On the Record
August 17, 2026Trucast

The register describes a firm that no longer exists

A large bank carries tens of thousands of third-party relationships. The register that describes them is assembled by questionnaire, on a cycle: annually for most, quarterly for the critical few.

The register is not wrong when it is written. It decays.

A vendor subcontracts a function in March. An integration is repointed in May. A contract renews with different exit terms in July. None of these events pass through the questionnaire cycle, because the questionnaire is a thing you answer, not a thing that watches. By the time anyone asks what depends on a given provider, the document answering that question describes an operating model the firm has already left behind.

This is tolerable right up until it isn't. It stops being tolerable during an incident, when the question is asked by someone who will write down your answer.

What is structurally true

The register was never the dependency. It was a description of the dependency, taken at a moment, by asking people.

The dependency itself lives somewhere else entirely: in the contract in SharePoint, in the integration configuration, in the ticket where someone noted the workaround, in the call where the vendor mentioned their own provider. Those artifacts sit closer to the truth than the register does. Nobody reads them, because reading them at the scale of tens of thousands of relationships is not work a person can do.

That claim is worth making precisely, because it is easy to oversell. Much of the evidence is vendor-produced: the SOC 2 report, the questionnaire response, the certificate of insurance. Reading your own files at question time does not make your picture of the vendor current. It makes the staleness legible, and dated, which is a smaller and more honest claim. Legible is not the same as gone. It is, however, the difference between a gap you can evidence and one you cannot.

So firms are now pointing language models at the register.

This produces fluent, confident, stale answers. The model is not the failure. The model faithfully reproduces its substrate, and the substrate is a snapshot with no lineage. What was previously an obviously-dated PDF becomes a well-written paragraph delivered on demand, and the staleness stops announcing itself. Confidence gets added; currency does not.

The general form: you cannot govern what you cannot cite. In a regulated firm the unit of trust is not the answer. It is the answer's lineage: which source, as of when, and what it said. An answer without lineage is not a weaker answer. It is a different kind of object, and it cannot be put in front of a regulator.

What this means for you

Treat the register as derived, not source. It is an artifact produced from underlying evidence. The evidence is what should be read at question time. If your architecture cannot re-derive the register, you do not have a third-party risk system. You have a document.

Make citation depth an acceptance criterion. Any AI answer entering a risk or regulatory workflow should resolve to its source in one click. Not a footnote, not a confidence score. The document, as of a date. If a vendor cannot demonstrate that, the demo is showing you fluency.

Make "no source" a valid answer. Systems that cannot say I don't have this will fill the gap, and they will fill it most aggressively in exactly the corners nobody has checked. The absence of a source is itself a finding, frequently a more useful one than the answer you were looking for.

On the record

DORA requires firms to maintain a register of information on contractual arrangements for ICT third-party providers, to keep it up to date, and to submit it on an annual cycle. It also has to be producible to the supervisor on request, and that is the obligation that bites. A register that is accurate each March and decaying by June satisfies the calendar and fails the request.

The questionnaire cycle is not being tightened. It is being made structurally insufficient.

Firms that treat this as a reporting exercise will produce a better document. Firms that treat it as an architecture problem will be able to answer the question at the moment it is asked.


Trucast builds Foundation, the governed layer for AI in regulated financial firms. Reads are live, every answer cites its source, and every change is a proposal a named person approves.

Skip to main content