A DORA register
you can defend.
Mlab TPRM manages your ICT third-party providers end to end — identification, risk scoring, contracts and exit plans — and generates the complete EBA register of information, on your own infrastructure.
EBA ITS Templates
Risk Dimensions
To Deploy
Self-Hosted
From onboarding to compliance.
Four stages, one platform. Every module maps to a DORA article and an EBA code — it is not a generic vendor-risk tool bent into shape.
Register
Onboard ICT providers with full identification: category, criticality, services, data access level and LEI.
Assess
Score risk across operational, security, compliance, financial and concentration dimensions, with history and review dates.
Contract
Track contractual arrangements, verify Art. 30 compliance, manage SLAs, renewal dates and exit strategies.
Report
Generate the 15 EBA ITS templates, validate referential integrity and produce the deposit-ready package.
Score and monitor, don't guess.
Five dimensions per provider, each with its own history and review date, aggregated into one composite score you can put in front of a regulator. Concentration is analysed by category and by geography, so an over-reliance shows up before an auditor finds it.
All 15 templates, generated for you.
Every module feeds the register. Mlab TPRM aggregates your data into the complete set of EBA ITS templates with controlled eba_* codes, runs a referential integrity validation, and builds the xBRL-CSV package matching the official deposit structure.
B_01.01Entity maintaining registerB_01.02Entities in scopeB_01.03BranchesB_02.01Contractual — generalB_02.02Contractual — specificB_02.03Arrangement linksB_03.01Signing entitiesB_03.02ICT TPSP signingB_03.03Service providersB_04.01Entities using servicesB_05.01ICT third partiesB_05.02Supply chainB_06.01Functions supportedB_07.01Criticality assessmentB_99.01DefinitionsGRC-grade compliance, without the GRC price tag.
Enterprise GRC suites charge six figures. Spreadsheets cost zero but lose every thread. Mlab TPRM sits between — a DORA-specific platform you actually own.
Runs entirely on your servers. The only outbound call is an hourly licence validation. No provider, contract, assessment or register data ever leaves your network.
docker compose up and you are done. Rust and Actix-web for the app, MySQL for business data, ClickHouse for analytics. Migrations run on startup.
Every module maps to a DORA article and an EBA code, rather than a generic vendor-risk questionnaire relabelled for the occasion.
Up to 5 ICT providers and 3 users, with dashboard, provider management, contracts, risk assessments and third-party incidents included.
Unlocks the DORA register, EBA export, exit strategies, due diligence, audits and analytics. A licence change, not a reinstall.
Up to 48 hours at a time without outbound HTTPS. Beyond that the instance locks until the licence check succeeds again.
Ready to take control of your third-party risks?
Free tier included, no credit card. Or bring us in to run the DORA gap analysis alongside the deployment.