dora-register-builder

Installation
SKILL.md

DORA Register of Information build pack

A Register of Information is the relational, identifier-driven file the financial entity maintains under DORA Article 28(3) and reports annually under Article 28(7). Supervisors read it for sub-contractor-chain visibility, cross-border data-flow posture, and ICT-third-party concentration. The Critical ICT Third-Party Service Provider designation pipeline under Article 31 reads it. The firm's own concentration analysis and exit-readiness review read it. So the register is not a procurement export. It is the firm's structured supervisory artifact for ICT third-party risk.

This skill produces a preparation-grade artifact, not the submission. The structured record (schemas/dora-register-entry.schema.json) follows a local B-table convention that approximates the ITS shape closely enough to drive field population, relational-integrity checks, and data-quality findings; the official EBA Register of Information template under Commission Implementing Regulation (EU) 2024/2956 is what the firm's regulatory-reporting pipeline actually files, and the schema mapping from this skill's structure to the official template is the firm's responsibility (and a known gap pending a future schema rebuild). The markdown build pack (templates/default-output.md shape) is what the named approver reads before signing off on the firm's data-quality posture. The skill stops at the build pack and the data-quality findings; it does not file, and it is not a substitute for the official ITS template.

Ask first

Before drafting, settle six things. The build is identifier-driven and relational, so getting these wrong upstream costs more than asking once.

  • Which legal entities are in scope, and at what consolidation level. Individual, sub-consolidated, or consolidated. An EU subsidiary of a non-EU group typically files individually to its host-state NCA; the parent's consolidated register is a separate filing where the parent has its own DORA scope through other EU entities. Resolve at scope, not in the table records.
  • Reporting reference date and reporting reference period. The ITS sets the reference-date convention; pin it from the adopted Commission Implementing Regulation and the NCA's filing-cycle instructions for the cycle in flight.
  • National competent authority and submission channel. ECB SSM for direct-supervised significant institutions. Host-state NCA for less-significant institutions, payment and e-money institutions, insurers and reinsurers, investment firms, fund managers, trading venues, CSDs, and CCPs (with ESMA, EIOPA, EBA coordination as applicable). The technical channel and validation rules vary; pin per filing.
  • Build review type. First-cycle build, annual refresh, off-cycle update, quality-review-only, post-onboarding update, post-termination update. Each has a different evidence ask, a different reviewer-question cluster, and a different decision-forum context. A first-cycle build for a complex group runs long and carries heavy data-quality and reconciliation sections; a quality-review-only run skips the substantive table records and concentrates on findings and reconciliations.
  • Source-data posture. Which firm systems are inputs: TPRM register, contract repository, ICT-asset inventory, prior-year register, EBA outsourcing register (EBA/GL/2019/02 §11), criticality-assessment outputs, vendor-diligence packs. Each carries a quality caveat. Name them.
  • Criticality-assessment availability. The register's b_04_functions.criticality field is sourced from criticality-assessment and backed by a criticality_evidence_record_id. If criticality has not been formally set for in-scope arrangements, route there first and consume the output here. Setting the flag in this skill without backing evidence is a defect, not a shortcut.

When the scope record is supplied, the skill consumes it for institution type, sector overlay set, cross-cutting overlay set, persona, and source posture. When it is not supplied, ask the questions above and default to public posture if the practitioner declines. Do not silently apply a sector overlay default.

Installs
1
First Seen
Jun 16, 2026
dora-register-builder — anotb/second-line-financial-services