DORA Pillar IV  ·  Self-Hosted

A DORA register
you can defend.

Mlab TPRM manages your ICT third-party providers end to end — identification, risk scoring, contracts and exit plans — and generates the complete EBA register of information, on your own infrastructure.

TPRM.EXAMPLE.COM / REGISTER Acme Cloud — core banking LEI 000000EXAMPLE0000191 · IE CRITICAL COMPOSITE RISK 78 / 100 high exposure Operational 72 Security 84 Compliance 65 Financial 58 Concentration 90 REGISTER OF INFORMATION · RF 4.0 register-2026Q2.zip xBRL-CSV · 15 templates · deposit-ready 15 / 15 B_01.01 B_02.01 B_03.03 B_05.01 B_07.01 +10 Referential integrity validated — no orphan references
15

EBA ITS Templates

5

Risk Dimensions

<5min

To Deploy

100%

Self-Hosted

( Workflow )

From onboarding to compliance.

Four stages, one platform. Every module maps to a DORA article and an EBA code — it is not a generic vendor-risk tool bent into shape.

STAGE 01

Register

Onboard ICT providers with full identification: category, criticality, services, data access level and LEI.

STAGE 02

Assess

Score risk across operational, security, compliance, financial and concentration dimensions, with history and review dates.

STAGE 03

Contract

Track contractual arrangements, verify Art. 30 compliance, manage SLAs, renewal dates and exit strategies.

STAGE 04

Report

Generate the 15 EBA ITS templates, validate referential integrity and produce the deposit-ready package.

( Scoring )

Score and monitor, don't guess.

Five dimensions per provider, each with its own history and review date, aggregated into one composite score you can put in front of a regulator. Concentration is analysed by category and by geography, so an over-reliance shows up before an auditor finds it.

OperationalService continuity, substitutability
72
SecurityCertifications, incident history, data access
84
ComplianceArt. 30 clauses, audit rights, sub-outsourcing
65
FinancialSolvency, dependency, contract value
58
ConcentrationBy category and by geography
90
( EBA ITS · Reporting Framework 4.0 )

All 15 templates, generated for you.

Every module feeds the register. Mlab TPRM aggregates your data into the complete set of EBA ITS templates with controlled eba_* codes, runs a referential integrity validation, and builds the xBRL-CSV package matching the official deposit structure.

B_01.01Entity maintaining register
B_01.02Entities in scope
B_01.03Branches
B_02.01Contractual — general
B_02.02Contractual — specific
B_02.03Arrangement links
B_03.01Signing entities
B_03.02ICT TPSP signing
B_03.03Service providers
B_04.01Entities using services
B_05.01ICT third parties
B_05.02Supply chain
B_06.01Functions supported
B_07.01Criticality assessment
B_99.01Definitions
( Deployment )

GRC-grade compliance, without the GRC price tag.

Enterprise GRC suites charge six figures. Spreadsheets cost zero but lose every thread. Mlab TPRM sits between — a DORA-specific platform you actually own.

Your infrastructure

Runs entirely on your servers. The only outbound call is an hourly licence validation. No provider, contract, assessment or register data ever leaves your network.

Five minutes to running

docker compose up and you are done. Rust and Actix-web for the app, MySQL for business data, ClickHouse for analytics. Migrations run on startup.

DORA-specific

Every module maps to a DORA article and an EBA code, rather than a generic vendor-risk questionnaire relabelled for the occasion.

Free tier

Up to 5 ICT providers and 3 users, with dashboard, provider management, contracts, risk assessments and third-party incidents included.

Licensed tier

Unlocks the DORA register, EBA export, exit strategies, due diligence, audits and analytics. A licence change, not a reinstall.

Offline grace

Up to 48 hours at a time without outbound HTTPS. Beyond that the instance locks until the licence check succeeds again.

Ready to take control of your third-party risks?

Free tier included, no credit card. Or bring us in to run the DORA gap analysis alongside the deployment.