Skip to Content
Pavan Geraedts
  • Practice
    • Working With Pavan Geraedts
    • Our Principles
    • About
    • FAQ
  • Services
    • Fiscal Advice
    • Juridical Advice
    • Digital, Data & IP
    • Company Structure & Governance
    • Transactions & Business Change
    • Business Mediation
  • Library
  • Academy
  • Contact
  • 0
  • 0
  • Nederlands English (US) Italiano
  • CLIENT AREA
Pavan Geraedts
  • 0
  • 0
    • Practice
      • Working With Pavan Geraedts
      • Our Principles
      • About
      • FAQ
    • Services
      • Fiscal Advice
      • Juridical Advice
      • Digital, Data & IP
      • Company Structure & Governance
      • Transactions & Business Change
      • Business Mediation
    • Library
    • Academy
    • Contact
  • Nederlands English (US) Italiano
  • CLIENT AREA
  • All Blogs
  • Compliance
  • DORA Registers Improved, but Local Responsibility Still Sits With Management
  • DORA Registers Improved, but Local Responsibility Still Sits With Management

    A polished register means little if contracts, owners and incident decisions cannot be found when systems fail.
    August 7, 2026 by
    Paolo Maria Pavan

    Imagine a Dutch financial firm on an ordinary Tuesday morning. Its client platform slows down, transactions begin to queue, and the software supplier cannot give a recovery time. IT knows the system. Finance knows the supplier on the invoices. Legal holds the contract. Compliance must decide whether the disruption requires a DORA report.

    The AFM’s DORA update of 6 August 2026 gives this scene real weight. The share of information registers accepted by the European Banking Authority rose from 40% in 2025 to 94% in 2026. Firms have improved their submissions and their command of the required format.

    The AFM also found incomplete policies and procedures. Incident reports remain below its expectations. The Dutch licence holder remains responsible when it relies on group-level policies. Together, those findings mark the end of DORA’s document phase. The harder test is whether a business can act from its records under pressure.

    The register must match the business

    DORA requires financial entities to maintain an information register covering contracts with third-party ICT service providers. Depending on the structure, firms maintain that record at entity, sub-consolidated or consolidated level. DNB’s 2026 quality checks cover group structures and provider data. Institutions must correct identified errors through resubmission.

    That makes the register more than a regulatory spreadsheet. It should show management which supplier provides a service, which activity depends on it, and who owns the relationship. It should connect with contracts, the supplier ledger, payment records and the firm’s list of critical functions.

    Small differences matter. Finance may pay a supplier’s Dutch subsidiary while the contract names its parent company. IT may use a product name while compliance records the provider’s legal name. A subcontractor may change without procurement hearing about it.

    During a normal week, these gaps can sit quietly in separate systems. During an outage, they delay answers to basic questions. Who must call the supplier? Which clients are affected? What service has actually failed?

    Group policies do not make local decisions

    Shared group policies can save time and create consistency. They can also leave a comfortable distance between policy language and the Dutch entity’s daily work. The AFM places responsibility with the DORA-obliged licence holder. The entity must establish that group documents meet the requirements for its own organisation.

    That takes more than changing a group name on the front page. The local entity needs to know which systems it uses, which suppliers support them, and who can classify an incident. It also needs an escalation route that works in Dutch business hours, with people who understand the licence, the clients and the reporting position.

    DNB’s 2025 survey of insurers and pension funds shows why this matters. Almost 95% of respondents had updated their outsourcing policies. Only 34% said all ICT contracts supporting critical or important functions had been aligned with DORA.

    Those figures concern specific sectors and reflect their position at the time of the survey. The business pattern is familiar. Policies often move faster than contracts and daily routines. A board should see that difference clearly instead of receiving a broad percentage-complete dashboard.

    Incident reporting starts before the form

    The AFM’s concern about incident reporting points to the working reality behind the report. Staff must detect an event, classify it, gather facts, and reach the person authorised to decide. They must do this while clients call, technicians investigate, and the supplier may still be working out what has happened.

    DNB states that serious ICT-related incidents must be reported under DORA. Since mid-April 2026, it has validated reports against the technical requirements for the relevant reporting stage. Reporting is therefore not a final compliance action. It is a process that starts while the disruption is still developing.

    Return to that Tuesday morning. If management first has to discover who owns the contract, which clients rely on the platform, and whether it supports a critical function, valuable time disappears. The problem is not an unfinished form. The firm has to reconstruct itself when it needs a reliable map.

    For a small regulated firm, technology failure soon reaches commercial life. Transactions may stop. Client communication may slow. Reconciliations, administration and billing may be delayed. The firm may need external specialists at short notice. A vague contract or unclear exit arrangement can narrow management’s room to negotiate with its supplier.

    A board view of unfinished work

    The practical task is to place the DORA register beside the supplier ledger, current contracts and the list of important business services. Management can then see whether names, services, owners and dependencies agree. A walkthrough of one realistic disruption will quickly show where the process depends on memory rather than a settled decision route.

    Boards and managing directors need a plain view of unfinished work. That includes contracts still being amended, local policy gaps, data corrections, untested escalation routes and risks management has consciously accepted. The useful question is not how much work has been completed. It is which unresolved dependency could stop client service or drain cash.

    For insurance intermediaries, DORA scope can also become a question of records and group structure. AFM guidance uses thresholds involving staff, turnover and balance-sheet totals. Relevant financial entities within a group are aggregated for that assessment. A sound scope decision therefore depends on a reliable group map and consistent figures across payroll, accounts and company records.

    Responsibility should be easy to locate

    DORA now sits in the ordinary management of suppliers, contracts, systems and incidents. The 94% acceptance rate shows that the sector has learned much about submitting the register. The next measure of maturity sits inside the business, where people must recognise a disruption and know what follows.

    When the platform fails on that Tuesday morning, nobody will be reassured by a polished policy folder alone. What matters is whether the firm can identify the service, reach the owner, understand the contract and make a timely decision.

    Good compliance does not eliminate disruption. It prevents confusion from becoming the firm’s second incident.

    Want to know whether your DORA records will work under pressure? We can help find the gaps

    CONTACT US

    The data, sourcing, and analysis behind this article were conducted by Paolo Maria Pavan. AI was not used to identify sources, build the factual basis, or produce the analytical judgment contained here. AI was used only as a drafting aid. The final English text was personally reviewed, edited, and approved by Paolo Maria Pavan before publication.

    References

    • DORA-update 7
    • Autoriteit Financiële Markten - Information register as a live outsourcing and concentration-risk record
    • De Nederlandsche Bank - Data-quality checks and resubmission pressure
    • De Nederlandsche Bank - Incident reporting is becoming a tested reporting capability
    • De Nederlandsche Bank - Board accountability and unfinished contract remediation
    • Autoriteit Financiële Markten - Scope for insurance intermediaries and group calculations
    • De Nederlandsche Bank - Third-party ICT concentration and the supervisory purpose of DORA
    in Compliance
    # AFM COMPLIANCE DORA DORA management responsibility Financial firms GOVERNANCE ICT risk Paolo Maria Pavan financial supervision incident reporting outsourcing
    Paolo Maria Pavan August 7, 2026
    Share this post

    Share

    Tags
    AFM COMPLIANCE DORA DORA management responsibility Financial firms GOVERNANCE ICT risk Paolo Maria Pavan financial supervision incident reporting outsourcing
    Our blogs
    • Market Pulse
    • Ledger & Tax
    • Human Resources
    • Compliance
    • Governance
    • Real Estate

    Read Next
    The 403-Rule Drive Must Reach the Small Firm’s Working Week
    Real relief means fewer repeated tasks without losing the records that protect staff, tax and cash.

    Upcoming Events

    Explore what’s happening next and join the moments that matter.

    See All
    Your Dynamic Snippet will be displayed here... This message is displayed because you did not provide enough options to retrieve its content.

    Pavan Geraedts Adviseurs

    Altroverso VOF trading as Pavan Geraedts Adviseurs. A boutique professional practice in Amersfoort for fiscal advice, juridical advice and business mediation.

    Chamber of Commerce: 56530021
    VAT: NL852171936B01
    BECON: 746393

    Complaints
    Email pg@altroverso.nl
    We acknowledge complaints as soon as possible and make reasonable efforts to find a satisfactory solution. Telephone and postal details are listed opposite.

    2012-2026 © Altroverso VOF
    All rights reserved.

    Practice

    About Pavan Geraedts
    Working With Pavan Geraedts
    Our Professional Principles
    Frequently Asked Questions
    Contact

    Areas of practice

    Fiscal Advice and Tax Matters
    Juridical Advice and Contracts
    Business Mediation
    Company Structure and Governance
    Digital, Data & IP
    Transactions & Business Change

    Knowledge and contact
    • Library
      Academy
      Client Area
    • Professional updates and invitations are shared with clients and contacts when they are relevant to the work of the practice.
    Pavan Geraedts
    • +31 (0)85 40 12 459

    • Rigaweg 9
    • 3825 PP Amersfoort
      The Netherlands
    Legal
    • Terms and Conditions
    • Privacy Manifesto
    • Cookie Policy
    • Salary and Employment Policy

    Your privacy matters.

    May this website use cookies in this browser?

    Essential cookies support the operation of the website. With your permission, additional cookies may be used to improve your experience. Further information is available in our Cookie Policy and change your choice later.

    Allow all cookiesAllow essential cookies only