---
sourceDocument: Xanadu Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/governance-risk-compliance

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Register of information regulatory packages

# Register of information regulatory packages {#ariaid-title1}

* Release version: Xanadu
* 
* Updated November 3, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

The Register of Information (RoI) is a regulatory reporting requirement under the Digital Operational Resilience Act (DORA) and is supported by the Digital Resilience Third-party Information Register application in the Vendor Management Workspace application.

## RoI overview

The RoI is a structured data package that financial entities must submit to regulators to demonstrate compliance with DORA. It includes information about legal entities, third-party service providers, contracts, and functions.  
Starting with version 21.1.x, third-party assessors (sn_vdr_risk_asmt.vendor_assessor) can generate regulator-ready RoI packages using the Plain-CSV Report Package option on the download page. The ZIP file includes metadata and report folders structured to regulator specifications, with file names containing LEI, entity ID, and release version. This enhancement ensures EU DORA compliance and supports automated validation workflows. You can follow the guide provided in the Instructions section on the Download/Upload request page for step-by-step instructions and required permissions.  
Note:  
You can use the Excel master template option to download a document to use for data preparation and internal review and the Plain-CSV reporting package option to download a document to use for regulator submission and compliance validation.

The RoI framework in TPRM is designed to align with DORA's five pillars, particularly ICT third-party risk management and incident reporting. RoI packages generated in TPRM follow the European Banking Authority's structure and
validation requirements.  
Note:  
RoI framework includes DPM business validation rules and additional configuration files such as report.json, reportPackage.json, and FrameworkCodeModuleVersion. These components enable third-party risk administrators (sn_vdr_risk_asmt.vendor_admin) to view and maintain validation logic and configuration settings for CSV reporting and automated validation workflows, ensuring consistency and compliance across regulatory submissions. TPR admins can access these properties by navigating to AllDigital Operational Resilience ManagementProperties and can access DPM business validation rules by navigating to AllDigital Operational Resilience ManagementDPM business validation rules.

## Digital Resilience Third-party Information Register support for RoI

The Digital Resilience Third-party Information Register provides the following capabilities to support RoI compliance:

* Data capture for entities, contracts, functions, and third parties
* CSV report generation aligned with regulator specifications
* ZIP packaging with metadata and report folders
* Validation workflows for technical, schema, and business rule checks
* Role-based access for managing RoI requests

Note:  
All RoI-related actions are performed in the Digital resilience third-party registers section of the Vendor Management Workspace. This workspace provides access to download/upload requests, validation tools,
and master templates.

For more information, see [Generate a register of information package](https://www.servicenow.com/docs/kVQVl_0~3RRyDVySIjZ73w "Use the CSV report option in the download page to generate regulator-ready Register of Information (RoI) packages.")

*[\>]: and then


