Imagine a Dutch financial firm on an ordinary Tuesday morning. Its client platform slows down, transactions begin to queue, and the software supplier cannot give a recovery time. IT knows the system. Finance knows the supplier on the invoices. Legal holds the contract. Compliance must decide whether the disruption requires a DORA report.
The AFM’s DORA update of 6 August 2026 gives this scene real weight. The share of information registers accepted by the European Banking Authority rose from 40% in 2025 to 94% in 2026. Firms have improved their submissions and their command of the required format.
The AFM also found incomplete policies and procedures. Incident reports remain below its expectations. The Dutch licence holder remains responsible when it relies on group-level policies. Together, those findings mark the end of DORA’s document phase. The harder test is whether a business can act from its records under pressure.
The register must match the business
DORA requires financial entities to maintain an information register covering contracts with third-party ICT service providers. Depending on the structure, firms maintain that record at entity, sub-consolidated or consolidated level. DNB’s 2026 quality checks cover group structures and provider data. Institutions must correct identified errors through resubmission.
That makes the register more than a regulatory spreadsheet. It should show management which supplier provides a service, which activity depends on it, and who owns the relationship. It should connect with contracts, the supplier ledger, payment records and the firm’s list of critical functions.
Small differences matter. Finance may pay a supplier’s Dutch subsidiary while the contract names its parent company. IT may use a product name while compliance records the provider’s legal name. A subcontractor may change without procurement hearing about it.
During a normal week, these gaps can sit quietly in separate systems. During an outage, they delay answers to basic questions. Who must call the supplier? Which clients are affected? What service has actually failed?
Group policies do not make local decisions
Shared group policies can save time and create consistency. They can also leave a comfortable distance between policy language and the Dutch entity’s daily work. The AFM places responsibility with the DORA-obliged licence holder. The entity must establish that group documents meet the requirements for its own organisation.
That takes more than changing a group name on the front page. The local entity needs to know which systems it uses, which suppliers support them, and who can classify an incident. It also needs an escalation route that works in Dutch business hours, with people who understand the licence, the clients and the reporting position.
DNB’s 2025 survey of insurers and pension funds shows why this matters. Almost 95% of respondents had updated their outsourcing policies. Only 34% said all ICT contracts supporting critical or important functions had been aligned with DORA.
Those figures concern specific sectors and reflect their position at the time of the survey. The business pattern is familiar. Policies often move faster than contracts and daily routines. A board should see that difference clearly instead of receiving a broad percentage-complete dashboard.
Incident reporting starts before the form
The AFM’s concern about incident reporting points to the working reality behind the report. Staff must detect an event, classify it, gather facts, and reach the person authorised to decide. They must do this while clients call, technicians investigate, and the supplier may still be working out what has happened.
DNB states that serious ICT-related incidents must be reported under DORA. Since mid-April 2026, it has validated reports against the technical requirements for the relevant reporting stage. Reporting is therefore not a final compliance action. It is a process that starts while the disruption is still developing.
Return to that Tuesday morning. If management first has to discover who owns the contract, which clients rely on the platform, and whether it supports a critical function, valuable time disappears. The problem is not an unfinished form. The firm has to reconstruct itself when it needs a reliable map.
For a small regulated firm, technology failure soon reaches commercial life. Transactions may stop. Client communication may slow. Reconciliations, administration and billing may be delayed. The firm may need external specialists at short notice. A vague contract or unclear exit arrangement can narrow management’s room to negotiate with its supplier.
A board view of unfinished work
The practical task is to place the DORA register beside the supplier ledger, current contracts and the list of important business services. Management can then see whether names, services, owners and dependencies agree. A walkthrough of one realistic disruption will quickly show where the process depends on memory rather than a settled decision route.
Boards and managing directors need a plain view of unfinished work. That includes contracts still being amended, local policy gaps, data corrections, untested escalation routes and risks management has consciously accepted. The useful question is not how much work has been completed. It is which unresolved dependency could stop client service or drain cash.
For insurance intermediaries, DORA scope can also become a question of records and group structure. AFM guidance uses thresholds involving staff, turnover and balance-sheet totals. Relevant financial entities within a group are aggregated for that assessment. A sound scope decision therefore depends on a reliable group map and consistent figures across payroll, accounts and company records.
Responsibility should be easy to locate
DORA now sits in the ordinary management of suppliers, contracts, systems and incidents. The 94% acceptance rate shows that the sector has learned much about submitting the register. The next measure of maturity sits inside the business, where people must recognise a disruption and know what follows.
When the platform fails on that Tuesday morning, nobody will be reassured by a polished policy folder alone. What matters is whether the firm can identify the service, reach the owner, understand the contract and make a timely decision.
Good compliance does not eliminate disruption. It prevents confusion from becoming the firm’s second incident.
Want to know whether your DORA records will work under pressure? We can help find the gaps
The data, sourcing, and analysis behind this article were conducted by Paolo Maria Pavan. AI was not used to identify sources, build the factual basis, or produce the analytical judgment contained here. AI was used only as a drafting aid. The final English text was personally reviewed, edited, and approved by Paolo Maria Pavan before publication.
References
- DORA-update 7
- Autoriteit Financiële Markten - Information register as a live outsourcing and concentration-risk record
- De Nederlandsche Bank - Data-quality checks and resubmission pressure
- De Nederlandsche Bank - Incident reporting is becoming a tested reporting capability
- De Nederlandsche Bank - Board accountability and unfinished contract remediation
- Autoriteit Financiële Markten - Scope for insurance intermediaries and group calculations
- De Nederlandsche Bank - Third-party ICT concentration and the supervisory purpose of DORA
