Skip to main content

B_05.01 ICT third-party service providers

What this template is for

B_05.01 is the master list of ICT third-party service providers: direct providers, intra-group providers, subcontractors from B_05.02 and their ultimate parents. B_02.02, B_03.02, B_05.02 and B_07.01 refer to it.

Filling it in

  • All providers: list every ICT third-party service provider, not only those supporting critical or important functions (EBA FAQ Q69).
  • Identifier type (0020): use a code from the list: LEI, EUID, CRN, VAT, PNR or NIN, without a country prefix. For legal persons in the Union, only an LEI or EUID may be used; for legal persons outside the Union, only an LEI (EBA FAQ Q47).
  • Ultimate parent (0110): if the provider has no parent undertaking, repeat the provider's own identifier (EBA FAQ Q99).
  • Fill this sheet early: other sheets reuse its identifiers.

AFM clarifications

How DORA Convert handles it

Our Excel template has a sheet named after this template. Each column header carries a note with what to enter, an example and the official source. Drop-down cells show each option as a label with its EBA code; the package carries the code. Errors block the package; warnings do not. See what we check.

  • LEI: where the identifier type is LEI, the identifier is checked for format and check digits and, with online checks on, looked up in GLEIF, as the EBA does with VR_71.
  • VAT: where the type is VAT, the number is checked for format and, with online checks on, in VIES.
  • EUID: checked for structure only; the EBA checks EUIDs against BRIS (VR_72), which we can't query.
  • Prefixes: an EUID or VAT prefix that does not match the provider's country is a warning.
  • Placeholders: values such as "n/a" or "tbd" are flagged as warnings.
  • Ultimate parent: required; a blank cell is an error.
  • LEI or EUID for EU legal persons: a provider that is a legal person with its headquarters in the EU, identified by a CRN, VAT or other code, gets a warning (EBA FAQ Q47). The AFM treats that as a data-quality issue, not a rejection. If the provider has no LEI or EUID, keep the code you have.
  • LEI for non-EU legal persons: a legal person with its headquarters outside the EU, identified by anything other than an LEI, also gets a warning (EBA FAQ Q47). We read the headquarters country (0080) to decide whether a provider is in the Union.
  • Reminder: unless your workbook shows it, you are asked to confirm that every provider is listed, not only critical ones (FAQ Q69).
  • EBA rules: the EBA's active business rules for this template run as warnings; inactive ones are not applied.

Official fields

Official summary: Lists the direct providers, intra-group providers, subcontractors in B_05.02, and their ultimate parent undertakings. (ITS Annex I Part 1)

ColumnOfficial labelData typeKey or referenceRequiredAllowed values
c0010Identification code of ICT third-party service providervarchar(255)PKNot nullIdentifier value as instructed by ITS/DM
c0020Type of code to identify the ICT third-party service providervarchar(255)Not nullClosed set; PV B0501/LISTIDTYPE
c0030Additional identification code of ICT third-party service providerintNullableInteger; TC rule 331 applies
c0040Type of additional identification code of the ICT third-party service providervarchar(255)NullableClosed set; PV B0501/LISTIDTYPE
c0050Legal name of the ICT third-party service providervarchar(255)Not nullFree text / narrative value per ITS and DM
c0060Name of the ICT third-party service provider in Latin alphabetvarchar(255)NullableFree text / narrative value per ITS and DM
c0070Type of person of the ICT third-party service providervarchar(255)Not nullClosed set; PV B0501/LISTB05010070
c0080Country of the ICT third-party service provider’s headquarterschar(2)Not nullClosed set; PV B0501/LISTCOUNTRY
c0090Currency of the amount reported in RT.05.01.0070char(3)NullableClosed set; PV B0501/LISTCURRENCY
c0100Total annual expense or estimated cost of the ICT third-party service providermoneyNullableMonetary amount; DM and FR numeric-reporting rules apply
c0110Identification code of the ICT third-party service provider’s ultimate parent undertakingvarchar(255)FKNot nullIdentifier value as instructed by ITS/DM
c0120Type of code to identify the ICT third-party service provider’s ultimate parent undertakingvarchar(255)NullableClosed set; PV B0501/LISTIDTYPE

From the EBA data model and validation rules, as recorded on 10 March 2026. Official labels are in English.

Official clarifications

  • Published typos that do not change reporting: The official FAQ states that certain B_07.01 and B_05.01 wording problems in the published ITS are typos that do not change code-based reporting and will be corrected in an updated ITS. (FAQ Q48)
  • Provider coverage in B_05.01: All ICT third-party service providers must be identified in B_05.01, not only those supporting critical or important functions. (FAQ Q69)
  • c0020 Type of code to identify the ICT third-party service provider: FAQ Q47: use only the closed-set code types without the country-prefix pattern shown in the published ITS text; only LEI or EUID may be used for legal persons in the Union.
  • c0110 Identification code of the ICT third-party service provider’s ultimate parent undertaking: FAQ Q99: if the ICT third-party service provider has no parent undertaking, repeat the provider identifier here.

EBA validation rules

Official note: Includes the broadest mix of active and inactive provider-related rules. (VR table B_05.01)

Active rules

  • e23674_e

    Official expression: with {tB_05.01, default:null, interval:false}: not ( isnull ({(c0020, c0050, c0060, c0070, c0080, c0110)}) )

    Our explanation: Columns c0020, c0050, c0060, c0070, c0080 and c0110 must be filled in every row. This includes "Name of the ICT third-party service provider in Latin alphabet" (c0060), which the field list marks as nullable; fill it in even when it equals the legal name.
  • v8850_m

    Official expression: with {tB_05.01, default: null, interval: false}: if ( not ( isnull ({c0030}) ) ) or not (( isnull ({c0040}) )) or not (( isnull ({c0050}) )) or not (( isnull ({c0060}) )) or not (( isnull ({c0070}) )) or not (( isnull ({c0080}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) then ( ( not ( isnull ({c0020}) ) )) endif

    Our explanation: When any other column from c0020 to c0120 is filled, "Type of code to identify the ICT third-party service provider" (c0020) must be filled too. Choose the code type in c0020.
  • v8851_m

    Official expression: with {tB_05.01, default: null, interval: false}: if ( not ( isnull ({c0030}) ) ) or not (( isnull ({c0040}) )) or not (( isnull ({c0020}) )) or not (( isnull ({c0060}) )) or not (( isnull ({c0070}) )) or not (( isnull ({c0080}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) then ( ( not ( isnull ({c0050}) ) )) endif

    Our explanation: When any other column from c0020 to c0120 is filled, "Legal name of the ICT third-party service provider" (c0050) must be filled too. Enter the legal name in c0050.
  • v8852_m

    Official expression: with {tB_05.01, default: null, interval: false}: if ( not ( isnull ({c0030}) ) ) or not (( isnull ({c0040}) )) or not (( isnull ({c0050}) )) or not (( isnull ({c0020}) )) or not (( isnull ({c0070}) )) or not (( isnull ({c0080}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) then ( ( not ( isnull ({c0060}) ) )) endif

    Our explanation: When any other column from c0020 to c0120 is filled, "Name of the ICT third-party service provider in Latin alphabet" (c0060) must be filled too. Enter the name in Latin characters in c0060, even when it equals the legal name.
  • v8853_m

    Official expression: with {tB_05.01, default: null, interval: false}: if ( not ( isnull ({c0030}) ) ) or not (( isnull ({c0040}) )) or not (( isnull ({c0050}) )) or not (( isnull ({c0060}) )) or not (( isnull ({c0020}) )) or not (( isnull ({c0080}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) then ( ( not ( isnull ({c0070}) ) )) endif

    Our explanation: When any other column from c0020 to c0120 is filled, "Type of person of the ICT third-party service provider" (c0070) must be filled too. Choose the type of person in c0070.
  • v8854_m

    Official expression: with {tB_05.01, default: null, interval: false}: if ( not ( isnull ({c0030}) ) ) or not (( isnull ({c0040}) )) or not (( isnull ({c0050}) )) or not (( isnull ({c0060}) )) or not (( isnull ({c0070}) )) or not (( isnull ({c0020}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) then ( ( not ( isnull ({c0080}) ) )) endif

    Our explanation: When any other column from c0020 to c0120 is filled, "Country of the ICT third-party service provider’s headquarters" (c0080) must be filled too. Choose the headquarters country in c0080.
  • v8855_m

    Official expression: with {tB_05.01, default: null, interval: false}: if ( not ( isnull ({c0030}) ) ) or not (( isnull ({c0040}) )) or not (( isnull ({c0050}) )) or not (( isnull ({c0060}) )) or not (( isnull ({c0070}) )) or not (( isnull ({c0080}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0020}) )) or not (( isnull ({c0120}) )) then ( ( not ( isnull ({c0110}) ) )) endif

    Our explanation: When any other column from c0020 to c0120 is filled, "Identification code of the ICT third-party service provider’s ultimate parent undertaking" (c0110) must be filled too. Enter the ultimate parent's code in c0110.

Inactive rules

  • v8817_m

    Official expression: with{tB_05.01, default:0, interval: false}: if ({c0070} = [eba_CT:x212]) then ({c0020} in {[eba_qCO:qx2000], [eba_qCO:qx2002]}) endif

    Our explanation: The EBA has marked this rule inactive. As written, when "Type of person of the ICT third-party service provider" (c0070) is "Legal person, excluding individual acting in a business capacity", "Type of code to identify the ICT third-party service provider" (c0020) must be LEI or EUID.
  • v8818_m

    Official expression: with{tB_05.01, default:0, interval: false}: if ({c0070} = [eba_CT:x212]) then ({c0040} in {[eba_qCO:qx2000], [eba_qCO:qx2002]}) endif

    Our explanation: The EBA has marked this rule inactive. As written, when "Type of person of the ICT third-party service provider" (c0070) is "Legal person, excluding individual acting in a business capacity", "Type of additional identification code of the ICT third-party service provider" (c0040) must be LEI or EUID.
  • v8821_m

    Official expression: with{tB_05.01, default:0, interval: false}: if({c0020} = [eba_qCO:qx2000]) then ( (match({c0030}, "^[A-Z0-9]{18}[0-9]{2}$"))) endif

    Our explanation: The EBA has marked this rule inactive. As written, when "Type of code to identify the ICT third-party service provider" (c0020) is LEI, "Additional identification code of ICT third-party service provider" (c0030) must have the LEI format: 20 characters, 18 capital letters or digits, then two digits.
  • v8823_m

    Official expression: with {tB_05.01, default: 0, interval: false}: if({c0030} != "null") then ({c0040} != "null") endif

    Our explanation: The EBA has marked this rule inactive. As written, when "Additional identification code of ICT third-party service provider" (c0030) is not the text "null", "Type of additional identification code of the ICT third-party service provider" (c0040) must not be "null" either; it compares with that text, not with an empty cell.
  • v8824_m

    Official expression: with {tB_05.01, default: 0, interval: false}: if({c0100} != "null") then ({c0090} != "null") endif

    Our explanation: The EBA has marked this rule inactive. As written, when "Total annual expense or estimated cost of the ICT third-party service provider" (c0100) is not the text "null", "Currency of the amount reported in RT.05.01.0070" (c0090) must not be "null" either; it compares with that text, not with an empty cell.

Rule texts are copied from the EBA validation-rule workbook, as recorded on 10 March 2026. The EBA writes most rules only as a formula, in English. "Our explanation" is our plain-language reading of the rule, not EBA text; where they differ, the official text applies.

Sources

  1. EBA: Preparations for reporting of DORA registers of information (opens in a new tab)
  2. EBA: DORA RoI reporting FAQ (28 March 2025) (opens in a new tab)
  3. EBA: Data Model for DORA RoI (opens in a new tab)
  4. AFM: Register of Information (opens in a new tab)
  5. AFM: Q&A after the Q&A session, March 2026 (PDF) (opens in a new tab)
  6. GLEIF: GLEIF API (opens in a new tab)