-party registers using Third-party Risk Management. You can then configure digital resilience information for the legal entity such as its name, type, country, and hierarchy."), [Create New Company form](https://servicenow-prod.fluidtopics.net/t2iifgGCICAO2N83JcJyXA "On the Create New Company form, fill in the fields for the legal entity."), and [Create New Legal entity form](https://servicenow-prod.fluidtopics.net/Lz3Dm~Ct4WdvG8PqV5wnEA "On the Create New Legal entity form, fill in the fields to set up the digital resilience information.").  
    Note:  
    When you enter or update the LEI code on a legal entity record, the system validates it against the GLEIF database and auto-populates the name and country fields. If you then edit the name or country to a value that no longer matches GLEIF data, an inline warning is displayed. For more information, see [Validate Legal Entity Identifier codes for DORA reporting](https://servicenow-prod.fluidtopics.net/PQXkTi5bEbCNKzjDx9WUgg "Review and resolve Legal Entity Identifier (LEI) validation results for DORA Register of Information reporting. LEI validation runs automatically during Plain-CSV Reporting Package generation and Microsoft Excel upload to verify that LEI codes in the digital resilience registers exist in the GLEIF database and have an active and issued status.").

Branches

:   You can create a branch record by navigating to the Digital resilience third-party registers in the Vendor Management Workspace. This enables you to enhance the branch's digital resilience information to help ensure compliance with DORA regulations. A legal entity can operate multiple branches across different cities or countries, and all these branches can be documented. When a new
    branch is established, its information must be included for regulatory reporting. Some common details captured include the branch name and description, owner's details, business units and departments for
    reporting purposes, whether the branch is a head office or another type, the branch ID, and its originating country. The branch number is auto-generated, and once all details are complete, the information is
    ready to be captured in the information register.

    For more information see, [Create a branch and enhance digital resilience data](https://servicenow-prod.fluidtopics.net/HRkW_FEjNbnp_77CPcU~9Q "Create a branch record in Digital resilience third-party registers using Third-party Risk Management. You can then enhance its digital resilience information for compliance with DORA regulation.") and [Create New Branch form](https://servicenow-prod.fluidtopics.net/bmswxzRN6DGXsf6l_NyVNw "On the Create New Branch form, fill in the fields.").

Function

:   You can create a function record, by navigating to the Digital resilience third-party registers in the Vendor Management Workspace. Here, you can add details such as the function identifier, license activity, function name, and criticality or importance assessment. Each function represents a specific
    service or group of services as defined by the Digital Operational Resilience Act (DORA). The functions record is used to capture detailed information about each function, including descriptive text. Once the function record is created, you
    can enhance its digital resilience information to help ensure compliance with DORA regulations, effectively documenting the third-party provided ICT service usage.

    For more information see, [Create a function and enhance digital resilience data](https://servicenow-prod.fluidtopics.net/GslS18DhI6~lL3e_keVhPg "Create a function record in Digital resilience third-party registers using Third-party Risk Management where you can configure details of the function such as function identifier, license activity, function name, criticality, or importance assessment details. You can then enhance its digital resilience information for compliance with DORA regulation.") and [Create New Function form](https://servicenow-prod.fluidtopics.net/v1L6S~V1xlnE3J0FWY_x5w "On the Create New Function form, fill in the fields.").

Third parties

:   You can access and view existing third-party records by selecting the Third parties list within the Digital resilience third-party registers in the Vendor Management Workspace. After installing the Digital resilience third-party registers, a Digital Resilience Information related list is added on the third party's page, enabling you to set up the digital resilience
    information details.

    Here, you can view the legal entity ID of the third party, which can be captured by the Value Added Tax (VAT) number or Company Registration Number (CRN). You can specify the country of registration and its code,
    which the system uses to generate the ID. Additionally, you can indicate if the third party is an ultimate or a subsidiary, include the name of the ICT third party and the type of service they provide (for example, Software as a Service), and optionally note if an individual acts on behalf of the organization. You can also
    select the reporting currency and input the total annual expense for this engagement.

    For more information see, [Create a third party and enhance digital resilience data](https://servicenow-prod.fluidtopics.net/1~UEt2wnonZ3k6~quY_r1A "Create a third-party record in Digital resilience third-party registers using Third-party Risk Management. Add the details of the third-party company such as its name, address, phone number, vendor manager. You can then enhance its digital resilience information for compliance with DORA regulation."), [Create New Company form](https://servicenow-prod.fluidtopics.net/c1ehx~s2EHoMjoacJYlOxQ "On the Create New Company form, fill in the fields for the third party."), and [Create New ICT third-party service provider form](https://servicenow-prod.fluidtopics.net/TwQ7rOTxVJEpR_22tN7Rtw "On the Create New ICT third-party service provider form, fill in the fields.").

Engagements

:   You can access and view existing third-party engagement records by selecting the Third-party engagements list within the Digital resilience third-party registers in the Vendor Management Workspace. After you install the Digital resilience third-party registers, the Digital Resilience Information related list is added on the third-party engagements page, enabling you to set up the digital
    resilience information details.

    Here you can view the third party's name, its type, annual spend, engagement tier, and other relevant information. You can enhance the record's digital resilience information by creating ICT third-party service provider records. Add ICT third-party service provider details such as the name of the service provider, its identification code, type of ICT services, currency, and so on. This enhances the digital resilience information of its associated third-party engagement for compliance with DORA regulation.

    For more information see, [Create a third-party engagement and enhance digital resilience data](https://servicenow-prod.fluidtopics.net/2Rq66Mchz~8tUZQ2mMgPoA "Create a third-party engagement record in Digital resilience third-party registers using Third-party Risk Management. Add details of the third-party engagement such as the name of the third party, its type, annual spend, engagement tier. You can then enhance its digital resilience information for compliance with DORA regulation."), [Create New Third-party engagement form](https://servicenow-prod.fluidtopics.net/A5Xs_WfQyPD9dBFCUyUJEQ "Use the create new third-party engagement form to capture all the information that you need to create a third-party engagement record in Digital resilience third-party registers using Third-party Risk Management. As a third-party risk assessor you can create a third-party engagement record."), and [Add Digital resilience information to third-party engagements](https://servicenow-prod.fluidtopics.net/tVx6QMrEO7r~MIcAuQan5w "Add Digital resilience information to third-party engagements by creating ICT third-party service provider records in Digital resilience third-party registers using Third-party Risk Management. Add details such as name of the service provider, its identification code, type of ICT services, currency, and so on. This enhances the digital resilience information of its associated third-party engagement for compliance with DORA regulation.").

Contracts
:   You can create a contract record by navigating to the Digital resilience third-party registers in the Vendor Management Workspace. Here, you can add details such as the vendor name, start and end dates, state, substate, and other relevant information. Once the contract record is established, you can
    enhance its digital resilience information to help ensure compliance with the DORA regulations.

    The Digital resilience third-party registers provide details about who within your organization is using externally outsourced ICT services, which functions and branches are using them, and who the third-party providers and their engagements are. Contracts serve as the link between these aspects,
    binding legal entities, branches, and functions to third parties and their engagements.

    You can access these contracts through the Contracts list in the Digital resilience third-party registers. Alternatively, navigate to a specific legal entity's record, open the Legal Entities related list, and access all associated
    contract information. To view contracts for a legal entity, go to the legal entity's record, open the Legal Entities related list, and navigate to the different Contracts-related tabs. If
    the entity signing the contract differs from the one using it, that detail is included in the record, along with the service provider. Details captured in these records can include data storage and processing
    locations, data sensitivity and service provider reliance, contract and termination details, annual assessments, and contractual reference numbers.

    For more information see, [Create a contract and enhance digital resilience data](https://servicenow-prod.fluidtopics.net/a_DX1HAn5_CUBGXOjPk7ig "Create a contract record in Digital resilience third-party registers using Third-party Risk Management where you add details of the contract such as vendor name, start and end dates, state, substate. You can then enhance its digital resilience information for compliance with DORA regulation."), [Create New Contract form](https://servicenow-prod.fluidtopics.net/qDHHVl8I_PyFYBo~L5WN1Q "On the Create New Contract form, fill in the fields."), and [Create New Contractual arrangement form](https://servicenow-prod.fluidtopics.net/KKPBnA2HEx2yovKd6eJMBw "On the Create New Contractual arrangement form, fill in the fields.").  
    Note:  
    Provider‑level annual expense totals may be automatically aggregated during report generation when all contracts meet the required criteria. Aggregation applies only to exported reports and does not change contract records.

    For more information, see [Currency conversion and third-party total expense aggregation](https://servicenow-prod.fluidtopics.net/wCCuA_CfAvFcvS0K4_DNAw "During report generation, the Register of Information (RoI) can standardize contract annual expenses by converting amounts to a base currency and aggregating totals per eligible third-party provider or engagement. The RoI is a regulatory reporting requirement under the Digital Operational Resilience Act (DORA) and is supported by the Digital Resilience Third-party Information Register application in the Vendor Management Workspace application.").

Supply chains
:   You can create a supply chain record by navigating to the Digital resilience third-party registers in the Vendor Management Workspace. Here you can capture details of the supply chain such as the type of the ICT services, Legal Entity Identifier (LEI) of the entity that provides the ICT services, and so on.

    For more information see, [Create a supply chain and enhance digital resilience data](https://servicenow-prod.fluidtopics.net/dkVAEwU0dTXW3wsPm70yuw "Create an Information and Communication Technology (ICT) service supply chain record in Digital resilience third-party registers using Third-party Risk Management. You can then configure details of the supply chain such as the type of the ICT services, Legal Entity Identifier (LEI) of the entity that provides the ICT services.") and [Create New Contractual arrangement form](https://servicenow-prod.fluidtopics.net/KKPBnA2HEx2yovKd6eJMBw "On the Create New Contractual arrangement form, fill in the fields.").

    Note:  
    Rank 1 supply chain records are generated automatically when you save a Contractual Arrangements -- Specific Information record. If you update or remove the Type of ICT services value, the corresponding supply chain records update or delete automatically. For more information, see [Create a supply chain and enhance digital resilience data](https://servicenow-prod.fluidtopics.net/dkVAEwU0dTXW3wsPm70yuw "Create an Information and Communication Technology (ICT) service supply chain record in Digital resilience third-party registers using Third-party Risk Management. You can then configure details of the supply chain such as the type of the ICT services, Legal Entity Identifier (LEI) of the entity that provides the ICT services.").

Assessments

:   You can create an assessment of the ICT service record by navigating to the Digital resilience third-party registers in the Vendor Management Workspace. Here, you can add details such as the contractual arrangement reference number, identification code, and type of code for the ICT third-party service provider. Once the assessment is created, you can enhance its digital resilience information to help ensure compliance with the DORA regulation. It's required to review your contracts and third parties annually.

    Add details such as the contractual arrangement reference number, identification code, and type of code for the ICT third-party service provider. You can then enhance its digital resilience information for compliance with DORA regulation.

    For more information see, [Create an assessment and enhance digital resilience data](https://servicenow-prod.fluidtopics.net/~UPTNPVNyBvq7oh0FfkyyA "Create an assessment of the Information and Communication Technology (ICT) service in Digital resilience third-party registers using Third-party Risk Management. Add details such as the contractual arrangement reference number, identification code, and type of code for the ICT third-party service provider. You can then enhance its digital resilience information for compliance with DORA regulation.") and [Create New Contractual arrangement form](https://servicenow-prod.fluidtopics.net/KKPBnA2HEx2yovKd6eJMBw "On the Create New Contractual arrangement form, fill in the fields.").

For more information on the roles related to using Digital resilience third-party registers, see [Roles in Third-party Risk Management](https://servicenow-prod.fluidtopics.net/evCsII5xVZfz3HPLJm9YZw "Roles determine permissions and access in TPRM.").

## Uploading and downloading records {#tprm-dora__section_dqj_bqt_ddc}

In addition to creating individual records, TPR assessors and TPR managers can request the download of records using the Excel download/upload requests feature. For more information see, [Create a Microsoft Excel download request](https://servicenow-prod.fluidtopics.net/mSgZh3NSKhCO0W33CsxeMA "Create a Microsoft Excel download request to download the records from the Digital resilience third-party registers using Third-party Risk Management for auditing purposes."), and [Create New Excel download/upload request form](https://servicenow-prod.fluidtopics.net/OaPtuubV~CP_keZ0oUo8DQ "Use the Create New Excel download/upload request form to capture all the information that you need to create a download/upload request for Digital resilience third-party registers using the Third-party Risk Management application. As a third-party risk manager or third-party risk assessor you can create an Excel download/upload request record.").  
Note:  
You need the TPR administrator role to edit and delete Excel download/upload requests.  
TPR administrators can create and update records in bulk using the Excel download/upload requests feature. For more information, see [Create records in bulk](https://servicenow-prod.fluidtopics.net/~BIGOoGxka8bK_lbBRgp6w "Create records in bulk from the Digital resilience third-party registers using Third-party Risk Management rather than creating one record at a time for single or multiple entities. You can save time and effort by working on multiple records at a time.") and [Update existing records in bulk](https://servicenow-prod.fluidtopics.net/ckd1BgvuG6e11c1Nw2QPaQ "Update existing records in bulk from the Digital resilience third-party registers using Third-party Risk Management.").  
Note:  
Annual expense data is evaluated during Register of Information report generation when currency conversion or third-party total expense aggregation is enabled on the Excel download/upload request. Ensure that currencies and annual expense fields are accurate to avoid conversion failures or skipped aggregation

The following example shows where you can view and create Excel download/upload requests.  

<br />

Note:  
If you have the Third-party assessment reviewer \[sn_vdr_risk_asmt.vendor_assessment_reviewer\] role, you can export a list of each record type by navigating to the list of records you want in the Digital resilience third-party registers in the Vendor Management Workspace.

## Register of Information packages {#tprm-dora__section_ppf_knt_hhc}

After upgrading the Digital Resilience Third-party Information Register application to version 21.1.x, third-party assessors (sn_vdr_risk_asmt.vendor_assessor) can generate regulator-ready Register of Information (RoI)
packages using the Plain-CSV Report Package option on the download page. The resulting ZIP file includes metadata and report folders structured to regulator specifications, with filenames containing the Legal Entity
Identifier (LEI), entity ID, and release version. This format ensures EU DORA compliance and supports automated validation workflows. Users can follow the guide provided in the Instructions section on the Download/Upload
request page for step-by-step instructions and required permissions. For more information, see [Register of information regulatory packages](https://servicenow-prod.fluidtopics.net/KJKt1InLPwVQr8A6g18ZqA "The Register of Information (RoI) is a regulatory reporting requirement under the Digital Operational Resilience Act (DORA) and is supported by the Digital Resilience Third-party Information Register application in the Vendor Management Workspace application.") and [Generate a register of information package](https://servicenow-prod.fluidtopics.net/BXu5Th2kmaD1K~KI3jouMg "Use the CSV report option in the download page to generate regulator-ready Register of Information (RoI) packages.").

During RoI package generation, users can optionally enable currency conversion and third-party total expense aggregation. When enabled, these options standardize annual expense values using
historical exchange rates and consolidate eligible contract expenses at the provider or engagement level in the exported package.

Third-party risk managers (sn_vdr_risk_asmt.vendor_risk_manager) can validate downloaded RoI packages using the same Plain-CSV Report Package option. The system performs validation across multiple tables, checking file format,
structure, encoding, naming conventions, and field-level data. If validation warnings are detected, a report is automatically attached, including mappings to regulator fields such as Template Code, Row Code, and Column Code.
These reports also include real-world field labels, rule expressions, and record identifiers. Validation errors can be cross-referenced using a downloadable Excel master template that mirrors the CSV structure, simplifying
issue identification and resolution. This template can be generated using the Excel master template option on the download page. Additional enhancements include support for "Not applicable" values, enforcement of file size
limits, and clearer error messages for malformed data. For more information, see [Validation framework for Register of Information](https://servicenow-prod.fluidtopics.net/xu3iRieHwR4nigy87uEaAw "The validation framework helps ensure that RoI packages meet regulatory requirements defined by the DORA."), [Validate Register of Information packages](https://servicenow-prod.fluidtopics.net/7Xn6glejLUKS1LdulbJPZQ "Run real-time validation on Register of Information (RoI) packages to help ensure compliance with DORA requirements."), and [Validate Legal Entity Identifier codes for DORA reporting](https://servicenow-prod.fluidtopics.net/PQXkTi5bEbCNKzjDx9WUgg "Review and resolve Legal Entity Identifier (LEI) validation results for DORA Register of Information reporting. LEI validation runs automatically during Plain-CSV Reporting Package generation and Microsoft Excel upload to verify that LEI codes in the digital resilience registers exist in the GLEIF database and have an active and issued status.").  
Note:  
Use the ITS on the Registers of Information, adopted and published in the Official Journal of the European Union ([Commission Implementing Regulation (EU) 2024/2956](https://eur-lex.europa.eu/eli/reg_impl/2024/2956/oj/eng)), together with the EBA FAQs on RoI reporting ([EBA FAQs)](https://www.eba.europa.eu/sites/default/files/2025-03/b90dc121-77cd-47cc-a8c7-ceebda33e381/20250319%20-%20DORA%20RoI%20reporting%20FAQ%20(updated).pdf), to understand regulatory reporting requirements and column-level descriptions.

Refer to the sample files provided under the taxonomy architecture v2.0 to validate reporting structure. Download the taxonomy package and, under `instances/xBRL-CSV`, locate the DORA sample file
`DUMMYLEI123456789012.CON_FR_DORA010100_DORA_2024-12-31_20241213174803429` to review the expected xBRL-CSV format.

