The register wants the chain,
not just the vendor.
Subcontracting depth is the part firms most often report as hardest to assemble. It is also, precisely, what a sub-processor list contains — so we produce it as a by-product of work you need doing anyway.
Chain beneath one arrangement
4 tiers deepEach tier dated, sourced and exportable in the shape a register of information expects.
The hard part is not the template.
The register format is published and stable. Filling in the subcontracting columns accurately is what consumes the quarter before submission.
Vendor-level is not enough
The arrangement is with your provider. The obligation reaches past them, to whoever they hand the work to.
Assembled by email, once a year
A picture built from questionnaires in January is already drifting by the time it is submitted.
The finding, not a footnote
Eleven of your providers sitting on the same cloud is exactly what the exercise is designed to surface.
The chain, dated, and kept current between cycles.
- Subcontracting depth mapped
For each provider, who they in turn rely on, with country and stated purpose, sourced from what each publishes.
- Register-shaped export
Structured for the register of information rather than a generic CSV you have to reshape by hand.
- Concentration surfaced
Which entities recur across your providers, and how many of your arrangements ultimately depend on one company.
- Maintained, not reconstructed
The picture updates daily, so the submission is a snapshot of something already true rather than a project.
- Dated evidence behind every line
When a supervisor asks how you know, the answer is a record with a date and a source, not a recollection.
This is one input to your register, not the whole of it.
Anyone selling you DORA compliance in a box is selling you something that does not exist.
- What we cover
The subcontracting chain beneath ICT providers who publish, plus anything you supply from contracts and procurement.
- What we do not
Contract values, criticality assessments, exit plans and the classification of critical or important functions. Those are yours, and they belong with the people who own the risk.
- How we fit
We feed the third-party inventory you already keep, rather than asking you to move it. If you run a TPRM platform, this is a source for it.