Free tool · No account needed

LEI validator for the Register of Information

Every ICT third-party provider in your DORA register needs a valid LEI, and a mistyped one fails at submission rather than at review. Paste a whole column and this checks the ISO 17442 structure and the MOD 97-10 check digits on every code at once — and finds the duplicates.

ISO 17442 · MOD 97-10 check digits · bulk paste · duplicate detection · nothing stored

Validate a list of LEIs

Runs in your browser · nothing uploaded

One LEI per line, or separated by commas, semicolons or tabs — paste a column straight out of a spreadsheet. Case and spacing are normalised for you. Nothing is transmitted; the check digit maths runs entirely on your machine.

0 codes detected
What this means: a structural and check-digit result only. A code can be perfectly formed and still be wrong for your register — it may belong to a different entity, or its registration may have lapsed. This tool does not query the Global LEI Index and cannot tell you whether a code is issued, active, or attached to the provider you think it is. Confirm each one against the GLEIF record before you submit.

A structurally valid LEI is the low bar. The DORA module keeps your Register of Information, resolves the entity and subcontracting chain, runs the validation checks and produces the XBRL-CSV package — with free record keeping and validation to start.

Create free account
Structure

Twenty characters, four blocks

The last two do the work. They are computed from the first eighteen, so a mistyped or transposed character breaks the code before anything else notices.

Characters 1–4

LOU prefix

Identifies the Local Operating Unit that issued the code. It carries no geography — a 5493 prefix tells you the issuer, not the country of the entity.

Characters 5–18

Reserved and entity part

Positions 5 and 6 are reserved and set to zero on codes issued under the standard. Positions 7 to 18 are assigned by the issuer and deliberately carry no meaning, so the code survives a rename or relocation.

Characters 19–20

Check digits

Computed over the first eighteen characters using ISO/IEC 7064 MOD 97-10 — the same scheme as an IBAN. Letters convert to numbers, and a valid code leaves a remainder of one when divided by 97.

Rules reviewed 21 August 2026 · ISO 17442 · ISO/IEC 7064 MOD 97-10 · DORA Art. 28(3) and Commission Implementing Regulation (EU) 2024/2956

Scope

What this validator does

It catches transcription errors before they reach a submission. It is not a registry lookup, and the difference matters.

It doesCheck structure and arithmetic

  • Confirms each code is exactly twenty characters, uppercase letters and digits only.
  • Verifies the MOD 97-10 check digits over the first eighteen characters.
  • Catches transposed pairs and single-character errors, which are what check digits exist for.
  • Flags duplicate codes across the list — a common register defect where one provider is entered twice.
  • Notes where the reserved positions are not zero, which is normal on legacy codes but unusual on recent ones.
  • Normalises case, spaces and separators so a spreadsheet column pastes straight in.

It does notLook anything up

  • Query the Global LEI Index. No registry call is made from this page.
  • Tell you whether a code has been issued, or whether it is active, lapsed or retired.
  • Confirm the code belongs to the entity you think it does.
  • Resolve parent, subsidiary or subcontracting relationships.
  • Validate any other field in your Register of Information.
  • Produce anything you can submit. It is a check, not a register.

A lapsed LEI passes this check

Check digits never expire; registrations do. A code can be mathematically perfect and still be a problem in your register if the provider stopped renewing it. That is a lookup against the Global LEI Index, and it is worth doing on every provider before you submit.

See DORA Register of Information

Nothing you paste here leaves your browser

The check digit calculation runs entirely on your own machine. No code you paste is sent to REGREP, to GLEIF, or to anyone else. Nothing is written to a log, saved to a database, or passed to any analytics tool.

That is deliberate. A list of your ICT providers is a map of your dependencies, and it is not something we want to hold.

Questions

About LEIs and the register

Why do LEIs matter for the Register of Information?

Article 28(3) requires financial entities to maintain a register covering all contractual arrangements for ICT services, reported to the competent authority using the templates in Commission Implementing Regulation (EU) 2024/2956. Entities in that register are identified by LEI, so a malformed or missing code is a validation failure at submission rather than a comment at review.

How do the check digits work?

Positions 19 and 20 are computed from the first eighteen characters using ISO/IEC 7064 MOD 97-10, the same algorithm as an IBAN. Letters are converted to numbers with A as 10 through Z as 35, the whole string is read as one long integer, and a valid code leaves a remainder of one when divided by 97. A single mistyped character or a transposed pair breaks that result.

My code has letters at positions 5 and 6. Is it wrong?

Probably not. Positions 5 and 6 are reserved and set to zero for codes issued under the standard, but a number of early codes were grandfathered into the global system from predecessor schemes and do not follow that convention. This tool notes it rather than treating it as an error, because a legacy code with valid check digits is a valid LEI.

Does a valid check digit mean the LEI is fine?

No, and this is the distinction that matters. Check digits confirm the code was transcribed correctly. They say nothing about whether it was ever issued, whether the registration is still active, or whether it belongs to the provider you have in mind. A lapsed LEI passes this check and still causes problems, so verify each one against the Global LEI Index.

Why does the tool flag duplicates?

Because the same provider entered twice under slightly different names is one of the more common register defects, and the LEI is what exposes it. Duplicates are not necessarily wrong — a single provider can legitimately appear against several contractual arrangements — but they are worth a look before you submit.

Do you store the codes I paste?

No. Everything runs in your browser and is discarded when you close or reload the page. No lookup is performed, so the codes are not sent anywhere at all.

Valid codes are the start of a register, not the end.

Create a free account and keep every ICT arrangement, its provider chain and its criticality flag in one place — validated before it goes anywhere.

No card required · free record keeping and validation · nothing stored from this validator