Twice a year, a familiar ritual. Someone in GRC opens last year’s spreadsheet. Procurement sends a list that does not match. Security has another list, in another tool. Legal has contracts that name entities the spreadsheet has never heard of. Engineering has services that call vendors nobody onboarded. Then the clock for the DORA Register of Information starts, and the organisation treats the gap as a project.
That project will always run late. Not because the team is slow. Because a register assembled for a date is already wrong on that date.
Homework is not a control
A Register of Information is a picture of the ICT estate: every third-party arrangement, the functions it supports, the data it can reach, the subcontractors behind it, the locations, the owners. DORA is explicit. The register must be complete and current.
Current is the word that breaks the process.
Vendors are not a quarterly event. A new SaaS tool is a credit card and a callback URL. A subcontractor is a clause in a DPA that nobody re-read. An agent starts calling an API that was meant for humans. A data flow moves from the EU to a US region because a default changed. None of that waits for the RoI working group.
If the register is homework (a freeze, a campaign, a shared drive) it describes last quarter’s estate with this quarter’s logo on the cover. Supervisors will notice. So will the incident that hits a vendor you did not know you had.
The same failure shows up in TPRM inventories, records of processing, and AI registers. Different templates. Same shape: a static table that pretends the estate holds still.
Reporting day should be an export
The alternative is not a better spreadsheet. It is to stop treating the register as the system of record.
The system of record is the estate itself: vendors, systems, agents, and the data that moves between them. Discovery from code, contracts, browsers, workstations, and public sources, kept in one graph, with owners on the nodes and evidence on the edges. When a vendor appears, the graph gains a node. When a contract names a subprocessor, the chain updates. When a service starts sending personal data to a new region, the flow is visible before anyone is asked to confirm the list.
Then the Register of Information is a view. DORA’s fields are a query over current reality, not a reconstruction. Reporting day is an export with a trail: what changed, who owns it, which evidence supports the row.
That is ICT governance at the speed the estate changes. TPRM reviews, DORA submissions, and agent inventories stop competing for the same stale list. Security, legal, and GRC work from one picture and produce the artefact each regime asks for.
A register you rebuild by hand will always go stale. A graph you keep alive will not. The difference is not formatting. It is whether governance is a project, or a property of the estate.
