B_05.01 ICT third-party service providers
What this template is for
B_05.01 is the master list of ICT third-party service providers: direct providers, intra-group providers, subcontractors from B_05.02 and their ultimate parents. B_02.02, B_03.02, B_05.02 and B_07.01 refer to it.
Filling it in
- All providers: list every ICT third-party service provider, not only those supporting critical or important functions (EBA FAQ Q69).
- Identifier type (0020): use a code from the list: LEI, EUID, CRN, VAT, PNR or NIN, without a country prefix. For legal persons in the Union, only an LEI or EUID may be used; for legal persons outside the Union, only an LEI (EBA FAQ Q47).
- Ultimate parent (0110): if the provider has no parent undertaking, repeat the provider's own identifier (EBA FAQ Q99).
- Fill this sheet early: other sheets reuse its identifiers.
AFM clarifications
- No LEI or EUID: enter another available identifier. For a legal person without an LEI or EUID, that is marked as a data-quality issue, but the register is not rejected (AFM Q&A, March 2026 (opens in a new tab)). Don't use a dummy code and don't leave the field empty (AFM (opens in a new tab)).
- Which providers: every third-party ICT provider you have a contract with, including digital advertising platforms. A free service without a contract does not need to be included (AFM Q&A, March 2026 (opens in a new tab)).
How DORA Convert handles it
Our Excel template has a sheet named after this template. Each column header carries a note with what to enter, an example and the official source. Drop-down cells show each option as a label with its EBA code; the package carries the code. Errors block the package; warnings do not. See what we check.
- LEI: where the identifier type is LEI, the identifier is checked for format and check digits and, with online checks on, looked up in GLEIF, as the EBA does with VR_71.
- VAT: where the type is VAT, the number is checked for format and, with online checks on, in VIES.
- EUID: checked for structure only; the EBA checks EUIDs against BRIS (VR_72), which we can't query.
- Prefixes: an EUID or VAT prefix that does not match the provider's country is a warning.
- Placeholders: values such as "n/a" or "tbd" are flagged as warnings.
- Ultimate parent: required; a blank cell is an error.
- LEI or EUID for EU legal persons: a provider that is a legal person with its headquarters in the EU, identified by a CRN, VAT or other code, gets a warning (EBA FAQ Q47). The AFM treats that as a data-quality issue, not a rejection. If the provider has no LEI or EUID, keep the code you have.
- LEI for non-EU legal persons: a legal person with its headquarters outside the EU, identified by anything other than an LEI, also gets a warning (EBA FAQ Q47). We read the headquarters country (0080) to decide whether a provider is in the Union.
- Reminder: unless your workbook shows it, you are asked to confirm that every provider is listed, not only critical ones (FAQ Q69).
- EBA rules: the EBA's active business rules for this template run as warnings; inactive ones are not applied.
Official fields
Official summary: Lists the direct providers, intra-group providers, subcontractors in B_05.02, and their ultimate parent undertakings. (ITS Annex I Part 1)
| Column | Official label | Data type | Key or reference | Required | Allowed values |
|---|---|---|---|---|---|
| c0010 | Identification code of ICT third-party service provider | varchar(255) | PK | Not null | Identifier value as instructed by ITS/DM |
| c0020 | Type of code to identify the ICT third-party service provider | varchar(255) | Not null | Closed set; PV B0501/LISTIDTYPE | |
| c0030 | Additional identification code of ICT third-party service provider | int | Nullable | Integer; TC rule 331 applies | |
| c0040 | Type of additional identification code of the ICT third-party service provider | varchar(255) | Nullable | Closed set; PV B0501/LISTIDTYPE | |
| c0050 | Legal name of the ICT third-party service provider | varchar(255) | Not null | Free text / narrative value per ITS and DM | |
| c0060 | Name of the ICT third-party service provider in Latin alphabet | varchar(255) | Nullable | Free text / narrative value per ITS and DM | |
| c0070 | Type of person of the ICT third-party service provider | varchar(255) | Not null | Closed set; PV B0501/LISTB05010070 | |
| c0080 | Country of the ICT third-party service provider’s headquarters | char(2) | Not null | Closed set; PV B0501/LISTCOUNTRY | |
| c0090 | Currency of the amount reported in RT.05.01.0070 | char(3) | Nullable | Closed set; PV B0501/LISTCURRENCY | |
| c0100 | Total annual expense or estimated cost of the ICT third-party service provider | money | Nullable | Monetary amount; DM and FR numeric-reporting rules apply | |
| c0110 | Identification code of the ICT third-party service provider’s ultimate parent undertaking | varchar(255) | FK | Not null | Identifier value as instructed by ITS/DM |
| c0120 | Type of code to identify the ICT third-party service provider’s ultimate parent undertaking | varchar(255) | Nullable | Closed set; PV B0501/LISTIDTYPE |
From the EBA data model and validation rules, as recorded on 10 March 2026. Official labels are in English.
Official clarifications
- Published typos that do not change reporting: The official FAQ states that certain B_07.01 and B_05.01 wording problems in the published ITS are typos that do not change code-based reporting and will be corrected in an updated ITS. (FAQ Q48)
- Provider coverage in B_05.01: All ICT third-party service providers must be identified in B_05.01, not only those supporting critical or important functions. (FAQ Q69)
- c0020 Type of code to identify the ICT third-party service provider: FAQ Q47: use only the closed-set code types without the country-prefix pattern shown in the published ITS text; only LEI or EUID may be used for legal persons in the Union.
- c0110 Identification code of the ICT third-party service provider’s ultimate parent undertaking: FAQ Q99: if the ICT third-party service provider has no parent undertaking, repeat the provider identifier here.
EBA validation rules
Official note: Includes the broadest mix of active and inactive provider-related rules. (VR table B_05.01)
Active rules
Official expression:
Our explanation: Columns c0020, c0050, c0060, c0070, c0080 and c0110 must be filled in every row. This includes "Name of the ICT third-party service provider in Latin alphabet" (c0060), which the field list marks as nullable; fill it in even when it equals the legal name.with {tB_05.01, default:null, interval:false}: not ( isnull ({(c0020, c0050, c0060, c0070, c0080, c0110)}) )Official expression:
Our explanation: When any other column from c0020 to c0120 is filled, "Type of code to identify the ICT third-party service provider" (c0020) must be filled too. Choose the code type in c0020.with {tB_05.01, default: null, interval: false}: if ( not ( isnull ({c0030}) ) ) or not (( isnull ({c0040}) )) or not (( isnull ({c0050}) )) or not (( isnull ({c0060}) )) or not (( isnull ({c0070}) )) or not (( isnull ({c0080}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) then ( ( not ( isnull ({c0020}) ) )) endifOfficial expression:
Our explanation: When any other column from c0020 to c0120 is filled, "Legal name of the ICT third-party service provider" (c0050) must be filled too. Enter the legal name in c0050.with {tB_05.01, default: null, interval: false}: if ( not ( isnull ({c0030}) ) ) or not (( isnull ({c0040}) )) or not (( isnull ({c0020}) )) or not (( isnull ({c0060}) )) or not (( isnull ({c0070}) )) or not (( isnull ({c0080}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) then ( ( not ( isnull ({c0050}) ) )) endifOfficial expression:
Our explanation: When any other column from c0020 to c0120 is filled, "Name of the ICT third-party service provider in Latin alphabet" (c0060) must be filled too. Enter the name in Latin characters in c0060, even when it equals the legal name.with {tB_05.01, default: null, interval: false}: if ( not ( isnull ({c0030}) ) ) or not (( isnull ({c0040}) )) or not (( isnull ({c0050}) )) or not (( isnull ({c0020}) )) or not (( isnull ({c0070}) )) or not (( isnull ({c0080}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) then ( ( not ( isnull ({c0060}) ) )) endifOfficial expression:
Our explanation: When any other column from c0020 to c0120 is filled, "Type of person of the ICT third-party service provider" (c0070) must be filled too. Choose the type of person in c0070.with {tB_05.01, default: null, interval: false}: if ( not ( isnull ({c0030}) ) ) or not (( isnull ({c0040}) )) or not (( isnull ({c0050}) )) or not (( isnull ({c0060}) )) or not (( isnull ({c0020}) )) or not (( isnull ({c0080}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) then ( ( not ( isnull ({c0070}) ) )) endifOfficial expression:
Our explanation: When any other column from c0020 to c0120 is filled, "Country of the ICT third-party service provider’s headquarters" (c0080) must be filled too. Choose the headquarters country in c0080.with {tB_05.01, default: null, interval: false}: if ( not ( isnull ({c0030}) ) ) or not (( isnull ({c0040}) )) or not (( isnull ({c0050}) )) or not (( isnull ({c0060}) )) or not (( isnull ({c0070}) )) or not (( isnull ({c0020}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) then ( ( not ( isnull ({c0080}) ) )) endifOfficial expression:
Our explanation: When any other column from c0020 to c0120 is filled, "Identification code of the ICT third-party service provider’s ultimate parent undertaking" (c0110) must be filled too. Enter the ultimate parent's code in c0110.with {tB_05.01, default: null, interval: false}: if ( not ( isnull ({c0030}) ) ) or not (( isnull ({c0040}) )) or not (( isnull ({c0050}) )) or not (( isnull ({c0060}) )) or not (( isnull ({c0070}) )) or not (( isnull ({c0080}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0020}) )) or not (( isnull ({c0120}) )) then ( ( not ( isnull ({c0110}) ) )) endif
Inactive rules
Official expression:
Our explanation: The EBA has marked this rule inactive. As written, when "Type of person of the ICT third-party service provider" (c0070) is "Legal person, excluding individual acting in a business capacity", "Type of code to identify the ICT third-party service provider" (c0020) must be LEI or EUID.with{tB_05.01, default:0, interval: false}: if ({c0070} = [eba_CT:x212]) then ({c0020} in {[eba_qCO:qx2000], [eba_qCO:qx2002]}) endifOfficial expression:
Our explanation: The EBA has marked this rule inactive. As written, when "Type of person of the ICT third-party service provider" (c0070) is "Legal person, excluding individual acting in a business capacity", "Type of additional identification code of the ICT third-party service provider" (c0040) must be LEI or EUID.with{tB_05.01, default:0, interval: false}: if ({c0070} = [eba_CT:x212]) then ({c0040} in {[eba_qCO:qx2000], [eba_qCO:qx2002]}) endifOfficial expression:
Our explanation: The EBA has marked this rule inactive. As written, when "Type of code to identify the ICT third-party service provider" (c0020) is LEI, "Additional identification code of ICT third-party service provider" (c0030) must have the LEI format: 20 characters, 18 capital letters or digits, then two digits.with{tB_05.01, default:0, interval: false}: if({c0020} = [eba_qCO:qx2000]) then ( (match({c0030}, "^[A-Z0-9]{18}[0-9]{2}$"))) endifOfficial expression:
Our explanation: The EBA has marked this rule inactive. As written, when "Additional identification code of ICT third-party service provider" (c0030) is not the text "null", "Type of additional identification code of the ICT third-party service provider" (c0040) must not be "null" either; it compares with that text, not with an empty cell.with {tB_05.01, default: 0, interval: false}: if({c0030} != "null") then ({c0040} != "null") endifOfficial expression:
Our explanation: The EBA has marked this rule inactive. As written, when "Total annual expense or estimated cost of the ICT third-party service provider" (c0100) is not the text "null", "Currency of the amount reported in RT.05.01.0070" (c0090) must not be "null" either; it compares with that text, not with an empty cell.with {tB_05.01, default: 0, interval: false}: if({c0100} != "null") then ({c0090} != "null") endif
Rule texts are copied from the EBA validation-rule workbook, as recorded on 10 March 2026. The EBA writes most rules only as a formula, in English. "Our explanation" is our plain-language reading of the rule, not EBA text; where they differ, the official text applies.
Sources
- EBA: Preparations for reporting of DORA registers of information (opens in a new tab)
- EBA: DORA RoI reporting FAQ (28 March 2025) (opens in a new tab)
- EBA: Data Model for DORA RoI (opens in a new tab)
- AFM: Register of Information (opens in a new tab)
- AFM: Q&A after the Q&A session, March 2026 (PDF) (opens in a new tab)
- GLEIF: GLEIF API (opens in a new tab)