Skip to main content

What we check

We check your workbook in the areas below, then build the xBRL-CSV package and check it again. Every check comes from an official source: the EBA's reporting package, the EBA FAQ or the AFM's naming rules. The sources page lists them.

How findings work

Each finding names the template, the field and the row, cites its official source and says what to change in Excel. It has one of three levels.

Level Meaning Blocks the package?
Error The data breaks the EBA data model, a technical check or an FAQ clarification. Yes
Warning An EBA business rule or a likely data problem. Review it before you submit. No
Info A reminder or a coverage note. No

The EBA publishes its DORA business rules with the severity "warning", so we report them as warnings too. You can build the package with open warnings, but the EBA may list them in its feedback.

Templates and structure

We read all 15 templates, B_01.01 to B_99.01, in one run. Each sheet is matched to its template by name and each column to its official field code.

A missing sheet, an unknown column or a sheet in the wrong layout is reported before any deeper check. Empty templates are allowed: the EBA expects every template to be declared, with or without data.

Fields and value lists

Every cell is checked against the EBA data model for its field.

  • Required fields: a field the data model marks as not null must be filled.
  • Data types: dates as yyyy-mm-dd, whole numbers, amounts and true/false values.
  • Lengths: fixed-length codes such as a 20-character LEI, and maximum text lengths.
  • Value lists: drop-down fields must hold a value from the EBA's list of possible values. Our template shows each option as a label with its code, and the package carries the code.
  • Hygiene: control characters are errors; placeholder text such as "n/a" or "tbd" and stray spaces are warnings.
  • Identifiers: LEI format and check digits (ISO 17442), VAT number format, EUID structure, and whether a VAT or EUID prefix matches the country reported.

Most templates point to others: a contract in B_02.02 must exist in B_02.01, a provider in B_05.01, a function in B_06.01. Broken links are the most common reason the EBA rejects a register (error 807, per the AFM (opens in a new tab)).

  • Primary keys: no two rows in a template may share the same key. Key fields may not be empty.
  • Foreign keys: every reference must exist in the template it points to. A link the data model states explicitly is an error. A link we infer from the field labels, because the data model does not name the target, is a warning. The AFM still rejects a broken reference as error 807, so fix it before you file.
  • Composite links: combined references, such as a contract and provider pair, must exist together in the target template when that template holds data.
  • Function and entity: a function identifier used in B_02.02 must belong to the same entity LEI in B_06.01.
  • Reporting entity: the LEI in B_01.01 must also appear in B_01.02.

EBA rules and FAQ clarifications

We apply all 58 active DORA business rules from the EBA's validation-rule workbook, such as v8826_m or e23674_e. Rules the EBA has deactivated are not applied.

On top of those, 11 checks enforce answers from the EBA FAQ that tighten the published rules. These are errors, because the EBA rejects what they catch:

  • B_01.02: the direct parent LEI is filled in; without a parent, the entity's own LEI (FAQ Q58).
  • B_02.01: the overarching arrangement reference is filled in, or "Not Applicable" where none exists (FAQ Q124).
  • B_02.02: the country of provision and the storage location use the closed-set "Not applicable" code where the FAQ requires it (FAQ Q59, Q61).
  • B_04.01: the branch code is "Not Applicable" when the user is not a branch, and a real branch code when it is (FAQ Q64).
  • B_05.02: at rank 1, the recipient repeats the provider's own identifier (FAQ Q65).

Three are warnings:

  • B_05.01: a provider that is a legal person with its headquarters in the EU should be identified by an LEI or EUID (FAQ Q47).
  • B_05.01: a legal person with its headquarters outside the EU should be identified by an LEI (FAQ Q47). For both, the AFM accepts another code but records it as a data-quality issue.
  • B_02.02: a service for a critical or important function should report its country of provision, not "Not applicable" (FAQ Q59).

A further 2 reminders ask you to confirm what no workbook can prove: that B_05.01 lists every ICT provider, not only critical ones (FAQ Q69), and that relevant non-financial group entities are in B_01.02 (FAQ Q125).

Package and archive

After building the package, we check it the way the EBA's reception and CSV checks do. A package with an error is deleted and not offered for download.

  • Files: all 19 files present and not empty: reportPackage.json, report.json, parameters.csv, FilingIndicators.csv and one CSV per template. No other files.
  • Name and folder: the AFM file name convention, a valid reference date that is not in the future, and one folder inside the ZIP with the same name as the ZIP.
  • Archive: 8 checks on the ZIP itself, such as unsafe paths, duplicate or encrypted entries and size.
  • Report metadata: 6 checks that report.json points to the DORA module of the EBA taxonomy.
  • Parameters: 10 checks on parameters.csv, including that entityID and refPeriod match the file name (error 714).
  • Filing indicators: 7 checks that every template is declared once, in capitals, as true (errors 702 and 808).
  • Template CSVs: 9 checks on headers, row shape and empty key values.
  • Encoding: UTF-8.
  • Echo check: the entity, reference date and row counts in the package match your workbook.

Together these cover 28 of the EBA's published technical checks.

Live LEI and VAT checks

With online checks on, we look up identifiers in public registries during validation. They catch problems the EBA finds only after you file.

  • GLEIF: each LEI in B_01.01, B_01.02 and, where the identifier type is LEI, B_05.01 must exist and have a valid status. A lapsed LEI is a warning; an annulled, retired or unknown LEI is an error. The entity countries in B_01.02 are compared with GLEIF. These mirror the EBA's own checks VR_2, VR_12, VR_16, VR_23, VR_71 and VR_77.
  • VIES: VAT numbers used as identifiers must exist.

If a registry is unavailable, you get a warning, not an error. The findings show what the registry returned, including the legal name, as evidence.

What we don't check

  • EUID against BRIS. The EBA checks EUIDs against BRIS (VR_72, VR_78). BRIS has no public lookup, so we check the EUID's structure only.
  • Codes outside the published catalogue. EBA feedback can cite rule codes the EBA has not published. We can't check what isn't published.
  • Your content decisions. Whether a contract, provider or function belongs in the register is yours to decide. We check that what you enter is consistent and complete.

We can't guarantee that the EBA accepts a package; the EBA's checks are the final word. If the AFM rejects a package built here, you get one free rebuild.

Sources

  1. EBA: Preparations for reporting of DORA registers of information (opens in a new tab)
  2. EBA: DORA RoI reporting FAQ (28 March 2025) (opens in a new tab)
  3. EBA: Filing Rules v5.5 (opens in a new tab)
  4. EBA: Reporting framework 4.0 (opens in a new tab)
  5. AFM: Register of Information (opens in a new tab)
  6. AFM: Q&A after the Q&A session, March 2026 (PDF) (opens in a new tab)
  7. GLEIF: GLEIF API (opens in a new tab)