DORA (EU 2022/2554) Art. 28/30 Register of Information annual build in one artifact: criticality designations for ICT third-party providers and functions are recorded as review_required approval records (a judgment call, not kernel-decided); the annual RoI release itself requires a dual_control(2) gate with a management-body-role approver before submission, reflecting the Art. 5 personal management-body accountability for ICT risk management -- both recorded now via the §27 Human Accountability vocabulary, enforced once HA-RETRO-1's runtime gating is wired to this chain. Each annual cycle's approvals and gate outcome export as one evidence bundle citing the Art. 5 accountability basis. Never a filed submission.
build_dora_roi_register{
"jsonrpc": "2.0",
"method": "tools/call",
"params": {
"name": "build_dora_roi_register",
"arguments": {}
},
"id": 1
}