Validate your DORA ICT Register before CSSF submission.
Drop your CSV here
or click to browse your files · CSV only
When to use DORA ICT Third-Party Information Register Validator
Pre-submission audit for CSSF eDesk portal filings in Luxembourg
Cross-checking LEI identifiers and contract criticalities across banking entities
Identifying third-party ICT service contracts lacking mandatory Article 28 clauses
How to export from EBA / CSSF eDesk Register and clean in MiniJudge
Follow these steps to extract your raw spreadsheet and filter it without writing code:
The Danger of “Excel Purgatory” in DORA ICT Third-Party Information Register Validator
The Regulatory Rejection Bottleneck
Whether submitting a 15-table DORA ICT register to the CSSF eDesk portal (Regulation EU 2024/2956) or maintaining an Article 30 RoPA for supervisory review, Excel cannot enforce relational integrity. A single malformed 20-character LEI, blank statutory retention period, or unmapped international transfer causes official package rejection and emergency legal review cycles costing €15,000+ in auditor fees.
The Missing Evidence Ledger
A simple “Yes” in an internal vendor questionnaire is no longer acceptable to auditors. Regulators demand verifiable provenance: Document → Page → Clause → Exact Excerpt → Status. Manual cross-referencing between 30-page PDF contracts and spreadsheets creates fatigue after just 5 documents, leaving critical subprocessor liabilities and AI training licenses undiscovered.
Hard Judge Schema
Deterministic regex checks ISO 17442 LEI syntax, date formats, required Article 30 columns, and cross-table foreign key constraints in microseconds.
Soft Clause Reasoning
Evaluates complex contractual text against GDPR Article 28(3) and EU AI Act obligations: subprocessor notice windows, audit access, and training opt-outs.
Typed Evidence Ledger
Assigns rigid regulatory statuses (VERIFIED, MISSING, CONFLICTING) with citation references.
Air-Gapped Export
Processes data 100% in-memory without persistent database storage, satisfying Luxembourg and Swiss banking confidentiality standards.
What MiniJudge appends to your spreadsheet
| Source / Item | Requirement | Status | Evidence Excerpt | Action Required |
|---|---|---|---|---|
| AWS_Cloud_DPA.pdf | Art. 28(3)(h) Audit Access | VERIFIED | “Allows for and contributes to audits...” | None (Compliant) |
| Shadow_Analytics.pdf | ISO 17442 LEI Syntax | MISSING | LEI field blank in contract register | Request vendor LEI before submission |
| FastMailer_DPA.pdf | Art. 28(3)(a) Subprocessors | CONFLICTING | “Vendor may add subprocessors without notice” | Require 30-day prior written notice |
MiniJudge vs. Enterprise GRC vs. Manual Excel
- • 4.5 hours per register audit
- • No relational validation across tables
- • High human fatigue & missed gaps
- • High risk of regulatory rejection
- • 3+ months enterprise procurement
- • Requires abandoning existing spreadsheets
- • Heavy overhead for mid-size teams
- • Expensive per-seat licensing
- • Zero setup: drop your existing CSV/XLSX
- • 12ms deterministic validation
- • Appends verified Evidence Ledgers
- • 100% ephemeral in-browser privacy
Frequently Asked Questions
What validation rules does MiniJudge enforce for DORA?
MiniJudge checks Commission Implementing Regulation (EU) 2024/2956 rules: 20-character ISO 17442 LEI syntax, minimum notice periods, explicit audit rights for critical functions, and data residency declarations.
Does our banking data leave our internal perimeter?
No. MiniJudge operates entirely in-memory within your browser or ephemeral edge container without permanent storage, satisfying CSSF and banking confidentiality guidelines.