DORA's Third-Party Register: What Financial Firms Still Get Wrong
A year into enforcement, the register of information remains the single biggest DORA compliance gap we see. Here's the checklist we use with clients.
Compliance teams tell us the same thing in almost every conversation: the problem was never a lack of awareness, it was a lack of a system that made the right thing the easy thing. This piece walks through what we've learned working directly with organisations tackling exactly this challenge.
What we're actually seeing
Across the engagements behind this article, the pattern holds firm — process gaps show up long before technology gaps do. The organisations that get ahead of the problem treat evidence-gathering as a continuous discipline, not an annual scramble before an audit.
"The gap isn't awareness. It's a system that makes the right thing the easy thing."
— Tom Whitfield, Head of Third-Party RiskThe practical next step
None of this requires a wholesale platform change to start improving. A short discovery conversation is usually enough to identify where the biggest, fastest win sits for your specific environment — and it's rarely where teams initially expect it to be.
With visibility first. You can't prioritise what you can't see, and most organisations are surprised by what a first scan actually surfaces.
Most clients see a measurable shift within the first month — not full maturity, but a clear, evidenced direction of travel your board can see.
Curious what this looks like in your environment? A short call is enough to map the gap and the fastest path to closing it.
Talk to Praeferre