EU-regulated bank - DORA ICT Third
Party Register
Article 28 / RoI reporting
GF Bankas was filing its first DORA ICT third-party report. The regulation had been published shortly before, so the team was learning the rules at the same time as filling in the data.
Their existing process ran on an Excel-based tool that the team described as quite primitive. Information went in by hand, attribute by attribute, and the same data points often needed to be repeated across multiple places.
Several people were pulled into the project to dedicate their time to the Register, and the team described the overall submission experience as exhausting.
The team flagged a few areas where the tool could be extended further: deeper subcontractor management features, a clean Excel export of all fields for internal analysis work, and a couple of small refinements to in-record save behavior and filter persistence. Each was raised as a constructive next step, building on a foundation that already carried them through their first submission with confidence.
Worth noting: These sit on the active roadmap. Copla continues to evolve the supplier view and data export capabilities in direct response to customer feedback like this.
Knowing a contract ID, finding and updating a record is quick. Knowing the filing rules, adding a new contract to the Register is straightforward. The team is confident that keeping providers and contracts current across the year is well within reach for them.
Lift in third-party risk awareness as service owners took on Register entry
EU-regulated bank · Lithuania
See how Copla Registry handles the structure, validation, and export — so you don't have to.