Glossary
The terms you meet when you fill in the DORA Register of Information and file it with the AFM. Each definition names its official source. Template and field codes (such as B_05.01) are the EBA's own and link to our template reference.
LEI
The Legal Entity Identifier is a 20-character code that identifies a legal entity worldwide, based on the ISO 17442 standard. GLEIF (opens in a new tab) administers the system and publishes every LEI.
In the register, the LEI identifies the entity maintaining the register (B_01.01), every entity in scope (B_01.02) and, where they have one, ICT third-party service providers (B_05.01). The EBA checks several of these fields against the GLEIF database after you file. The LEI of the reporting entity also appears in the file name of the package.
EUID
The European Unique Identifier identifies a company in an EU business register. It combines a country code, a register identifier, the registration number and an optional check digit, as set out in Implementing Regulation (EU) 2021/1042 (opens in a new tab).
The register accepts an EUID for ICT third-party service providers without an LEI. The EBA checks EUIDs against BRIS, the EU system that interconnects business registers. The AFM says that only an LEI or EUID may be used for legal persons; any other identifier is flagged as a data-quality issue but does not cause a rejection (AFM Q&A, March 2026 (opens in a new tab)).
DPM
The Data Point Model is the EBA's data dictionary for supervisory reporting. For DORA it defines every template, column, key and allowed value, and the validation rules the EBA runs on your package.
When feedback seems to contradict the ITS, the AFM says the EBA FAQ comes first, then the DPM, then the ITS (AFM Q&A, March 2026 (opens in a new tab)).
xBRL-CSV
xBRL-CSV is the CSV-based form of XBRL, the standard for exchanging business reports. It is the only format in which the AFM accepts the register: a ZIP file, not Excel and not iXBRL (AFM (opens in a new tab)).
The package holds META-INF/reportPackage.json and a reports/ folder with report.json, parameters.csv, FilingIndicators.csv and one CSV file per template. The ZIP and the folder inside it carry the same name.
Filing indicator
A filing indicator declares that a template is reported. The indicators sit in FilingIndicators.csv, one row per template.
For DORA, every template must be declared as reported with the value true, including templates you leave empty. Template IDs are written in capitals, such as B_01.01 (EBA common issues, April 2025 (opens in a new tab)). A missing or extra indicator returns error 702 or 808.
Reference date
The reference date is the date the register reports on. It appears in the file name and as refPeriod in parameters.csv.
For the 2026 collection the AFM fixed the reference date at 2025-12-31 (AFM (opens in a new tab)). The EBA rejects a file name whose reference date is not a valid date or lies in the future.
Reporting entity
The reporting entity is the financial entity that submits the register. Its LEI opens the file name, followed by .IND for an individual report or .CON for a consolidated one (AFM (opens in a new tab)).
The same value must appear as entityID in parameters.csv; a mismatch returns error 714. The AFM itself checks only that this LEI matches its records and that the file name follows the convention.
ICT third-party service provider
DORA defines an ICT third-party service provider as "an undertaking providing ICT services" (DORA, Article 3(19) (opens in a new tab)). ICT services are "digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis" (Article 3(21)).
The register lists every such provider you have a contract with in B_05.01, not only those supporting critical or important functions. The AFM notes the definition is broad; digital advertising platforms are included (AFM Q&A, March 2026 (opens in a new tab)).
Critical or important function
A critical or important function is a function whose disruption would materially impair the financial performance of a financial entity, the soundness or continuity of its services, or its compliance with its authorisation and obligations (DORA, Article 3(22) (opens in a new tab)).
You record functions and their criticality assessment in B_06.01. B_07.01 assesses only the ICT services that support such a function.
CTPP
A CTPP is a critical ICT third-party service provider: a provider "designated as critical in accordance with Article 31" (DORA, Article 3(23) (opens in a new tab)). CTPPs fall under EU-level oversight by the European Supervisory Authorities.
The ESAs use the registers of information to designate CTPPs. They published the first list, of 19 providers, in November 2025 (AFM (opens in a new tab)).
ITS
The ITS is the Implementing Technical Standard that lays down the templates and instructions for the register: Commission Implementing Regulation (EU) 2024/2956 (opens in a new tab). Its annex defines the 15 templates, B_01.01 to B_99.01.
The EBA's FAQ and data model correct some errors in the published ITS text, such as the field numbering in B_06.01.
NOK, PEN and RES
These are the three statuses of an EBA feedback file, shown in the suffix of its name (EBA feedback explanation (opens in a new tab)).
| Status | Official label | Meaning |
|---|---|---|
| NOK | REJECTED | The package failed a reception or structure check. The feedback names the check, for example "Failed reception check 103". |
| PEN | PENDING_FURTHER_VALIDATIONS | Reception is complete; the data checks are still to run. There is no findings file yet. |
| RES | VALIDATION_RESULTS | The data and LEI/EUID checks have run. Findings are listed row by row in detailed-feedback.csv. |
The AFM passes the EBA feedback to you as a .txt file in the AFM Portal, normally within one business day (AFM (opens in a new tab)).
Sources
- EUR-Lex: Regulation (EU) 2022/2554 (DORA) (opens in a new tab)
- EUR-Lex: Commission Implementing Regulation (EU) 2024/2956 (ITS on the register of information) (opens in a new tab)
- EUR-Lex: Commission Implementing Regulation (EU) 2021/1042 (EUID structure) (opens in a new tab)
- GLEIF: Introducing the Legal Entity Identifier (opens in a new tab)
- EBA: Preparations for reporting of DORA registers of information (opens in a new tab)
- EBA: RoI validation feedback explanation (10 February 2025) (opens in a new tab)
- EBA: Observations from RoI reporting testing, common issues (April 2025) (opens in a new tab)
- AFM: Register of Information (opens in a new tab)
- AFM: Q&A after the Q&A session, March 2026 (PDF) (opens in a new tab)