Documentation · Platform

Getting Started.

Accounts, navigation, settings and sessions — the foundations every REGREP module depends on.

Manual All REGREP modules · Version 2.2 · 6 screenshots
NoteThis guide replaces the navigation and settings chapters that were previously repeated at the start of every module manual. Module guides now begin at the module itself and refer back to this document.

About this guide

REGREP is a regulatory reporting platform for investment firms. It brings prudential reporting, tax transparency reporting, operational resilience reporting and regulatory file conversion into a single workspace, with a shared corporate profile and a common way of working.

This guide covers everything that is the same across the platform: how to get an account, how the interface is organised, how to configure the settings that every calculation depends on, and how reporting sessions work. Read it once before you open a module guide for the first time.

The documentation set

Each reporting engine has its own guide. All of them assume you have read this one.

#GuideCovers
1Getting StartedAccounts, sign-in, navigation, Settings, sessions, glossary — this document
2Pillar 1 — Capital RequirementsOwn funds, fixed overheads, K-Factors, concentration risk, reports and exports
3DAC2EU automatic exchange of financial account information
4Pillar 2 — ICARAInternal capital and risk assessment, operational and market risk, liquidity adequacy
5Pillar 3 — DisclosuresPublic disclosure templates CC1, CC2 and CCA
6CRSCommon Reporting Standard for non-DAC2 jurisdictions
7TIN ValidationSingle and batch taxpayer identification number checks
8DORA — Register of InformationICT third-party contractual arrangements and the relational template structure
9AdministrationUsers, access rights, IP whitelisting and the audit trail
10EBA XBRL ConverterExcel to XBRL-CSV conversion, validation and the error-bypass control

Conventions used

  • Bold text names something you click or type into — a button, a tab, a field.

  • Menu paths are written with arrows: Solutions → Regulatory Reporting → Prudential Reporting Engine → Pillar 1.

  • Screenshots use a fictional firm, "Sample Investment Firm Ltd", with invented identifiers and figures. Your own screens will show your firm's data.

  • Numbered markers on a screenshot are explained in the key immediately below it.

Getting an account

Access to REGREP is granted per person, not per firm. Every user has their own credentials and their own second factor. Accounts are never shared.

Registering

  1. Open the REGREP sign-in page and choose Sign Up / Register.

  2. Complete the registration form.

  3. Select SIGN UP.

The registration form asks for:

FieldWhat to enter
Full NameYour first and last name as they appear on your firm's records.
Legal Entity NameThe registered name of your firm. This is used to link your account to the right tenant.
Work EmailYour corporate email address. Personal email addresses are not accepted.
Password / Confirm PasswordA password meeting the rules below.

Password rules: at least 8 characters, including at least one capital letter, one number and one special character.

NoteChoose a passphrase well beyond the 8-character minimum — three or four unrelated words are both stronger and easier to remember than a short password with substituted characters. Never reuse a password you have used on another service.

Verifying your email

  1. Open the verification email sent to the address you registered. Check your junk folder if it has not arrived within a few minutes.

  2. Select the confirmation link inside it.

The link takes you straight to two-factor authentication setup.

Setting up two-factor authentication

REGREP requires a time-based one-time password (TOTP) from an authenticator app. Any standard authenticator works — Google Authenticator, Microsoft Authenticator, Authy, 1Password and others.

  1. Open your authenticator app on your phone and choose to add a new account.

  2. Scan the QR code shown on screen. Your app pairs with your REGREP account and starts generating a six-digit code that changes every 30 seconds.

  3. Enter the current code to confirm the pairing.

ImportantPair the authenticator on a device you control and will keep. REGREP does not currently issue backup or recovery codes at enrolment, so if you lose the paired device you will need an administrator or REGREP support to verify your identity and reset the second factor before you can sign in again. If your authenticator app supports encrypted cloud backup, enable it.

Signing in

  1. Enter your email address and password, then select Login.

  2. Open your authenticator app, enter the current six-digit code, and select Verify.

You are taken to the Dashboard. The code is required at every sign-in.

If you cannot sign in

ProblemWhat to do
The code is rejectedCodes expire every 30 seconds. Wait for the next code and try again. If codes are consistently rejected, check that the clock on your phone is set to update automatically — TOTP depends on accurate time.
You have forgotten your passwordSelect Forgot Password? on the sign-in page, enter your registered email address, and follow the reset link sent to you.
You have lost the paired deviceContact your firm's REGREP administrator, or REGREP support. Your identity will be verified before the second factor is reset. There is no self-service route.
Your account appears lockedRepeated failed sign-ins are recorded and shown on the Dashboard under Account Security. Contact your administrator.

Finding your way around

The top navigation bar

The bar across the top of every screen is the platform's permanent navigation. It has three menus on the left and three utilities on the right.

ItemWhat it does
DashboardReturns you to the landing page: company overview, account security status, system events, the compliance calendar and recent user access logs.
SolutionsOpens the reporting engines and conversion tools. This is where the actual work lives.
HelpDocumentation, and a route to contact support.
Notifications (bell)System alerts, task statuses and administrative updates. The badge shows the unread count.
Settings (gear)The corporate, prudential and tax parameters described in section 4. Not the same as your personal account settings.
Profile (person)Your own account settings, security details and sign-out.
NoteThe gear icon opens firm-wide Settings that feed the calculation engines. Your personal preferences and security details are under the profile icon. It is worth being clear which one you are in before you change anything.

Reaching a module

Modules sit three levels deep under Solutions. The pattern is always the same: choose a reporting domain, then an engine, then the module.

The Solutions menu expanded to Pillar 1. Each level opens to the right
Figure 1 — The Solutions menu expanded to Pillar 1. Each level opens to the right.
  1. 1Reporting domain — Regulatory Reporting, Operational Resilience, Professional Development or Audit Management.
  2. 2Engine — within Regulatory Reporting: the Prudential Reporting Engine, the Tax Reporting Engine, or the EBA XBRL Converter.
  3. 3Module — the workspace you actually open.

So the full path to Pillar 1 is Solutions → Regulatory Reporting → Prudential Reporting Engine → Pillar 1 — Capital Requirements. Module guides state the path once at the start and then assume you are inside.

Modules your firm does not have

REGREP shows the full catalogue of modules to everyone, and greys out the ones your firm is not licensed for. A greyed entry is not a fault — it means the module is available in the platform but not enabled for your tenant.

The Tax Reporting Engine. Greyed entries are not enabled for this firm
Figure 2 — The Tax Reporting Engine. Greyed entries are not enabled for this firm.

In the example above, DAC2, FATCA and TIN Validation are available; CRS, AEOI, CbCR / DAC4, MDR / DAC6, Digital Platforms / DAC7 and CARF / DAC8 are not. If you need a module that is greyed out, contact your REGREP account manager.

Frameworks delivered as custom solutions

CbCR / DAC4, MDR / DAC6, Digital Platforms / DAC7 and CESOP are delivered as custom solutions rather than self-serve modules. They are scoped and configured per firm, so they do not appear as enabled entries in the menu even where your firm is in scope. Speak to your REGREP account manager if you report under any of them.

Professional Development

The Professional Development entry in the Solutions menu is delivered by EUCPD, a REGREP group company. Course content, certification and CPD records are EUCPD’s; access is provisioned through your REGREP account, and questions about course content go to EUCPD rather than the REGREP service desk.

Getting help

The Help menu
Figure 3 — The Help menu.
  • Documentation — this guide and the module guides.

  • Contact Support — raise a question with the REGREP team.

  • FAQs and Tutorials are shown greyed out because they are not yet published.

Knowing where you are

Inside a module, a breadcrumb sits above the page title showing the full path — for example "Regulatory Reporting / Prudential Reporting Engine / Pillar 1 - Capital Requirements". Inside a session, the left sidebar shows the session name and its key parameters, so you can confirm at a glance which reporting date and scope you are working on before you change anything.

Settings — configure this first

ImportantSettings feed the calculation engines directly. Fixed overheads, permanent minimum capital, thresholds, currency and corporate identifiers are all read from here when a session is created. Complete Settings before you create your first session, and re-check them whenever your firm's circumstances change.

Open Settings from the gear icon in the top-right of any screen. It is organised into three tabs.

Corporate Information

The identity and governance profile of the firm. These values populate DAC2, CRS and DORA exports, so accuracy matters beyond the screen itself.

Settings → Corporate Information
Figure 4 — Settings → Corporate Information.
  1. 1The three Settings tabs. Each tab saves independently.
  2. 2SAVE applies to the current tab only. Save before switching tabs.

The tab has three sections:

SectionContents
Corporate DetailsLegal entity name, LEI, type of entity, country of incorporation, company type, TIN, GIIN and FATCA filer status.
Contact InformationPrimary and secondary compliance contacts used for regulatory correspondence.
Address DetailsThe registered and mailing addresses of the legal entity.
NoteThe LEI field is validated as you type and will show "must be a valid LEI" until a well-formed 20-character identifier is entered. A value that fails validation can still be left in place, but downstream exports that require an LEI will carry the invalid value — check this field before generating any submission package.

Prudential Reporting Variables

The quantitative baselines the prudential calculation engine works from. Pillar 1, Pillar 2 and Pillar 3 all read this tab.

Settings → Prudential Reporting Variables, showing Entity Information and the start of Fixed Overheads
Figure 5 — Settings → Prudential Reporting Variables, showing Entity Information and the start of Fixed Overheads.
  1. 1The Prudential Reporting Variables tab.

The tab is divided into five sections:

SectionWhat it sets
Entity InformationIdentification code, accounting framework, functional and reporting currency, consolidating entity, permanent minimum capital (PMC), competent authority, licence number, date format and reporting scope (Solo, Consolidated, or both).
Fixed OverheadsPrior-year expense figures from which the Fixed Overhead Requirement (FOR) is derived. Shaded rows are calculated by the platform; white rows are yours to complete.
Threshold RequirementsOperational volume baselines across business activities — assets under management, client money held, client orders handled, daily trading flow, net position risk, on- and off-balance-sheet totals, and the annual gross revenue breakdown.
Trading LimitsInternal exposure limits of your own choosing, monitored on the Pillar 1 Analytics page.
AdjustmentsSupervisory overlays including Individual Capital Guidance (ICG) and Pillar 2 adjustments.
NoteReporting scope is a pair of checkboxes, not a single choice — a firm that reports both Solo and Consolidated can tick both, and then choose the scope per session.

Tax Reporting Variables

Jurisdiction-specific parameters for the tax reporting engines. The main control is Upload Country List, which accepts an .xlsx file defining the active tax jurisdictions and any custom country matrix your firm needs for cross-border reporting.

Saving your changes

ImportantEach tab has its own SAVE button in the top-right corner, and it saves only that tab. Moving between tabs does not save. Save each tab you have edited before leaving Settings, and always save before creating a new session — a session takes a copy of the settings as they stand at the moment it is created.

Which settings each module needs

ModuleRequired before you start
Pillar 1, 2 and 3Corporate Information (entity name, LEI) and the whole Prudential Reporting Variables tab.
DAC2, CRS, FATCACorporate Information in full — legal entity name, LEI, type of entity, country of incorporation, company type, TIN, GIIN and FATCA filer.
DORA ROICorporate Information — the entity metadata panel is populated from it.
TIN ValidationNone. The module works standalone.
EBA XBRL ConverterCorporate Information and the reporting currency from Prudential Reporting Variables.

Working with sessions

Most REGREP modules organise work into sessions. A session is one reporting cycle: a set of source data, the parameters that applied when it was created, everything the engine calculated from them, and the outputs generated. Sessions are independent of each other, so last quarter's figures are never disturbed by this quarter's work.

The session list

Opening a module lands you on its session list. If your firm has not created any sessions yet, the list is empty.

A module session list, using Pillar 1 as the example
Figure 6 — A module session list, using Pillar 1 as the example.
  1. 1Current Sessions — the active workspace.
  2. 2Archived Sessions — sessions that have been moved out of the active list. They remain readable here.
  3. 3Add (+) — creates a new session.
  4. 4Search and filter the list.
  5. 5Row actions: open the session, rename it, delete it.

Creating a session

Select the + button above the list. A dialog asks for the session parameters, which differ by module — the module guide sets them out. In every case, choosing the reporting date and scope correctly at this point matters, because the session inherits the Settings values that apply to them.

Once saved, you are taken into the session and the module's own workspace opens.

Renaming, archiving and deleting

Each row in the session list offers up to three actions, and the toolbar above offers archiving.

ActionEffectReversible?
OpenEnters the session workspace.n/a
RenameChanges the session's label only. No data or calculation is affected.Yes
ArchiveMoves the session out of Current Sessions and into the Archived Sessions tab, where it stays readable.No — a session cannot be returned to the active list
DeleteRemoves the session and its data from the system.No
Note

Warning — this cannot be undone

Deleting a session removes it permanently. Archiving moves a session to the Archived Sessions tab, where it can still be read, but it cannot be moved back to the active list. Neither action can be undone from the interface, and neither prompts a second confirmation beyond the initial dialog.

Before you delete or archive anything, be sure that no downstream session depends on it. A Pillar 3 disclosure draws its figures from a linked Pillar 1 and Pillar 2 session; removing a source session will leave the disclosure without the data behind it.

If a session supported a report that has been filed with a regulator, keep it. It is the evidence of what you submitted.

How sessions differ between modules

ModuleSession actionsArchivingVersioning
Pillar 1, 2, 3Open, rename, deleteYesNone — a restatement means a new session
DAC2, CRSOpen, deleteNoYes — 701 original and 702 correction, linked to a parent, with an auto-incrementing version
DORA ROIRegister entries rather than sessionsn/aBy reporting date

Your account and your team

Account Settings

Reached from the Dashboard or the profile menu. Holds your personal details, password and second-factor configuration.

Team Management

Where administrators invite colleagues, decide which modules each of them can open, restrict sign-in by IP address, and remove people who have left. Because the ability to delete sessions, archive them and generate submission packages follows from what a user is permitted to do, keeping this list current is a control in its own right, not housekeeping.

It has three tabs:

TabWhat it controls
UsersWho has an account, when they last signed in and from where.
IP WhitelistingWhich network addresses an account may sign in from.
Access ManagementWhich module areas each user can open — granted per user, per module.
NoteThe Administration guide covers all of this in full, including the limits of the permission model and what they mean for separating preparers from reviewers. Anyone administering REGREP for your firm should read it.

Account Security and Access Logs

The Dashboard shows your last sign-in, the IP address it came from, your MFA status and the number of failed sign-in attempts. Below that, User Access Logs record who did what and when; select See All for the full history.

Check the MFA status indicator on your own account. If it reads "Not Activated" while you are signing in with an authenticator code, raise it with support — the indicator and the enforcement should agree.

The Compliance Calendar

The Dashboard calendar is where reporting deadlines appear. If your calendar is empty, no deadlines have been configured for your firm yet; ask your REGREP account manager to have your reporting obligations loaded so that submission dates surface here rather than living in a spreadsheet.

Glossary

Terms and abbreviations used across the REGREP documentation set.

TermMeaning
ASAAssets Safeguarded and Administered. A K-Factor under Risk to Client.
AUMAssets Under Management. A K-Factor under Risk to Client.
AVAAdditional Valuation Adjustment. A deduction from own funds for prudent valuation.
CET1Common Equity Tier 1. The highest-quality component of regulatory capital.
CIFCritical or Important Function. A DORA concept for functions whose failure would materially impair the firm.
CMGClearing Margin Given. A K-Factor under Risk to Market.
CMHClient Money Held. A K-Factor under Risk to Client, split into segregated and non-segregated.
COHClient Orders Handled. A K-Factor under Risk to Client, split into cash trades and derivatives.
COREPCommon Reporting framework. The EBA's prudential reporting standard.
CRSCommon Reporting Standard. The OECD framework for automatic exchange of financial account information.
CVaRCredit Value at Risk. The potential credit loss at a stated confidence level.
DAC2The EU Directive on Administrative Cooperation, second amendment — automatic exchange of financial account information.
DORADigital Operational Resilience Act.
DTFDaily Trading Flow. A K-Factor under Risk to Firm.
EBAEuropean Banking Authority.
EWMAExponentially Weighted Moving Average. A volatility estimation method.
FATCAForeign Account Tax Compliance Act.
FORFixed Overhead Requirement. One quarter of the prior year's fixed overheads. Some screens abbreviate this as FOH.
GIINGlobal Intermediary Identification Number, issued for FATCA reporting.
ICARAInternal Capital and Risk Assessment. The Pillar 2 process.
ICGIndividual Capital Guidance. A supervisory capital overlay.
IFR / IFDInvestment Firms Regulation and Investment Firms Directive — the prudential regime for investment firms.
K-CONK-Concentration Risk. The own funds requirement for trading book exposures exceeding the limits in Article 37(1) IFR.
KFRK-Factor Requirement. The sum of all applicable K-Factors.
LEILegal Entity Identifier. A 20-character alphanumeric code identifying a legal entity.
MKRMarket Risk.
NPRNet Position Risk. A K-Factor under Risk to Market.
OpVaROperational Value at Risk.
PMCPermanent Minimum Capital. The fixed capital floor for the firm's class of authorisation.
ROIRegister of Information. The DORA register of ICT third-party contractual arrangements.
RtC / RtM / RtFRisk to Client, Risk to Market, Risk to Firm — the three K-Factor groupings.
SMASimple Moving Average. A volatility estimation method.
TCDTrading Counterparty Default. A K-Factor under Risk to Firm.
TINTax Identification Number.
TPPThird-Party Provider. Under DORA, a provider of ICT services.
VaRValue at Risk.
XBRLeXtensible Business Reporting Language. The format regulators use for structured submissions.

Document control

VersionDateChange
2.2January 2026AEOI, FATCA, CARF and DAC8 module guides added, bringing the documentation set to fourteen. The CRS guide no longer lists target jurisdictions individually. Adds the frameworks delivered as custom solutions, and the EUCPD attribution for Professional Development.
2.1January 2026Documentation set completed to ten guides. Team Management tabs documented and cross-referenced to the new Administration guide.
2.0January 2026New consolidated guide. Absorbs the navigation chapter previously repeated in six module manuals, and the Sign Up, Login and Settings guides. Settings documented as three tabs, replacing the older flat-list description. Adds module entitlement, session lifecycle, glossary and document control.
1.0Separate Sign Up, Login and Settings guides.

Report an error in this guide through Help → Contact Support.

REGREP is an independent software provider. This manual describes how to operate the platform and is not legal, tax or regulatory advice. Confirm scope, thresholds and submission dates with your competent authority before you file.

Other guides

The rest of the documentation set.

All documentation
Manual

DAC2

Preparing, validating and submitting financial account information under the EU automatic exchange framework.

Read the guide