Post by Complissimo
228 followers
๐ ๐๐ข๐ฅ๐ ๐ฅ๐ผ๐: ๐๐ต๐ฒ ๐ฟ๐ฒ๐ด๐ถ๐๐๐ฒ๐ฟ ๐ถ๐ ๐๐ฒ๐๐๐ฒ๐ฑ ๐ฑ๐๐ฟ๐ถ๐ป๐ด ๐ถ๐ป๐ฐ๐ถ๐ฑ๐ฒ๐ป๐๐ โ ๐ป๐ผ๐ ๐ฟ๐ฒ๐ฝ๐ผ๐ฟ๐๐ถ๐ป๐ด ๐๐ฒ๐ฎ๐๐ผ๐ป The Belgian regulator recently made something clear about the DORA Register of Information (RoI): yes, itโs submitted once per year โ but it must reflect reality at all times. Thatโs easier said than done. The RoI reporting template is extremely intricate because itโs designed for supervisory automation: detecting concentration risk and identifying ICT providers for possible direct oversight. But regulators also insist the RoI should primarily be an internal third-party risk management tool. Thatโs the contradiction: ๐ a format built for supervision,ย ๐ incentivising annual โtick-the-boxโ exports, ๐ while the real expectation is continuous accuracy. And hereโs why this matters: regulators have explicitly warned that ๐ถ๐ป๐ฐ๐ผ๐บ๐ฝ๐น๐ฒ๐๐ฒ๐ป๐ฒ๐๐ ๐ถ๐ ๐ป๐ผ๐ป-๐ฐ๐ผ๐บ๐ฝ๐น๐ถ๐ฎ๐ป๐ฐ๐ฒ โ ๐ฎ๐ป๐ฑ ๐ถ๐ ๐๐ถ๐น๐น ๐ฒ๐๐ฒ๐ป๐๐๐ฎ๐น๐น๐ ๐๐๐ฟ๐ณ๐ฎ๐ฐ๐ฒ. For example, if a major incident involves a provider missing from your RoI thatโs not a minor documentation issue โ itโs a direct compliance gap (and can trigger findings, remediation and potentially sanctions). The RoI shouldnโt be a yearly spreadsheet ritual. It should be a living dataset that supports daily risk decisions โ and is always submission-ready. โก๏ธ We unpack this contradiction โ and what a โcontinuous RoIโ approach looks like โ in a short article on our website (link in comments below). ๐ How are you keeping your RoI accurate throughout the year? #DORA #ThirdPartyRisk #ICTRisk #OperationalResilience #RegTech #Complissimo