B_05.02 ICT service supply chains
What this template is for
B_05.02 maps the supply chain behind each ICT service in each arrangement. It ranks the providers in the chain: rank 1 is the direct provider, higher ranks are subcontractors further down.
Filling it in
- One row per arrangement, service type, provider and recipient.
- Every provider in the chain, subcontractors included, must also be listed in B_05.01.
- Rank 1: the direct provider. Its recipient repeats the provider's own identifier (EBA FAQ Q65).
- Ranks are whole numbers.
AFM clarifications
Include a subcontractor when its failure would put the security or continuity of the service at risk (AFM Q&A, March 2026 (opens in a new tab)).
How DORA Convert handles it
Our Excel template has a sheet named after this template. Each column header carries a note with what to enter, an example and the official source. Drop-down cells show each option as a label with its EBA code; the package carries the code. Errors block the package; warnings do not. See what we check.
- Rank 1: a recipient that differs from the provider is an error.
- Recipient (0060): must appear in B_05.01 or in B_01.02; we check both. A recipient in neither is an error.
- References: an arrangement missing from B_02.01 or a provider missing from B_05.01 is a warning, because the data model does not name the target tables. The AFM still rejects it as error 807, so fix it before you file.
- Keys: each combination of arrangement, service type, provider, rank and recipient may appear once.
- EBA rules: the EBA publishes no business rules for this template.
Official fields
Official summary: Lists ICT service supply chains by identifying the providers in the same chain and ranking them within each ICT service and contractual arrangement. (ITS Annex I Part 1)
| Column | Official label | Data type | Key or reference | Required | Allowed values |
|---|---|---|---|---|---|
| c0010 | Contractual arrangement reference number | varchar(255) | PK; FK -> B_02.01 | Not null | Identifier value as instructed by ITS/DM |
| c0020 | Type of ICT services | varchar(255) | PK | Not null | Closed set; PV B0502/LISTSERVICE |
| c0030 | Identification code of the ICT third-party service provider | varchar(255) | PK; FK -> B_05.01 | Not null | Identifier value as instructed by ITS/DM |
| c0040 | Type of code to identify the ICT third-party service provider | varchar(255) | Nullable | Closed set; PV B0502/LISTIDTYPE | |
| c0050 | Rank | int | PK | Not null | Integer; TC rule 331 applies |
| c0060 | Identification code of the recipient of sub-contracted ICT services | varchar(255) | PK; FK | Not null | Identifier value as instructed by ITS/DM |
| c0070 | Type of code to identify the recipient of sub-contracted ICT services | varchar(255) | Nullable | Closed set; PV B0502/LISTIDTYPE |
From the EBA data model and validation rules, as recorded on 10 March 2026. Official labels are in English.
Official clarifications
- c0060 Identification code of the recipient of sub-contracted ICT services: FAQ Q65: for a direct provider at rank 1, repeat the identifier reported in B_05.02.0030.
EBA validation rules
The EBA publishes no validation rules for this template.
Official note: No DORA validation rules are listed for this template. (VR table B_05.02)