DORA Register of Information
The DORA Register of Information surface prepares annual RoI evidence for a financial-entity operator. Stella provides deterministic local B.01-B.14 projection, prior-year hash binding, retention metadata, and offline verification. The operator remains responsible for content, legal review, competent-authority filing, and effective retention choices.
This is a surface of the DORA Operational Resilience Pack.
Claim boundary: operator-support.
Primary evidence scope: operator-observed-estate for Stella-observed ICT software and integrations, with operator-supplied required for financial entity, contract, subcontracting, and filing facts.
Source Docs
- DORA Register of Information v1
- Assurance Evidence Export v1
- Assurance Setup Prerequisites v1
- DORA RoI CLI guide
- DORA RoI retention policy
- Integrations DORA RoI metadata
- Asset Registry v1
- Tenant Compliance Profile v1
Source Boundaries
RoI generation consumes source-owned data. It must not invent missing legal, contract, or subcontracting information.
| Source | Owner | RoI use |
|---|---|---|
| Tenant compliance profile | Authority | LEI, legal name, jurisdiction, and DORA financial-entity flags. |
| Asset registry | Graph | ICT service and integration asset identities. |
| Integration metadata | Integrations | Criticality, contract dates, and operator-filled subcontracting-chain provenance. |
| Prior-year artifact references | EvidenceLocker | Previous annual bundle hash and signed artifact refs. |
| Stella supplier evidence | CRA/Product Security and release evidence | Stella release, SBOM/VEX, CVD, lifecycle, and incident-notification posture when Stella itself is in the operator estate. |
Stella auto-discovers only direct integrations. Deeper subcontracting-chain ranks are operator-filled and must carry provenance. Rank 1 direct-provider rows may be auto-captured only when they match the direct provider.
Local Contract Export
stella export dora-roi wraps the local dora-roi.v1 output in a deterministic ZIP for offline handoff and verification. The ZIP entries are:
index.json;manifest.json;signature.json;templates/*.xmlfor B.01 through B.14.
stella verify dora-roi validates the ZIP manifest, hashes, local HMAC signature, retention metadata, and prior-year binding offline.
The target Assurance export profile id is dora.roi. ExportCenter does not currently publish this as a built-in profile; current operators use the CLI compatibility route until the registry and production signing contract are wired.
Retention
Default annual RoI retention is 7 years. Tenant overrides are allowed only in the inclusive 5 to 10 year range and require an audit reason and approver. Shortening a previously committed regulatory or customer period requires separate approval.
EvidenceLocker remains the durable retention ledger owner after artifacts are sealed. Authority stores operator policy and exposes normalized effective retention settings; it must not store sealed storage roots, private keys, or provider secrets.
Schema Status
The current export is a deterministic local contract pinned to:
- Stella contract version
dora-roi.v1; - local taxonomy marker
its-eu-2024-2956-local-contract-v1.
Official EBA taxonomy validation
The approved EBA package eba-dora-roi-reporting-framework-4.0-taxo-package-4.0-errata5 is vendored verbatim into the local offline schema path with source, hash, licence, and notice evidence (counsel Path A — see the EBA taxonomy schema-intake counsel reply and the REG-20260502 EBA DORA RoI 4.0 errata5 record). When the package is loaded, the RoI encoder validates the produced B.01-B.07 templates structurally against the package’s canonical b_NN.NN.xsd entries (offline; SHA-256-pinned) and flips the bundle’s regulatory-conformance flag from not-claimed (EBA taxonomy not loaded) to claimed-against:eba-reporting-framework-4.0-taxo-package-4.0-errata5. The local dora-roi.v1 contract remains the fail-closed fallback: when the package is absent or its SHA-256 does not match, the encoder refuses to claim EBA conformance and stays on the local-contract posture.
Product-facing statement. Official EBA taxonomy validation uses an unmodified local copy of the applicable EBA reporting-framework package. Stella does not alter the EBA package and does not represent that the EBA has certified, approved, or endorsed Stella.
Scope and residual: validation is XSD-structural (template-to-XSD mapping plus XML well-formedness against the SHA-256-pinned package). Deeper XBRL conformance — DPM dimensional validation, formula/assertion rules, and full instance-level XBRL processing — is a residual follow-up and is not yet claimed.
Blocking Conditions
Do not treat an RoI bundle as filing-ready when:
- the tenant is not marked as a DORA financial entity;
- LEI validation fails;
- required B.01 through B.14 source fields are missing;
- deeper subcontracting-chain rows are absent or lack operator provenance;
- the selected official schema/taxonomy package is not locally pinned;
- the prior-year hash does not match the retained prior bundle;
- retention override values or audit metadata are invalid;
- bundle verification fails or produces a different hash on clean replay.
