Register of information regulatory packages
Summarize
Summary of Register of information regulatory packages
The Register of Information (RoI) is a mandatory regulatory reporting package under the Digital Operational Resilience Act (DORA) designed for financial entities to demonstrate compliance. It includes detailed data on legal entities, third-party service providers, contracts, and functions. RoI submissions are structured according to the European Banking Authority’s specifications and support automated validation workflows for consistency and compliance.
Show less
Key Features
- Regulator-ready RoI Packages: Starting with ServiceNow version 21.1.x, third-party assessors can generate ZIP files containing CSV reports and metadata organized by legal entity identifiers and release versions for direct submission to regulators.
- Reporting Options: Users can download an Excel master template for internal data preparation and review or a Plain-CSV reporting package for regulator submission and validation.
- Validation Framework: The RoI includes DPM business validation rules and configuration files that enable third-party risk administrators to maintain and review validation logic, ensuring accurate regulatory submissions.
- Automated Notifications: After report validation, the system emails the request initiator with validation results and attaches reports highlighting errors or warnings.
- Currency Conversion and Aggregation: Optional features during report generation allow standardizing currency values and aggregating third-party total expenses without modifying source data.
- Role-based Access and Workflow Support: The Digital Resilience Third-party Information Register within the Vendor Management Workspace provides comprehensive tools for data capture, report generation, packaging, validation, and managing RoI requests with appropriate access controls.
Practical Benefits for ServiceNow Customers
ServiceNow customers using the Digital Resilience Third-party Information Register can efficiently meet DORA regulatory requirements through automated, structured reporting packages that align with EU standards. The platform supports robust validation workflows, reducing errors and streamlining regulator submissions. Role-based access ensures secure management of sensitive data and regulatory processes. Optional currency conversion and expense aggregation enhance reporting accuracy. Customers can leverage clear instructions and templates to prepare and validate data effectively, thereby simplifying compliance with DORA’s ICT third-party risk management and incident reporting pillars.
The Register of Information (RoI) is a regulatory reporting requirement under the Digital Operational Resilience Act (DORA) and is supported by the Digital Resilience Third-party Information Register application in the Vendor Management Workspace application.
RoI overview
The RoI is a structured data package that financial entities must submit to regulators to demonstrate compliance with DORA. It includes information about legal entities, third-party service providers, contracts, and functions.
Starting with version 21.1.x, third-party assessors (sn_vdr_risk_asmt.vendor_assessor) can generate regulator-ready RoI packages using the Plain-CSV Report Package option on the download page. The ZIP file includes metadata and report folders structured to regulator specifications, with file names containing LEI, entity ID, and release version. This enhancement ensures EU DORA compliance and supports automated validation workflows. You can follow the guide provided in the Instructions section on the Download/Upload request page for step-by-step instructions and required permissions.
The RoI framework is designed to align with DORA’s five pillars, particularly ICT third-party risk management and incident reporting. TPRM contributes third-party risk data that is included in RoI packages generated by Digital Operational Resilience capabilities. These RoI packages follow the European Banking Authority’s structure and validation requirements.
After validation completes, the system automatically notifies the request initiator by email and attaches the validation report when errors or warnings are detected.
Currency conversion and aggregation
During report generation, you can enable optional currency conversion and third‑party total expense aggregation. These options standardize or combine annual expense values in the reporting package. These options affect only the generated reporting package and do not modify source records in the digital resilience registers.
For more information, see Currency conversion and third-party total expense aggregation.
Digital Resilience Third-party Information Register support for RoI
The Digital Resilience Third-party Information Register provides the following capabilities to support RoI compliance:
- Data capture for entities, contracts, functions, and third parties
- CSV report generation aligned with regulator specifications
- ZIP packaging with metadata and report folders
- Validation workflows for technical, schema, and business rule checks
- Role-based access for managing RoI requests
All RoI-related actions are performed in the Digital resilience third-party registers section of the Vendor Management Workspace. This workspace provides access to download/upload requests, validation tools, and master templates.
For more information, see Generate a register of information package