Chapter 11 of 11
Regulation 2025/532: Critical-Function ICT Subcontracting, Material Changes, and Termination
The collection culminates where outsourcing chains become most difficult to see and control: subcontracting beneath an ICT third-party provider. This final chapter consolidates the wider DORA control logic while examining subcontracting complexity, due diligence, contractual chain controls, material changes, termination rights, and continuing financial-entity accountability.
1. Orientation: Seeing the Full Subcontracting Chain
The hidden delivery chain
A financial entity may sign with one ICT provider, but delivery can depend on multiple downstream subcontractors. Regulation 2025/532 addresses the risks created by that indirect reliance.
Recital (1): identify the chain
Where the chain may be long or complex, Recital (1) says: "it is essential that financial entities identify the overall chain of subcontractors providing ICT services supporting critical or important functions."
Recital (2): focus attention
Financial entities "should focus in particular and continuously on those subcontractors that effectively underpin the ICT service that supports critical or important functions". This remains a recital-level should.
Status on 17 August 2026
The Regulation is in force. It was published on 2 July 2025 and entered into force on 22 July 2025. EUR-Lex records no end date.
2. Article 1: Proportionality Does Not Mean Superficiality
The Article 1 rule
Article 1 says financial entities shall take account of size, overall risk profile, and the nature, scale, and increased or reduced complexity of their services, activities, and operations.
Recital rationale versus Article duty
Recital (3) says "Financial entities vary widely in size, structure, internal organisation, and in the nature and complexity of their activities." Its proportionality statement uses should; Article 1 uses shall.
Map the chain and locations
The Article 1 assessment includes contract types, subcontractor and parent-company location, data shared, group links, and the length and complexity of the subcontracting chain.
Three operational risk tests
Article 1 expressly covers concentration at one or a few subcontractors, whether subcontracting impairs transferability to another provider, and the disruption impact on continuity and availability.
3. Worked Example: Applying Article 1 to a Cloud Payment Platform
The scenario
A payment institution contracts with Provider A. A uses B for database hosting, C for identity verification, and D for security monitoring. Each link can create a distinct operational dependency.
Apply Article 1, not a made-up score
Article 1 supplies required assessment elements, not a numeric score. The institution must consider services, locations, data, group relationships, oversight status, chain complexity, concentration, and transferability.
Location has two dimensions
The institution must distinguish where a service is actually provided from from where data are actually processed and stored. Those locations may differ across B, C, and D.
Concentration and exit
If B is the only database host, concentration matters. If replacing B requires major redesign, transferability matters. A failure scenario tests continuity and availability.
4. Article 2 and Article 3(1)(a)-(e): Group Control and Pre-Contract Gatekeeping
Article 2: consolidated consistency
Where the Regulation applies on a consolidated or sub-consolidated basis, the responsible parent undertaking shall ensure consistent implementation of subcontracting conditions across relevant group entities.
Intra-group is still subcontracting
Recital (5) says intra-group entities providing relevant ICT services or material parts thereof should be considered as ICT subcontractors, including specified entities in the same institutional protection scheme.
Decision before the contract
Under Article 3(1), the financial entity shall, before entering the provider contract, decide whether the provider may subcontract the relevant ICT service or material part.
Conditions (a)-(d)
The provider must be able to assess subcontractor capability, identify and disclose relevant subcontractors, pass through compliance support, and secure the same contractual access and inspection rights.
5. Article 3(1)(e)-(j): Capability, Risk Assessment, and Final Responsibility
Two capable monitors are required
Article 3 requires monitoring capability both at provider level and financial-entity level. A provider's monitoring programme does not replace the financial entity's own capability.
Financial entity capability
The financial entity needs sufficient expertise and financial, human, and technical resources, plus information security, risk management, incident response, business continuity management, and controls.
Risk questions (g)-(j)
Assess subcontractor failure, location risk, entity-level ICT concentration risk, and obstacles to audit, inspection, and access rights for authorities and the financial entity.
Periodic reassessment and accountability
Article 3(2) requires periodic reassessment against business-environment changes. Article 3(3) says reliance on provider risk assessments shall not limit the financial entity's final responsibility.
6. Flashcards: The Article 3 Control Logic
Flashcards
Flip each card and state the rule before checking the answer. Focus on who is responsible, when the assessment happens, and what must be assessed.
- When must the financial entity decide whether subcontracting is permitted?
- Before entering into the contractual arrangement with the ICT third-party service provider, under Article 3(1).
- Who must identify all relevant subcontractors and notify the financial entity?
- The ICT third-party service provider, under Article 3(1)(b).
- What rights must the subcontractor grant under Article 3(1)(d)?
- The same contractual rights of access and inspection as those granted by the ICT third-party service provider to the financial entity and competent and resolution authorities.
- Which Article 3 risks are periodically reassessed?
- The risk assessment in Article 3(1)(f) to (j), against possible changes in the business environment.
- Can a financial entity transfer its final DORA responsibility by relying on its provider's assessment?
- No. Article 3(3) states that reliance on the provider's risk assessment shall not limit the financial entity's final responsibility.
7. Article 4(1)(a)-(f): Make the Chain Contractually Visible
Eligible services and conditions
Article 4(1) says the contract shall identify which relevant ICT services or material parts are eligible for subcontracting and under which conditions. Blanket, undefined permission is not what Article 4 specifies.
Provider responsibility remains
The contract shall state that the ICT third-party service provider is responsible for services provided by subcontractors. Subcontracting does not erase the provider's delivery responsibility.
Continuous monitoring
The provider is required to monitor all relevant subcontracted services so its contractual obligations to the financial entity are continuously met. Monitoring and reporting obligations must be specified.
Location and reporting through tiers
Contract terms must cover location-risk assessment, relevant data-location information, and subcontractor monitoring and reporting duties towards the provider and, where agreed, the financial entity.
8. Article 4(1)(g)-(l) and Article 4(2): Continuity, Audit Rights, and Contract Remediation
Continuity through every tier
The provider must ensure continuity throughout the subcontractor chain if an ICT subcontractor fails to meet contractual obligations. The focus is the relevant ICT service, not only one contract link.
Contingency plans and security
Provider-subcontractor contracts must contain the referenced business-contingency requirements and related service levels, as well as the referenced ICT security standards and additional security requirements.
Equivalent audit rights
The subcontractor is to grant the financial entity and relevant competent and resolution authorities the same access, inspection, and audit rights referred to in DORA Article 30(3)(e).
Update contracts promptly
Necessary contractual changes shall be implemented in a timely manner and as soon as possible. The financial entity shall document its planned implementation timeline; Article 4(2) sets no numeric deadline.
9. Article 5: Material Changes Require Notice, Review, and Control
Step 1: meaningful advance notice
The provider shall inform the financial entity of intended material changes well in time. The purpose is to enable risk-impact assessment and assessment of the provider's continuing ability to meet obligations.
Step 2: a reasonable contractual period
The contract shall contain a reasonable notice period for approval or objection. Article 5 gives no universal numerical notice period, so the period must be set in the contract.
Step 3: no premature implementation
The provider shall only implement a material change after approval or after the financial entity has not objected by the end of the notice period.
Step 4: risk tolerance exceeded
If the financial entity considers the change to exceed its risk tolerance, it shall inform the provider, object, and request modifications before the notice period ends.
10. Worked Example: A Material Change and the Article 6 Exit Route
A proposed replacement
Provider A proposes a new database subcontractor. The bank must receive notice well in time and assess location, data, concentration, transferability, continuity, audit-access, and other relevant risks.
If risk tolerance is exceeded
Before the notice period ends, the bank shall inform Provider A, object, and request modifications. Provider A shall not implement until approval or no objection by the period's end.
Article 6 termination cases
The contract must give a termination right for implementation despite objection, implementation before the notice period ends without approval, or subcontracting not explicitly permitted by the contract.
Right to provide for termination
Article 6 does not say termination is automatic. It says the financial entity shall have the right to provide in the contractual arrangement that the arrangement is to terminate in each listed case.
11. Quiz: Article 3 Due Diligence and Accountability
Check your understanding
A financial entity receives a detailed subcontractor risk assessment from its ICT third-party service provider. The financial entity has not developed enough internal expertise or resources to monitor the subcontracted critical-function service itself. Which answer best reflects Article 3?
Which statement is correct?
- The provider's detailed assessment transfers the financial entity's responsibility, so internal monitoring capability is unnecessary.
- The financial entity must have sufficient abilities, expertise, and adequate financial, human, and technical resources to monitor the relevant ICT risks; reliance on the provider's assessment does not limit final responsibility.
- The financial entity only needs to reassess the provider if a regulator instructs it to do so.
- The financial entity may assess audit-access obstacles only after a subcontractor failure.
Show Answer
Answer: B) The financial entity must have sufficient abilities, expertise, and adequate financial, human, and technical resources to monitor the relevant ICT risks; reliance on the provider's assessment does not limit final responsibility.
Article 3(1)(f) requires the financial entity's own sufficient monitoring capability. Article 3(2) requires periodic reassessment of points (f) to (j), and Article 3(3) states that reliance on the provider's assessment shall not limit the financial entity's final responsibility.
12. Quiz: Notice Period, Objection, and Entry into Force
Final check
Select the answer that accurately combines Article 5, Article 6, and Article 7. Remember to distinguish a contractual termination right from automatic termination.
Which option is accurate?
- A provider may implement a material change as soon as it gives notice, unless the financial entity explicitly approves it.
- The Regulation fixes a 30-day notice period for all material changes and automatically terminates the contract if the provider breaches it.
- The contract shall contain a reasonable notice period; the provider shall only implement after approval or no objection by the end of that period; Article 6 requires a right to provide for termination in the listed cases.
- The Regulation entered into force on 24 March 2025 because that was the date it was adopted.
Show Answer
Answer: C) The contract shall contain a reasonable notice period; the provider shall only implement after approval or no objection by the end of that period; Article 6 requires a right to provide for termination in the listed cases.
Article 5(2) requires a reasonable contractual notice period, not a fixed 30-day period. Article 5(3) controls implementation. Article 6 requires the financial entity to have the right to provide contract termination in the specified cases. Article 7 states that entry into force was on the twentieth day following publication: publication was 2 July 2025 and entry into force was 22 July 2025.
Key Terms
- Material part
- A material component of an ICT service supporting a critical or important function; Regulation 2025/532 repeatedly applies its requirements to both the service and a material part thereof.
- Notice period
- The reasonable contractual period under Article 5(2) in which the financial entity is to approve or object to intended material subcontracting changes.
- Risk tolerance
- The financial entity's threshold used in Article 5(4): where it considers intended material changes to exceed this threshold, it shall inform the provider, object, and request modifications before the notice period ends.
- Transferability
- Whether subcontracting would affect the ability to move relevant ICT services to another ICT third-party service provider, an Article 1 assessment element.
- ICT subcontractor
- A downstream provider supplying ICT services supporting critical or important functions or material parts thereof. Recital (5) indicates that relevant intra-group providers should be considered ICT subcontractors.
- Concentration risk
- Risk arising where relevant ICT services are concentrated at one subcontractor or a small number of subcontractors; Article 1 requires it to be taken into account and Article 3 refers to entity-level ICT concentration risk under DORA Article 29.
- Final responsibility
- The financial entity's continuing legal and regulatory responsibility. Article 3(3) says provider risk assessments shall not limit it.
- Equivalent audit rights
- The downstream requirement that a subcontractor grant the financial entity and relevant competent and resolution authorities the same access, inspection, and audit rights referred to in DORA Article 30(3)(e).
- Critical or important function
- The category of function used throughout Regulation 2025/532 to determine when the specific subcontracting assessment and contractual rules apply.
- ICT third-party service provider
- The provider contracted by the financial entity to provide ICT services; under Article 4, it remains responsible for services delivered by its subcontractors.