In 12 closed in-house searches in Madrid over 36 months, Sartori records that 4 processes stalled when ICT-register ownership was split across two group entities. A chief legal officer at a foreign bank branch in Madrid said the DORA register seat needed someone who had already lived through a second-cycle filing. Register mapping is the work, not a policy memo on operational resilience.
Day to day, in-house counsel in this seat reconcile ICT contracts, subcontracting chains, and critical-function flags to Banco de España's DORA 4.0 taxonomy, available for credit-institution filings from March 2025. They overlay Spain's infringement catalog — project of law 121/000105, published in the Boletín Oficial de las Cortes Generales on 27 July 2026 — onto those live rows. CNMV required its 2026 register cycle between 1 and 29 March 2026 on template v_2_0; the 2025 template was not accepted. Head of legal buyers who treat this as a 2025 go-live hire will miss the second cycle already on file.
Adjacent seats that actually convert: financial-regulation product lawyers who have approved MiCA or DLT files; payments counsel who sit against Iberpay and the SNCE; financial-crime advisory lawyers only when the file is third-party ICT, not KYC. Private-practice banking counsel are the thinner inbound path. The Madrid seat maps live ICT registers onto a bill still in Cortes. Our mandate telemetry on those 12 files shows the stall pattern: group legal owned the register in one entity and technology legal owned the contracts in another, and we cannot see the subcontracting chain until both sides join.