SkarpSkarp

Chapter 11 of 11

Regulation 2025/532: Critical-Function ICT Subcontracting, Material Changes, and Termination

The collection culminates where outsourcing chains become most difficult to see and control: subcontracting beneath an ICT third-party provider. This final chapter consolidates the wider DORA control logic while examining subcontracting complexity, due diligence, contractual chain controls, material changes, termination rights, and continuing financial-entity accountability.

27 min readen

1. Orientation: Seeing the Full Subcontracting Chain

The hidden delivery chain

A financial entity may sign with one ICT provider, but delivery can depend on multiple downstream subcontractors. Regulation 2025/532 addresses the risks created by that indirect reliance.

Recital (1): identify the chain

Where the chain may be long or complex, Recital (1) says: "it is essential that financial entities identify the overall chain of subcontractors providing ICT services supporting critical or important functions."

Recital (2): focus attention

Financial entities "should focus in particular and continuously on those subcontractors that effectively underpin the ICT service that supports critical or important functions". This remains a recital-level should.

Status on 17 August 2026

The Regulation is in force. It was published on 2 July 2025 and entered into force on 22 July 2025. EUR-Lex records no end date.

2. Article 1: Proportionality Does Not Mean Superficiality

The Article 1 rule

Article 1 says financial entities shall take account of size, overall risk profile, and the nature, scale, and increased or reduced complexity of their services, activities, and operations.

Recital rationale versus Article duty

Recital (3) says "Financial entities vary widely in size, structure, internal organisation, and in the nature and complexity of their activities." Its proportionality statement uses should; Article 1 uses shall.

Map the chain and locations

The Article 1 assessment includes contract types, subcontractor and parent-company location, data shared, group links, and the length and complexity of the subcontracting chain.

Three operational risk tests

Article 1 expressly covers concentration at one or a few subcontractors, whether subcontracting impairs transferability to another provider, and the disruption impact on continuity and availability.

3. Worked Example: Applying Article 1 to a Cloud Payment Platform

The scenario

A payment institution contracts with Provider A. A uses B for database hosting, C for identity verification, and D for security monitoring. Each link can create a distinct operational dependency.

Apply Article 1, not a made-up score

Article 1 supplies required assessment elements, not a numeric score. The institution must consider services, locations, data, group relationships, oversight status, chain complexity, concentration, and transferability.

Location has two dimensions

The institution must distinguish where a service is actually provided from from where data are actually processed and stored. Those locations may differ across B, C, and D.

Concentration and exit

If B is the only database host, concentration matters. If replacing B requires major redesign, transferability matters. A failure scenario tests continuity and availability.

4. Article 2 and Article 3(1)(a)-(e): Group Control and Pre-Contract Gatekeeping

Article 2: consolidated consistency

Where the Regulation applies on a consolidated or sub-consolidated basis, the responsible parent undertaking shall ensure consistent implementation of subcontracting conditions across relevant group entities.

Intra-group is still subcontracting

Recital (5) says intra-group entities providing relevant ICT services or material parts thereof should be considered as ICT subcontractors, including specified entities in the same institutional protection scheme.

Decision before the contract

Under Article 3(1), the financial entity shall, before entering the provider contract, decide whether the provider may subcontract the relevant ICT service or material part.

Conditions (a)-(d)

The provider must be able to assess subcontractor capability, identify and disclose relevant subcontractors, pass through compliance support, and secure the same contractual access and inspection rights.

5. Article 3(1)(e)-(j): Capability, Risk Assessment, and Final Responsibility

Two capable monitors are required

Article 3 requires monitoring capability both at provider level and financial-entity level. A provider's monitoring programme does not replace the financial entity's own capability.

Financial entity capability

The financial entity needs sufficient expertise and financial, human, and technical resources, plus information security, risk management, incident response, business continuity management, and controls.

Risk questions (g)-(j)

Assess subcontractor failure, location risk, entity-level ICT concentration risk, and obstacles to audit, inspection, and access rights for authorities and the financial entity.

Periodic reassessment and accountability

Article 3(2) requires periodic reassessment against business-environment changes. Article 3(3) says reliance on provider risk assessments shall not limit the financial entity's final responsibility.

6. Flashcards: The Article 3 Control Logic

Flashcards

Flip each card and state the rule before checking the answer. Focus on who is responsible, when the assessment happens, and what must be assessed.

When must the financial entity decide whether subcontracting is permitted?
Before entering into the contractual arrangement with the ICT third-party service provider, under Article 3(1).
Who must identify all relevant subcontractors and notify the financial entity?
The ICT third-party service provider, under Article 3(1)(b).
What rights must the subcontractor grant under Article 3(1)(d)?
The same contractual rights of access and inspection as those granted by the ICT third-party service provider to the financial entity and competent and resolution authorities.
Which Article 3 risks are periodically reassessed?
The risk assessment in Article 3(1)(f) to (j), against possible changes in the business environment.
Can a financial entity transfer its final DORA responsibility by relying on its provider's assessment?
No. Article 3(3) states that reliance on the provider's risk assessment shall not limit the financial entity's final responsibility.

7. Article 4(1)(a)-(f): Make the Chain Contractually Visible

Eligible services and conditions

Article 4(1) says the contract shall identify which relevant ICT services or material parts are eligible for subcontracting and under which conditions. Blanket, undefined permission is not what Article 4 specifies.

Provider responsibility remains

The contract shall state that the ICT third-party service provider is responsible for services provided by subcontractors. Subcontracting does not erase the provider's delivery responsibility.

Continuous monitoring

The provider is required to monitor all relevant subcontracted services so its contractual obligations to the financial entity are continuously met. Monitoring and reporting obligations must be specified.

Location and reporting through tiers

Contract terms must cover location-risk assessment, relevant data-location information, and subcontractor monitoring and reporting duties towards the provider and, where agreed, the financial entity.

8. Article 4(1)(g)-(l) and Article 4(2): Continuity, Audit Rights, and Contract Remediation

Continuity through every tier

The provider must ensure continuity throughout the subcontractor chain if an ICT subcontractor fails to meet contractual obligations. The focus is the relevant ICT service, not only one contract link.

Contingency plans and security

Provider-subcontractor contracts must contain the referenced business-contingency requirements and related service levels, as well as the referenced ICT security standards and additional security requirements.

Equivalent audit rights

The subcontractor is to grant the financial entity and relevant competent and resolution authorities the same access, inspection, and audit rights referred to in DORA Article 30(3)(e).

Update contracts promptly

Necessary contractual changes shall be implemented in a timely manner and as soon as possible. The financial entity shall document its planned implementation timeline; Article 4(2) sets no numeric deadline.

9. Article 5: Material Changes Require Notice, Review, and Control

Step 1: meaningful advance notice

The provider shall inform the financial entity of intended material changes well in time. The purpose is to enable risk-impact assessment and assessment of the provider's continuing ability to meet obligations.

Step 2: a reasonable contractual period

The contract shall contain a reasonable notice period for approval or objection. Article 5 gives no universal numerical notice period, so the period must be set in the contract.

Step 3: no premature implementation

The provider shall only implement a material change after approval or after the financial entity has not objected by the end of the notice period.

Step 4: risk tolerance exceeded

If the financial entity considers the change to exceed its risk tolerance, it shall inform the provider, object, and request modifications before the notice period ends.

10. Worked Example: A Material Change and the Article 6 Exit Route

A proposed replacement

Provider A proposes a new database subcontractor. The bank must receive notice well in time and assess location, data, concentration, transferability, continuity, audit-access, and other relevant risks.

If risk tolerance is exceeded

Before the notice period ends, the bank shall inform Provider A, object, and request modifications. Provider A shall not implement until approval or no objection by the period's end.

Article 6 termination cases

The contract must give a termination right for implementation despite objection, implementation before the notice period ends without approval, or subcontracting not explicitly permitted by the contract.

Right to provide for termination

Article 6 does not say termination is automatic. It says the financial entity shall have the right to provide in the contractual arrangement that the arrangement is to terminate in each listed case.

11. Quiz: Article 3 Due Diligence and Accountability

Check your understanding

A financial entity receives a detailed subcontractor risk assessment from its ICT third-party service provider. The financial entity has not developed enough internal expertise or resources to monitor the subcontracted critical-function service itself. Which answer best reflects Article 3?

Which statement is correct?

  1. The provider's detailed assessment transfers the financial entity's responsibility, so internal monitoring capability is unnecessary.
  2. The financial entity must have sufficient abilities, expertise, and adequate financial, human, and technical resources to monitor the relevant ICT risks; reliance on the provider's assessment does not limit final responsibility.
  3. The financial entity only needs to reassess the provider if a regulator instructs it to do so.
  4. The financial entity may assess audit-access obstacles only after a subcontractor failure.
Show Answer

Answer: B) The financial entity must have sufficient abilities, expertise, and adequate financial, human, and technical resources to monitor the relevant ICT risks; reliance on the provider's assessment does not limit final responsibility.

Article 3(1)(f) requires the financial entity's own sufficient monitoring capability. Article 3(2) requires periodic reassessment of points (f) to (j), and Article 3(3) states that reliance on the provider's assessment shall not limit the financial entity's final responsibility.

12. Quiz: Notice Period, Objection, and Entry into Force

Final check

Select the answer that accurately combines Article 5, Article 6, and Article 7. Remember to distinguish a contractual termination right from automatic termination.

Which option is accurate?

  1. A provider may implement a material change as soon as it gives notice, unless the financial entity explicitly approves it.
  2. The Regulation fixes a 30-day notice period for all material changes and automatically terminates the contract if the provider breaches it.
  3. The contract shall contain a reasonable notice period; the provider shall only implement after approval or no objection by the end of that period; Article 6 requires a right to provide for termination in the listed cases.
  4. The Regulation entered into force on 24 March 2025 because that was the date it was adopted.
Show Answer

Answer: C) The contract shall contain a reasonable notice period; the provider shall only implement after approval or no objection by the end of that period; Article 6 requires a right to provide for termination in the listed cases.

Article 5(2) requires a reasonable contractual notice period, not a fixed 30-day period. Article 5(3) controls implementation. Article 6 requires the financial entity to have the right to provide contract termination in the specified cases. Article 7 states that entry into force was on the twentieth day following publication: publication was 2 July 2025 and entry into force was 22 July 2025.

Key Terms

Material part
A material component of an ICT service supporting a critical or important function; Regulation 2025/532 repeatedly applies its requirements to both the service and a material part thereof.
Notice period
The reasonable contractual period under Article 5(2) in which the financial entity is to approve or object to intended material subcontracting changes.
Risk tolerance
The financial entity's threshold used in Article 5(4): where it considers intended material changes to exceed this threshold, it shall inform the provider, object, and request modifications before the notice period ends.
Transferability
Whether subcontracting would affect the ability to move relevant ICT services to another ICT third-party service provider, an Article 1 assessment element.
ICT subcontractor
A downstream provider supplying ICT services supporting critical or important functions or material parts thereof. Recital (5) indicates that relevant intra-group providers should be considered ICT subcontractors.
Concentration risk
Risk arising where relevant ICT services are concentrated at one subcontractor or a small number of subcontractors; Article 1 requires it to be taken into account and Article 3 refers to entity-level ICT concentration risk under DORA Article 29.
Final responsibility
The financial entity's continuing legal and regulatory responsibility. Article 3(3) says provider risk assessments shall not limit it.
Equivalent audit rights
The downstream requirement that a subcontractor grant the financial entity and relevant competent and resolution authorities the same access, inspection, and audit rights referred to in DORA Article 30(3)(e).
Critical or important function
The category of function used throughout Regulation 2025/532 to determine when the specific subcontracting assessment and contractual rules apply.
ICT third-party service provider
The provider contracted by the financial entity to provide ICT services; under Article 4, it remains responsible for services delivered by its subcontractors.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself