Wie unterstützt Leno bei Prüfungen und Auskunftsersuchen?

Leno provides the register at any time in an audit-proof, consistent, and traceable manner as of a given date. Data states, changes, and histories can be made available at the push of a button - without manual preparation.

Weitere hilfreiche Antworten

Is the Leno GRC platform customizable as a No-Code solution?

Yes, as a modern cloud platform, Leno allows for No-Code configuration.

Yes, as a modern cloud platform, Leno allows for No-Code configuration. The solution is highly scalable and can be flexibly adapted to your internal structures, processes, and permission sets without any programming effort.

How does Leno replace manual Excel sheets with automated GRC workflows?

Leno eliminates manual errors through high-level automation and integrated AI

Leno eliminates manual errors through high-level automation and integrated AI. Structured workflows and built-in regulatory expertise replace tedious email-based coordination and static lists with a modern, digital process.

Can Leno link existing Third-Party Risk (TPRM) processes with Contract Management (CLM)?

Yes, Leno eliminates fragmented data silos by seamlessly linking vendors directly to their corresponding contracts, risks, and mitigation measures.

Yes, Leno eliminates fragmented data silos by seamlessly linking vendors directly to their corresponding contracts, risks, and mitigation measures. This seamless integration prevents redundant data entry and ensures full transparency.

What makes Leno the leading GRC platform for TPRM, CLM & ISR?

Leno is a modular GRC platform designed to digitalize and automate Governance, Risk & Compliance.

Leno is a modular GRC platform designed to digitalize and automate Governance, Risk & Compliance. It serves as a central hub for Third-Party Risk Management (TPRM), Contract Lifecycle Management (CLM), Information Security (ISM), and BCM.

What is an outsourcing register?

An outsourcing register or vendor repository is a structured overview of all outsourcing arrangements of a financial institution. It ensures transparency towards supervisory authorities and auditors and provides a reliable basis for identifying and managing concentration risks, including at EU level.

How fast can Leno be deployed using onboarding and templates?

Thanks to pre-defined GRC templates and expert onboarding support, you can achieve a rapid "Go-Live".

Thanks to pre-defined GRC templates and expert onboarding support, you can achieve a rapid "Go-Live". We guide you from initial data migration to full production to ensure a smooth transition.

What is the information register under DORA?

The information register is a DORA-mandated register that contains detailed information on ICT services, ICT third-party providers, and critical functions across 15 tables. It allows supervisory authorities to gain a quick, consistent overview of an institution's ICT landscape, as well as concentration risks and dependencies at the EU level.

Is the platform available in multiple languages for global teams?

Yes, Leno supports English and German as standard.

Yes, Leno supports English and German as standard. Additional languages for international GRC teams can be added upon request to support your global compliance operations.

How does Leno handle user management and data security?

Security is ensured through Single Sign-On (SSO) and role-based access control (RBAC).

Security is ensured through Single Sign-On (SSO) and role-based access control (RBAC). Leno provides hosting and support directly from Germany, adhering to the highest security standards and architectural requirements.

How can Leno generate registers automatically and in real time?

Leno generates outsourcing and information registers automatically based on a central, integrated data source. Information on outsourcing, ICT services, third parties, risks, and contracts is recorded once in a structured manner and then transferred in real time to the respective registers. Changes—such as updates to service providers, services, risk classifications, or approvals—are immediately applied and are visible in the outsourcing and information registers without manual maintenance.

Which modules does Leno offer for DORA, BCM, and Contract Management?

Leno TPRM (Third-Party Risk & Outsourcing), Leno CLM (Contract Management), and Leno ISM (Information Security & BCM).

Leno is modular and fully integrated. We offer specialized modules: Leno TPRM (Third-Party Risk & Outsourcing), Leno CLM (Contract Management), and Leno ISM (Information Security & BCM). All modules work together to form a holistic GRC ecosystem.

Wie unterstützt Leno bei Prüfungen und Auskunftsersuchen?

Leno provides the register at any time in an audit-proof, consistent, and traceable manner as of a given date. Data states, changes, and histories can be made available at the push of a button - without manual preparation.

When must an information register be created?

Under DORA, financial institutions are required to maintain an information register as soon as they enter into contractual arrangements for the use of ICT services with third-party providers. This register must be kept up to date on an ongoing basis and submitted to the competent supervisory authorities at least once a year or made available upon request.

Which information must be included in the information register?

The information register must include detailed information on ICT service providers and their respective contracts, including service identification, contract details, supported functions, classification as critical or non-critical, information on risks, and any subcontractors.

What are the differences between the outsourcing register and the DORA information register?

The DORA information register goes beyond traditional outsourcing registers, as it must additionally include structured data on ICT services, third parties, and critical functions—often in predefined tables (15-table model)—and is specifically designed for use by supervisory authorities and ESAs.

Does the information register need to be reported to the supervisory authority?

Yes. Financial institutions must provide the register in full to the competent supervisory authority upon request and, in many jurisdictions, submit it annually. This includes information on new contracts, categories of service providers, and the type of ICT services provided.

Is the information register only relevant internally, or is it also used externally?

The register serves internal ICT risk management but is also used externally by supervisory authorities to monitor systemic risks and support the identification of critical ICT third-party providers at the EU level.

Up to which level must ICT third-party providers be listed in the information register?

This depends on the criticality of the supported function. If an ICT service does not support a critical or important function of the financial institution, generally only the ICT third-party provider in a direct contractual relationship with the financial institution (Tier 1) needs to be recorded. Subcontractors at downstream levels do not need to be listed in this case.

Do intra-group ICT services need to be recorded in the information register?

Yes, intra-group ICT services must also be recorded in the information register. DORA generally does not distinguish between external and intra-group ICT providers. What matters is that an ICT service is provided to a financial institution and may impact its ICT resilience. An exception exists for the use of intra-group ICT providers, where additional information may be required, particularly to map ICT service chains. The relevant requirements are outlined in Commission Implementing Regulation (EU) 2024/2956, Annex I, Part 2, including the specifications for completing Template B_05.02.

Our products

Third-Party Risk Management according to DORA, EBA Guidelines & MaRisk

Our TPRM and outsourcing management software enables compliant, transparent, and efficient lifecycle management of outsourcing arrangements, ICT services, and onward outsourcing in accordance with DORA, EBA Guidelines, and MaRisk. AI-driven automation delivers excellent usability, high data quality, and complete audit readiness.

Main functions
Explore Leno TPRM

AI-based contract lifecycle management (CLM) Software – intelligent and centralized

Our AI-powered, user-friendly, and automated software für contract lifecycle management (CLM) provides a dynamic hierarchical representation of all contract documents, continuous compliance with regulatory requirements, and transparent search and filter functions, including approval workflows and deadline monitoring.

Main functions
Explore Leno CLM

A solution for integrated ISM and BCM in accordance with international standards

Map a complete information ecosystem and connect all assets in real time. Our information security and Business Continuity Management (BCM) software enables you to conduct protection needs analyses, business impact analyses, and risk assessments, forming a fully integrated information risk management and BCM system.

Main functions
Explore Leno ISR

Get to know Leno

Book a demo
Book a meeting today to discover Leno.