Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Building a lightweight DORA "Register of Information" (Article 28) for Jira – feedback on fields?

Alex M
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
November 30, 2025

Hi everyone,

I’m a VP of Data & Analytics at a regulated bank. We are currently scrambling to prepare our DORA Article 28 Register of Information (RoI) for the upcoming 2026 reporting cycle.

I noticed existing Jira apps are either heavy GRC suites (expensive/complex) or generic asset managers. I just need a clean way to tag our ICT vendors on tickets and export the mandatory ESMA report.

I decided to build a simple "DORA Register" plugin for my own team to solve this, and I'm thinking of releasing it.

The concept:

  1. Vendor Panel: A dedicated dashboard to list vendors + LEI Codes (mandatory).
  2. Risk Link: A custom field on Jira Issues to link a vendor and mark "Critical Function: Yes/No."
  3. The "Auditor" Export: A button that generates the exact XML/CSV structure the regulator demands.

My Question: For those dealing with DORA, is linking vendors to specific Jira Issues enough for your audit trails? Or do you strictly need to link them to Service Desk Assets/Objects?

If you want to beta test the CSV export script next week, let me know.

Thanks!

1 comment

Comment

Log in or Sign up to comment
fcerullocx
Contributor
December 1, 2025

Hi

I would recommend creating a vendor database for all vendors with all relevant details.

Then, you could create JIRA tickets / issues when you need to perform the annual/semi-annual review and link to those database entries. Also, having a database will make things much easier for exporting data (rather than exporting JIRA issues).

Hope that helps.

Kind regards,

Fabio

 

TAGS
AUG Leaders

Atlassian Community Events