DORA Register of Information

The DORA Register of Information surface prepares annual RoI evidence for a financial-entity operator. Stella provides deterministic local B.01-B.14 projection, prior-year hash binding, retention metadata, and offline verification. The operator remains responsible for content, legal review, competent-authority filing, and effective retention choices.

This is a surface of the DORA Operational Resilience Pack.

Claim boundary: operator-support.

Primary evidence scope: operator-observed-estate for Stella-observed ICT software and integrations, with operator-supplied required for financial entity, contract, subcontracting, and filing facts.

Source Docs

Source Boundaries

RoI generation consumes source-owned data. It must not invent missing legal, contract, or subcontracting information.

SourceOwnerRoI use
Tenant compliance profileAuthorityLEI, legal name, jurisdiction, and DORA financial-entity flags.
Asset registryGraphICT service and integration asset identities.
Integration metadataIntegrationsCriticality, contract dates, and operator-filled subcontracting-chain provenance.
Prior-year artifact referencesEvidenceLockerPrevious annual bundle hash and signed artifact refs.
Stella supplier evidenceCRA/Product Security and release evidenceStella release, SBOM/VEX, CVD, lifecycle, and incident-notification posture when Stella itself is in the operator estate.

Stella auto-discovers only direct integrations. Deeper subcontracting-chain ranks are operator-filled and must carry provenance. Rank 1 direct-provider rows may be auto-captured only when they match the direct provider.

Local Contract Export

stella export dora-roi wraps the local dora-roi.v1 output in a deterministic ZIP for offline handoff and verification. The ZIP entries are:

stella verify dora-roi validates the ZIP manifest, hashes, local HMAC signature, retention metadata, and prior-year binding offline.

The target Assurance export profile id is dora.roi. ExportCenter does not currently publish this as a built-in profile; current operators use the CLI compatibility route until the registry and production signing contract are wired.

Retention

Default annual RoI retention is 7 years. Tenant overrides are allowed only in the inclusive 5 to 10 year range and require an audit reason and approver. Shortening a previously committed regulatory or customer period requires separate approval.

EvidenceLocker remains the durable retention ledger owner after artifacts are sealed. Authority stores operator policy and exposes normalized effective retention settings; it must not store sealed storage roots, private keys, or provider secrets.

Schema Status

The current export is a deterministic local contract pinned to:

Official EBA taxonomy validation

The approved EBA package eba-dora-roi-reporting-framework-4.0-taxo-package-4.0-errata5 is vendored verbatim into the local offline schema path with source, hash, licence, and notice evidence (counsel Path A — see the EBA taxonomy schema-intake counsel reply and the REG-20260502 EBA DORA RoI 4.0 errata5 record). When the package is loaded, the RoI encoder validates the produced B.01-B.07 templates structurally against the package’s canonical b_NN.NN.xsd entries (offline; SHA-256-pinned) and flips the bundle’s regulatory-conformance flag from not-claimed (EBA taxonomy not loaded) to claimed-against:eba-reporting-framework-4.0-taxo-package-4.0-errata5. The local dora-roi.v1 contract remains the fail-closed fallback: when the package is absent or its SHA-256 does not match, the encoder refuses to claim EBA conformance and stays on the local-contract posture.

Product-facing statement. Official EBA taxonomy validation uses an unmodified local copy of the applicable EBA reporting-framework package. Stella does not alter the EBA package and does not represent that the EBA has certified, approved, or endorsed Stella.

Scope and residual: validation is XSD-structural (template-to-XSD mapping plus XML well-formedness against the SHA-256-pinned package). Deeper XBRL conformance — DPM dimensional validation, formula/assertion rules, and full instance-level XBRL processing — is a residual follow-up and is not yet claimed.

Blocking Conditions

Do not treat an RoI bundle as filing-ready when: