SkarpSkarp

Chapter 4 of 15

DORA Regulation (EU) 2022/2554 — Contracts and Critical ICT Provider Oversight

Outsourcing technology does not outsource regulatory responsibility. These recitals map the safeguards expected before, during, and after ICT contracts and justify Union oversight where provider concentration becomes systemically important.

24 min readen

1. Why DORA Regulates ICT Contracts

The central problem

DORA treats external ICT dependence as a resilience issue: a provider failure, cyber incident, or inability to restore services can affect delivery of financial services.

Recital (62)

Recital (62) calls for principle-based rules to guide monitoring of risk from outsourced ICT functions, particularly services supporting critical or important functions.

Read the legal language carefully

These are recitals. Their "should" statements explain the Regulation's approach; this lesson does not upgrade them into mandatory "shall" obligations.

2. Who Counts as an ICT Third-Party Service Provider?

Express examples

Recital (63) includes cloud computing, software, data analytics, and data-centre providers within the wide range of ICT third-party service providers.

Group arrangements still matter

An undertaking serving mainly its parent, the parent's subsidiaries or branches can be an ICT third-party service provider. Financial entities serving other financial entities can be one too.

Payment ecosystem and exceptions

Payment processors and payment-infrastructure operators should be included, except central banks operating payment or securities settlement systems and public authorities fulfilling State functions.

3. Responsibility, Proportionality, Strategy, and the Register

Continuing responsibility

"A financial entity should at all times remain fully responsible for complying with its obligations set out in this Regulation." Contracting out ICT does not remove that responsibility.

Proportionate monitoring

Recital (64) links monitoring intensity to dependencies' nature, scale, complexity, and importance; the function's criticality; and effects on continuity and quality of services.

Strategy and register

The management body should adopt a dedicated strategy based on continuous screening. The register covers all contractual arrangements for ICT services from ICT third-party providers.

4. Pre-Contracting Analysis and When Termination May Be Prompted

Before formal conclusion

A thorough pre-contracting analysis should come before the contract. It should examine criticality, approvals or conditions, concentration risk, due diligence, and conflicts of interest.

Critical or important functions

For these contracts, the financial entity should take into consideration whether the provider uses the most up-to-date and highest information security standards.

Termination triggers

Termination could be prompted by significant legal or contractual breaches, impaired performance, weak ICT risk management, or ineffective supervision by the competent authority.

5. Concentration Risk: Serious Assessment, but No Rigid Caps

What concentration means

Concentration risk arises where reliance on the same provider can make a single operational disruption affect multiple important functions, firms, or markets.

No strict caps

"it is not considered appropriate to set out rules on strict caps and limits to ICT third-party exposures". This is not permission to ignore concentration.

Lead Overseer focus

For critical providers, the Lead Overseer should assess interdependencies, identify Union-wide stability risks from high concentration, and maintain dialogue where that risk is identified.

6. Contract Content for All ICT Services

Why harmonise contract elements?

Recital (68) links harmonisation to regular monitoring of secure service delivery and to a financial entity's dependence on service stability, functionality, availability, and security.

Baseline information

Regardless of criticality, contracts should describe functions and services completely, identify service and data-processing locations, and state service-level descriptions.

Data, incidents, authorities, exit

Contracts should cover data access, recovery, and return; incident assistance; full cooperation with authorities; and termination rights with related minimum notice periods.

7. Additional Protections for Critical or Important Functions

Measurable service control

Critical-or-important-function contracts should state precise quantitative and qualitative performance targets, plus notices and reporting for developments with potential material impact.

Resilience duties in the contract

The provider should implement and test contingency plans, maintain secure-service measures, tools, and policies, and participate and fully cooperate in the entity's TLPT.

Audit and exit

"provisions enabling the rights of access, inspection and audit by the financial entity, or an appointed third party, and the right to take copies" are crucial monitoring instruments.

Resolution resilience

For entities within Directive 2014/59/EU, contracts should remain enforceable in resolution and, while payments continue, include non-termination, non-suspension, and non-modification clauses.

8. Worked Contract Review: A Core Banking Cloud Migration

Scenario

A retail bank moves payment processing and transaction-data storage to a cloud platform. Because the platform supports a critical or important function, both baseline and additional protections matter.

Before signing

The bank should assess criticality, supervisory conditions, concentration, due diligence, conflicts, and security standards; then record the arrangement and continuously screen the dependency.

Contract design

It should specify services, locations, data safeguards, recovery and return, incident assistance, authority cooperation, measurable targets, notifications, contingencies, security, and TLPT cooperation.

Control and exit

The bank should retain audit and copy-taking rights and build a transition-capable exit strategy. The provider's contractual role does not displace the bank's continuing responsibility.

9. The Union Oversight Framework and Criticality

Framework purpose

The Union Oversight Framework should promote supervisory convergence and resilience where critical ICT providers support financial-service delivery and can affect system stability.

Designation and opt-in

Only critical providers should be covered. Designation should use quantitative and qualitative criteria and assess the entire group structure; non-automatic providers should be able to opt in.

Exemptions

Recital (78) identifies exemptions for certain financial-entity providers, predominantly intra-group providers, and strictly single-Member-State providers serving entities active only there.

Why cooperation matters

Cyber disruption can propagate quickly. Oversight depends on monitoring, inspections, and provider cooperation; refusal of access or information can justify a commensurate sanctioning regime.

10. Third-Country Critical Providers: Union Presence Without Data Localisation

The 12-month incorporation point

A third-country provider designated critical that continues serving Union financial entities should undertake "within 12 months of such designation, all necessary arrangements to ensure its incorporation within the Union".

No data-localisation rule

"This Regulation does not impose a data localisation obligation as it does not require data storage or processing to be undertaken in the Union." Incorporation is not a storage mandate.

Oversight outside the Union

Where Union-based activity is insufficient, the Lead Overseer should be able to act in third countries, subject to conditions including provider consent, no objection by authorities, and cooperation arrangements.

11. Flashcards: Contracting and Oversight Vocabulary

Flip each card, answer from memory, then compare your answer with the recital-based explanation.

Continuing responsibility
Recital (64): "A financial entity should at all times remain fully responsible for complying with its obligations set out in this Regulation."
Register of information
Recital (65) says all financial entities should be required to maintain it with all contractual arrangements concerning ICT services provided by ICT third-party service providers.
Concentration-risk approach
Financial entities should thoroughly assess concentration risk, including subcontracting; Recital (67) says strict caps and limits to ICT third-party exposures are not considered appropriate.
Audit rights for critical or important functions
Contracts should contain access, inspection, audit, and copy-taking rights for the financial entity or an appointed third party, with provider cooperation.
Third-country critical provider deadline
Within 12 months of designation, it should undertake all necessary arrangements to ensure incorporation within the Union by establishing a subsidiary.
Data localisation
DORA does not impose a data localisation obligation: it does not require data storage or processing to occur in the Union.

12. Quiz: Identify the Accurate Recital Statement

Select the statement that accurately reflects Recitals (67), (81), and (82).

Which statement is accurate?

  1. DORA sets strict numerical caps on every financial entity's exposure to an ICT third-party provider.
  2. A third-country provider designated as critical must move all data storage and processing into the Union within 12 months.
  3. A designated critical third-country provider that continues serving Union financial entities should undertake, within 12 months of designation, arrangements for incorporation within the Union; this does not create a data localisation obligation.
  4. A financial entity ceases to be responsible for DORA compliance once an ICT service is outsourced under a detailed contract.
Show Answer

Answer: C) A designated critical third-country provider that continues serving Union financial entities should undertake, within 12 months of designation, arrangements for incorporation within the Union; this does not create a data localisation obligation.

Recital (67) says strict caps and limits are not considered appropriate. Recital (81) gives the 12-month incorporation point for a designated critical third-country provider. Recital (82) expressly says DORA does not impose a data localisation obligation. Recital (64) preserves the financial entity's continuing responsibility.

Key Terms

TLPT
Threat-led penetration testing. Recital (72) says providers supporting critical or important functions should participate and fully cooperate in the TLPT carried out by the financial entity.
Lead Overseer
The overseer appointed under DORA that should monitor critical ICT third-party service providers and, where relevant, assess interdependencies and concentration-related systemic risk.
exit strategy
Contractual arrangements designed to reduce disruption when an ICT service ends, including transition periods that can support a move to another provider or an in-house solution.
concentration risk
Risk associated with dependence on one or a small number of ICT providers, including risk arising through subcontracting and potentially affecting financial-system stability.
ICT third-party risk
Risk arising from a financial entity's dependencies on ICT services provided by ICT third-party service providers.
resolution resilient
For financial entities within Directive 2014/59/EU's scope, the quality of ICT contracts being robust and fully enforceable in resolution, including specified protections against termination, suspension, or modification where payment obligations continue.
register of information
The record that Recital (65) says all financial entities should be required to maintain, covering all contractual arrangements for ICT services supplied by ICT third-party service providers.
data localisation obligation
A requirement that data be stored or processed in a particular territory. Recital (82) states that DORA does not impose such an obligation requiring storage or processing in the Union.
critical or important function
A DORA concept used to identify functions requiring heightened contractual protections; Recital (70) states that it encompasses critical functions under Article 2(1), point (35), of Directive 2014/59/EU.
ICT third-party service provider
A broad category described in Recital (63), including providers of cloud computing, software, data analytics, and data-centre services, as well as specified intra-group and payment-ecosystem providers.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself