Chapter 4 of 15
DORA Regulation (EU) 2022/2554 — Contracts and Critical ICT Provider Oversight
Outsourcing technology does not outsource regulatory responsibility. These recitals map the safeguards expected before, during, and after ICT contracts and justify Union oversight where provider concentration becomes systemically important.
1. Why DORA Regulates ICT Contracts
The central problem
DORA treats external ICT dependence as a resilience issue: a provider failure, cyber incident, or inability to restore services can affect delivery of financial services.
Recital (62)
Recital (62) calls for principle-based rules to guide monitoring of risk from outsourced ICT functions, particularly services supporting critical or important functions.
Read the legal language carefully
These are recitals. Their "should" statements explain the Regulation's approach; this lesson does not upgrade them into mandatory "shall" obligations.
2. Who Counts as an ICT Third-Party Service Provider?
Express examples
Recital (63) includes cloud computing, software, data analytics, and data-centre providers within the wide range of ICT third-party service providers.
Group arrangements still matter
An undertaking serving mainly its parent, the parent's subsidiaries or branches can be an ICT third-party service provider. Financial entities serving other financial entities can be one too.
Payment ecosystem and exceptions
Payment processors and payment-infrastructure operators should be included, except central banks operating payment or securities settlement systems and public authorities fulfilling State functions.
3. Responsibility, Proportionality, Strategy, and the Register
Continuing responsibility
"A financial entity should at all times remain fully responsible for complying with its obligations set out in this Regulation." Contracting out ICT does not remove that responsibility.
Proportionate monitoring
Recital (64) links monitoring intensity to dependencies' nature, scale, complexity, and importance; the function's criticality; and effects on continuity and quality of services.
Strategy and register
The management body should adopt a dedicated strategy based on continuous screening. The register covers all contractual arrangements for ICT services from ICT third-party providers.
4. Pre-Contracting Analysis and When Termination May Be Prompted
Before formal conclusion
A thorough pre-contracting analysis should come before the contract. It should examine criticality, approvals or conditions, concentration risk, due diligence, and conflicts of interest.
Critical or important functions
For these contracts, the financial entity should take into consideration whether the provider uses the most up-to-date and highest information security standards.
Termination triggers
Termination could be prompted by significant legal or contractual breaches, impaired performance, weak ICT risk management, or ineffective supervision by the competent authority.
5. Concentration Risk: Serious Assessment, but No Rigid Caps
What concentration means
Concentration risk arises where reliance on the same provider can make a single operational disruption affect multiple important functions, firms, or markets.
No strict caps
"it is not considered appropriate to set out rules on strict caps and limits to ICT third-party exposures". This is not permission to ignore concentration.
Lead Overseer focus
For critical providers, the Lead Overseer should assess interdependencies, identify Union-wide stability risks from high concentration, and maintain dialogue where that risk is identified.
6. Contract Content for All ICT Services
Why harmonise contract elements?
Recital (68) links harmonisation to regular monitoring of secure service delivery and to a financial entity's dependence on service stability, functionality, availability, and security.
Baseline information
Regardless of criticality, contracts should describe functions and services completely, identify service and data-processing locations, and state service-level descriptions.
Data, incidents, authorities, exit
Contracts should cover data access, recovery, and return; incident assistance; full cooperation with authorities; and termination rights with related minimum notice periods.
7. Additional Protections for Critical or Important Functions
Measurable service control
Critical-or-important-function contracts should state precise quantitative and qualitative performance targets, plus notices and reporting for developments with potential material impact.
Resilience duties in the contract
The provider should implement and test contingency plans, maintain secure-service measures, tools, and policies, and participate and fully cooperate in the entity's TLPT.
Audit and exit
"provisions enabling the rights of access, inspection and audit by the financial entity, or an appointed third party, and the right to take copies" are crucial monitoring instruments.
Resolution resilience
For entities within Directive 2014/59/EU, contracts should remain enforceable in resolution and, while payments continue, include non-termination, non-suspension, and non-modification clauses.
8. Worked Contract Review: A Core Banking Cloud Migration
Scenario
A retail bank moves payment processing and transaction-data storage to a cloud platform. Because the platform supports a critical or important function, both baseline and additional protections matter.
Before signing
The bank should assess criticality, supervisory conditions, concentration, due diligence, conflicts, and security standards; then record the arrangement and continuously screen the dependency.
Contract design
It should specify services, locations, data safeguards, recovery and return, incident assistance, authority cooperation, measurable targets, notifications, contingencies, security, and TLPT cooperation.
Control and exit
The bank should retain audit and copy-taking rights and build a transition-capable exit strategy. The provider's contractual role does not displace the bank's continuing responsibility.
9. The Union Oversight Framework and Criticality
Framework purpose
The Union Oversight Framework should promote supervisory convergence and resilience where critical ICT providers support financial-service delivery and can affect system stability.
Designation and opt-in
Only critical providers should be covered. Designation should use quantitative and qualitative criteria and assess the entire group structure; non-automatic providers should be able to opt in.
Exemptions
Recital (78) identifies exemptions for certain financial-entity providers, predominantly intra-group providers, and strictly single-Member-State providers serving entities active only there.
Why cooperation matters
Cyber disruption can propagate quickly. Oversight depends on monitoring, inspections, and provider cooperation; refusal of access or information can justify a commensurate sanctioning regime.
10. Third-Country Critical Providers: Union Presence Without Data Localisation
The 12-month incorporation point
A third-country provider designated critical that continues serving Union financial entities should undertake "within 12 months of such designation, all necessary arrangements to ensure its incorporation within the Union".
No data-localisation rule
"This Regulation does not impose a data localisation obligation as it does not require data storage or processing to be undertaken in the Union." Incorporation is not a storage mandate.
Oversight outside the Union
Where Union-based activity is insufficient, the Lead Overseer should be able to act in third countries, subject to conditions including provider consent, no objection by authorities, and cooperation arrangements.
11. Flashcards: Contracting and Oversight Vocabulary
Flip each card, answer from memory, then compare your answer with the recital-based explanation.
- Continuing responsibility
- Recital (64): "A financial entity should at all times remain fully responsible for complying with its obligations set out in this Regulation."
- Register of information
- Recital (65) says all financial entities should be required to maintain it with all contractual arrangements concerning ICT services provided by ICT third-party service providers.
- Concentration-risk approach
- Financial entities should thoroughly assess concentration risk, including subcontracting; Recital (67) says strict caps and limits to ICT third-party exposures are not considered appropriate.
- Audit rights for critical or important functions
- Contracts should contain access, inspection, audit, and copy-taking rights for the financial entity or an appointed third party, with provider cooperation.
- Third-country critical provider deadline
- Within 12 months of designation, it should undertake all necessary arrangements to ensure incorporation within the Union by establishing a subsidiary.
- Data localisation
- DORA does not impose a data localisation obligation: it does not require data storage or processing to occur in the Union.
12. Quiz: Identify the Accurate Recital Statement
Select the statement that accurately reflects Recitals (67), (81), and (82).
Which statement is accurate?
- DORA sets strict numerical caps on every financial entity's exposure to an ICT third-party provider.
- A third-country provider designated as critical must move all data storage and processing into the Union within 12 months.
- A designated critical third-country provider that continues serving Union financial entities should undertake, within 12 months of designation, arrangements for incorporation within the Union; this does not create a data localisation obligation.
- A financial entity ceases to be responsible for DORA compliance once an ICT service is outsourced under a detailed contract.
Show Answer
Answer: C) A designated critical third-country provider that continues serving Union financial entities should undertake, within 12 months of designation, arrangements for incorporation within the Union; this does not create a data localisation obligation.
Recital (67) says strict caps and limits are not considered appropriate. Recital (81) gives the 12-month incorporation point for a designated critical third-country provider. Recital (82) expressly says DORA does not impose a data localisation obligation. Recital (64) preserves the financial entity's continuing responsibility.
Key Terms
- TLPT
- Threat-led penetration testing. Recital (72) says providers supporting critical or important functions should participate and fully cooperate in the TLPT carried out by the financial entity.
- Lead Overseer
- The overseer appointed under DORA that should monitor critical ICT third-party service providers and, where relevant, assess interdependencies and concentration-related systemic risk.
- exit strategy
- Contractual arrangements designed to reduce disruption when an ICT service ends, including transition periods that can support a move to another provider or an in-house solution.
- concentration risk
- Risk associated with dependence on one or a small number of ICT providers, including risk arising through subcontracting and potentially affecting financial-system stability.
- ICT third-party risk
- Risk arising from a financial entity's dependencies on ICT services provided by ICT third-party service providers.
- resolution resilient
- For financial entities within Directive 2014/59/EU's scope, the quality of ICT contracts being robust and fully enforceable in resolution, including specified protections against termination, suspension, or modification where payment obligations continue.
- register of information
- The record that Recital (65) says all financial entities should be required to maintain, covering all contractual arrangements for ICT services supplied by ICT third-party service providers.
- data localisation obligation
- A requirement that data be stored or processed in a particular territory. Recital (82) states that DORA does not impose such an obligation requiring storage or processing in the Union.
- critical or important function
- A DORA concept used to identify functions requiring heightened contractual protections; Recital (70) states that it encompasses critical functions under Article 2(1), point (35), of Directive 2014/59/EU.
- ICT third-party service provider
- A broad category described in Recital (63), including providers of cloud computing, software, data analytics, and data-centre services, as well as specified intra-group and payment-ecosystem providers.