---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Create a contract and enhance digital resilience data

# Create a contract and enhance digital resilience data {#ariaid-title1}

* Release version: Australia
* 
* Updated May 15, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Create a contract record in Digital resilience third-party registers using Third-party Risk Management where you add details of the contract such as vendor name, start and end dates, state, substate. You can then enhance its digital resilience information for compliance with DORA regulation.

## Before you begin

Role required: sn_vdr_risk_asmt.vendor_assessor

## About this task

The Digital resilience third-party registers include details about who within your organization is using externally outsourced ICT services, which functions and branches are using them, and who the third-party providers and their engagements are. The contracts link these two aspects together.

The contracts link both parties---those using the information and those providing it. Essentially, they bind legal entities, branches, and functions to third parties and third-party engagements.

You can navigate to the contracts from the Contracts menu item in Digital resilience third-party registers. Alternatively, you can navigate to the legal entities record, open the Legal entities tab, and navigate to the contracts.  
Note:  
The annual expense may be converted during report generation if currency conversion is enabled. If aggregation is enabled and all criteria are met, contract expenses may also be combined into a provider‑level total.

After setting up contract and Specific Information records, you can generate a Register of Information reporting package. For more information, see [Generate a register of information package](https://servicenow-prod.fluidtopics.net/BXu5Th2kmaD1K~KI3jouMg "Use the CSV report option in the download page to generate regulator-ready Register of Information (RoI) packages.").

LEI codes on records associated with this contract are validated against the GLEIF database during Register of Information reporting. For more information, see [Validate Legal Entity Identifier codes for DORA reporting](https://servicenow-prod.fluidtopics.net/PQXkTi5bEbCNKzjDx9WUgg "Review and resolve Legal Entity Identifier (LEI) validation results for DORA Register of Information reporting. LEI validation runs automatically during Plain-CSV Reporting Package generation and Microsoft Excel upload to verify that LEI codes in the digital resilience registers exist in the GLEIF database and have an active and issued status.").

## Procedure

1. Navigate to WorkspacesVendor Management Workspace, select the list icon ![]() and then navigate to Digital resilience third-party registers.
2. Select Contracts and then create a contract by selecting New.
3. On the form, fill in the fields.  
   For descriptions of all these fields, see [Create New Contract form](https://servicenow-prod.fluidtopics.net/qDHHVl8I_PyFYBo~L5WN1Q "On the Create New Contract form, fill in the fields.").
4. Select Save.
5. To submit the contract for review, select Submit for Review.
6. To add entities signing the contract to use the ICT services associated with the contract, navigate to the Entities signing contract to use service related list of the contract record and select Add.
7. Select Save.
8. To add entities using the ICT services associated with the contract, navigate to the Entities making use of services related list of the contract record and select Add.
9. Select Save.  
   Note:  
   When creating multiple entities using the ICT services, the combination of LEI and Nature of the entity must be unique. If the nature of the entity is a branch, the combination of the LEI of the entity, Nature of the entity, and the identification code of the branch must be unique.
10. To add entities signing the contract to provide ICT services associated with the contract, navigate to the Entity providing services related list of the contract record and select Add.
11. Select Save.
12. To add third parties signing the contract to provide ICT services associated with the contract, navigate to the Third party signing contract to provide services related list of the contract record and select Add.
13. Select Save.
14. To add third-party engagements signing the contract to provide ICT services associated with the contract, navigate to the Third-party engagements signing contract related list of the contract record and select Add.
15. Select Save.
16. To set up the digital resilience information for DORA regulation, navigate to the Specific information related list and create a contractual arrangement by selecting New.
17. On the form, fill in the fields.
18. Select Save.  
    * When you save a Specific Information record, Rank 1 ICT service supply chain records are generated automatically using the Type of ICT services value. If you update the Type of ICT services value, the supply chain records update automatically. If you remove a Type of ICT services value, the corresponding Rank 1 and higher supply chain records are deleted automatically. To create Rank 2 and higher supply chain records manually, see [Create a supply chain and enhance digital resilience data](https://servicenow-prod.fluidtopics.net/dkVAEwU0dTXW3wsPm70yuw "Create an Information and Communication Technology (ICT) service supply chain record in Digital resilience third-party registers using Third-party Risk Management. You can then configure details of the supply chain such as the type of the ICT services, Legal Entity Identifier (LEI) of the entity that provides the ICT services.").
    * If a Specific Information record with the same combination of contract reference, entity using service, service provider, country of provision, function identifier, Type of ICT services, storage location, and processing location already exists, the save is blocked. The error message includes a link to the conflicting record so you can compare the two records before saving.

    Note:  
    If the Storage of data field is set to No on a contractual arrangement, the associated location field values are cleared automatically.
19. To add intra-group contractual arrangements, navigate to the Intra-group contractual arrangements tab of the contract and select Add.  
    Note:  
    If all Specific Information records are removed from a contract, making it no longer DORA relevant, any intra-group contractual arrangements linked to the contract are removed automatically. A confirmation message is displayed when this occurs.
20. Select Save.
21. To add ICT service supply chains associated with the contract, navigate to the ICT service supply chains tab of the contract and select New and fill in the fields.
22. Select Save.
23. To add Assessments of the ICT services associated with the contract, navigate to the Assessments of the ICT services tab of the contract and select New and fill in the fields.
24. Select Save.  
    For descriptions of all these fields, see [Create New Contractual arrangement form](https://servicenow-prod.fluidtopics.net/KKPBnA2HEx2yovKd6eJMBw "On the Create New Contractual arrangement form, fill in the fields.").  
    Note:  
    The annual expense may be converted during report generation if currency conversion is enabled. If aggregation is enabled and all criteria are met, contract expenses may also be combined into a provider‑level total.
25. To edit the contract record, select it from the list and select Save after making your edits.
26. To export contract records, select Export.
27. To delete the contract record, select it from the list and select Delete.
{#tprm-drtp-reg-contract__steps_jky_zbn_ycc}
**Related tasks**   

* [Generate a register of information package](https://servicenow-prod.fluidtopics.net/BXu5Th2kmaD1K~KI3jouMg "Use the CSV report option in the download page to generate regulator-ready Register of Information (RoI) packages.")
* [Create a supply chain and enhance digital resilience data](https://servicenow-prod.fluidtopics.net/dkVAEwU0dTXW3wsPm70yuw "Create an Information and Communication Technology (ICT) service supply chain record in Digital resilience third-party registers using Third-party Risk Management. You can then configure details of the supply chain such as the type of the ICT services, Legal Entity Identifier (LEI) of the entity that provides the ICT services.")
* [Validate Legal Entity Identifier codes for DORA reporting](https://servicenow-prod.fluidtopics.net/PQXkTi5bEbCNKzjDx9WUgg "Review and resolve Legal Entity Identifier (LEI) validation results for DORA Register of Information reporting. LEI validation runs automatically during Plain-CSV Reporting Package generation and Microsoft Excel upload to verify that LEI codes in the digital resilience registers exist in the GLEIF database and have an active and issued status.")  
**Related reference**   

* [Create New Contract form](https://servicenow-prod.fluidtopics.net/qDHHVl8I_PyFYBo~L5WN1Q "On the Create New Contract form, fill in the fields.")

*[\>]: and then


