DORA ICT Third-Party Governance Platform
Your DORA register, built once and kept ready - not rebuilt every year.
Treica structures your ICT providers, contracts, functions, sub-outsourcing chains and evidence into one connected record. It validates that record against DORA rules, flags what could still attract supervisory attention, and produces your submission package in the format your authority accepts.
Deterministic validation. Every finding linked to a rule and a regulatory source. EU-region hosting. Read-only, time-boxed access for your auditor.
The real shape of the problem
The register is not a document. It is a set of relationships that has to stay consistent.
Your register connects legal entities, ICT providers, the services they deliver, contractual arrangements, the functions those arrangements support, and the sub-outsourcing chains beneath them. Each of those links has to agree with the others.
When the data lives in spreadsheets, contracts, shared drives and email, the links break quietly. A provider is renamed in one place and not another. An arrangement supports a function that no one classified. A subcontractor exists in a contract but not in the register.
None of this shows up as a missing cell. It shows up as an inconsistency between tables - the kind a supervisor cross-references and asks about.
Why the spreadsheet stops working
Spreadsheets fail at the relationships, not the row count.
A spreadsheet can hold a few hundred rows without complaint. That is not where it breaks. It breaks because it cannot enforce the links between tables.
Nothing stops a provider being listed under two spellings, which understates your concentration. Nothing checks that an arrangement supporting a critical function actually names that function. Nothing records why a function was classified critical, or who confirmed it, or when. Nothing preserves what you filed last year so you can prove what changed.
So the data can look complete and still be internally inconsistent. The work of finding those inconsistencies falls on one person, under deadline, once a year.
What Treica is
A connected record of your ICT third-party arrangements, with the register as its output.
Treica holds your third-party operating model as a single connected structure: providers, the services they deliver, the arrangements that consume those services, the functions the arrangements support, the sub-outsourcing chains, and the evidence behind each assertion.
The Register of Information is projected from that structure. You maintain the source records once; the register is generated from them, with each field traceable back to where it is governed.
When you file, the exact submitted version is frozen and kept, so you can always reproduce what the authority received.
How it works
Construct, validate, resolve, file - then keep it current.
- 1. Construct
Import your existing register or build it record by record - with likely duplicate providers detected and arrangements mapped to services and functions.
- 2. Validate
Run deterministic validation. Errors that would block a filing are separated from warnings that could attract supervisory attention.
- 3. Resolve
Assign findings, attach evidence, and record your position where you choose not to act. Every finding links to its rule and regulatory source.
- 4. File
Generate the xBRL-CSV package for your authority, checked against documented structural rejection conditions before it leaves the system.
- 5. Maintain
Between filings, the platform tracks expiries, reviews and changes - so the next cycle starts from a current register, not a rebuild.
The warning tier
Some registers pass file validation and still raise questions. We flag those first.
A structurally valid file is the starting point, not the finish. Free validators and the published check set confirm the format. They do not tell you where your register is likely to attract a supervisor’s attention.
Treica’s warning tier does. It flags patterns that pass technical validation but read as gaps to an examiner. Each warning prompts you to record your position, with a justification - turning an open question into evidence of active management.
A major cloud provider declared with no sub-outsourcing.
An exit strategy documented but never tested.
A designated critical provider with no clause coverage assessed.
An arrangement added after your last filing that predates it.
Capabilities
Depth where the register is thinnest.
Sub-outsourcing & fourth parties
Map the chain to multiple tiers, check it for cycles, and record what the provider disclosed - so a gap becomes a substantiated position.
Evidence & audit trail
Attach content-addressed evidence to the exact record it supports, stored in an EU region. Every change is written to an immutable audit log.
Submission generation
Generate the xBRL-CSV package against the correct taxonomy version, gated while any blocking error is open, and checked against structural rejection conditions.
Continuous maintenance
An attention dashboard surfaces expiries, overdue reviews and stale classifications, so the next cycle is maintenance, not reconstruction.
Multi-entity & group
Report at entity, sub-consolidated and consolidated levels - with the impossible configurations caught and concentration analysed across the group.
Built to be examined
Give your auditor read-only, time-boxed access and a 17-section evidence pack that assembles in under a minute, in the order a reviewer works.
Security and procurement
Built to pass a demanding third-party review, because you will run one on us.
Every dependency we add becomes an entry in your own register. We treat that as a cost, and keep our external surface small.
Data is hosted in the EU. Access control is enforced at the data layer, not only in the interface, and each tenant is isolated in several layers. Sign-in uses a magic link with TOTP two-factor authentication. Evidence and generated packages are served through time-limited, non-guessable links. Administrative access happens only through logged, time-limited impersonation you can see in your own audit view.
Who this is for
Built for regulated financial entities that file a DORA register.
Treica is for the teams accountable for the register: Heads of Compliance, Heads of Risk, Chief Risk Officers, DORA programme owners, and the operational and ICT risk people who maintain the data.
Its first market is the entities preparing for the CySEC cycle - Cyprus Investment Firms, crypto-asset service providers, fund managers, electronic money and payment institutions - and the banks, insurers and fintech firms across the EU subject to the same obligation.
Advisory firms can construct a client’s register inside the platform and hand it over through a permission change alone - no export, no re-import, full history retained.
Questions we are asked
Straight answers before you commit time to a demonstration.
Does Treica guarantee my submission will be accepted?+
No, and no tool honestly can. We check your package against the documented structural conditions that authority parsers reject, and block generation while any blocking error is open. The filing decision, and its acceptance, remain with you and your authority.
Is this legal or regulatory advice?+
No. Treica is software. It applies a versioned rule set with each finding linked to a regulatory source, so your own advisors and auditors can review the reasoning. It does not replace them.
How is this different from a free validator?+
Free validators confirm file structure. Treica does that, and adds a warning tier that flags patterns which pass format validation but tend to attract supervisory questions. You can run the same register through both and see the additional findings.
Where is our data stored?+
In the EU. Evidence documents and generated packages are stored in an EU region and served through time-limited, non-guessable links.
What happens to old submissions when the data changes?+
Each filed package is frozen with its hash, taxonomy version and the validation run behind it. Later changes to your records never alter what was filed.
Next step
See where your register stands before the next deadline.
Bring your current register - spreadsheet or export. In a guided review, we will run it through validation, show you the blocking errors and the supervisory-attention warnings, and walk through what maintaining it continuously would look like.