ESMA_QA_2435
Topic
Register of information
10/02/2025
Subject Matter
Register of Information at consolidated level
Question
A Group contains within it both insurance entities and banking entities; for the purposes of preparing the Register at a consolidated level, must it consider both types of Entity? To which Authority is the Register sent at a consolidated level?
Level 1 Regulation
Regulation (EU) 2022/2554 - The Digital Operational Resilience Act (DORA)
ESMA_QA_2431
Topic
Register of information
04/02/2025
Subject Matter
Non-EU ICT service providers without a LEI - conflicting validation rules
Question
When an ICT service provider reported under schedule 05.01 is a legal person outside of the EU, the absence of a EUID and LEI will result in a report validation error rendering the submission of the ROI impossible. Should such service provider be left out of the register or should a dummy EUID be used (preferably issued by ESA to adequately consolidate missing positions)
Level 1 Regulation
Regulation (EU) 2022/2554 - The Digital Operational Resilience Act (DORA)
ESMA_QA_2428
Topic
Register of information
03/02/2025
Subject Matter
Register of Information at sub-consolidated Level
Question
For the purpose of preparing the Register of ICT Supplier Information (RoI) on a sub-consolidated basis, is it necessary to include within the different templates (ref. “B_XX.XX.XXX”) the information pertaining to both the Contractual Agreements that the Entity signs and those that it uses?
Specifically then, the “financial entity maintaining the register of information” is to be considered corresponding to the "entity signing the contractual arrangement" and the "financial entity making use of the ICT service(s)"?
Level 1 Regulation
Regulation (EU) 2022/2554 - The Digital Operational Resilience Act (DORA)
ESMA_QA_2399
Topic
Digital operational resilience testing
14/01/2025
Subject Matter
Finalised Comprehensive List of DORA questions
Question
Is there a finalised comprehensive list of all questions that the firms involved in the financial markets should answer? For each question is it clear to which type of firm it applies?
Level 1 Regulation
Regulation (EU) 2022/2554 - The Digital Operational Resilience Act (DORA)
ESMA_QA_2396
Topic
ICT risk management
10/01/2025
Subject Matter
Definition on ICT services
Question
Article 3 (21) of DORA defines that 'ICT services’ means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis.

It is not clear whether "digital and data services" should be interpreted as:
Version one: either digital or data services (so two different of sets of activities or
Version two: services which need to be both: digital service and parallel/in the same time data service.
Level 1 Regulation
Regulation (EU) 2022/2554 - The Digital Operational Resilience Act (DORA)