The financial sector still has a few months left to make its IT contracts compliant with the Digital Operational Resilience Act (DORA). DORA is an EU Regulation that seeks to strengthen the digital operational resilience of the financial sector and has the objective, among other things, to harmonise fragmented IT risk management and IT outsourcing laws and regulations and to address gaps or overlaps in them. Starting from 17 January 2025, financial institutions like banks, insurers and investment institutions will have to meet the requirements DORA sets in this context.
An important part of DORA deals with third party risk management of financial institutions, with requirements in place for the situation in which financial institutions involve third parties – IT suppliers – in their use of IT services.
In this article we list the mandatory elements in IT contracts that have to comply with DORA. We make a distinction between the topics that all IT contracts must contain, and the elements that must be added to contracts concerning IT services that support critical or important positions of financial institutions.
An important point of attention is that the contractual requirements arise not only from DORA itself, but also from delegated regulations under DORA (also referred to as level-2 regulations); the Regulatory Technical Standards (“RTS”) and Implementing Technical Standards (“ITS”) designed for the joint European supervisory authorities for the financial sector EBA, EIOPA and ESMA.
Mandatory payments in all IT contracts
The following elements must be reflected in any case in a contract between a financial institution that is subject to DORA and its IT supplier:
- Description of service – A clear and complete description of the IT services and functions to be supplied.
- Arrangements about suboutsourcing – Determining whether the suboutsourcing of critical or important functions is permitted, and if yes, on what conditions. If suboutsourcing is permitted, it must be agreed in any case that the IT supplier remains responsible for performing the services, has a monitoring obligation and reporting obligations regarding the suboutsourced services, arrangements regarding relevant locations, information security, certain safeguards for the continuity of the services, such as Business Continuity Plans (BCPs) and certain service levels, that the supplier imposes audit rights in favour of the financial institution and its supervisors on its subcontractors, and will be notified of any changes to the suboutsourced services and certain termination rights related to suboutsourcing.
- Location of the services and data – A description of the locations where the service is provided and the (personal) data are processed and/or stored, and an obligation for the supplier to inform the financial institution in advance of any changes to these locations
- Information security – Arrangements to safeguard the availability, authenticity, integrity and confidentiality of (personal) data.
- Access, restoration & return of data upon termination – The agreement should include safeguards for access, restoration and return in usable format in the event of insolvency, settlement or discontinuation of the business operations.
- SLA – A description of the services level (‘service level descriptions’ in the English version of DORA), at least in broad outline (see also the list below).
- Support to incidents – An obligation for the IT supplier to lend the financial entity support in the event of incidents, free of charge or at pre-agreed rates.
- Obligation to cooperate – A contractual obligation to lend full cooperation to supervisory authorities and/or competent authorities.
- Termination rights and minimum notice periods – The option to terminate the agreement, at least in the event of (i) significant breach by the IT service provider of applicable laws or regulations; (ii) circumstances identified throughout the monitoring of the IT risk, which may adversely affect the agreement or the IT service provider; (iii) the IT service provider’s evidenced weaknesses pertaining to its IT risk management and in particular information security; and (iv) where the competent authority can no longer effectively supervise the entity, with the related appropriate notice periods.
- Participation in awareness programmes and training courses – Arrangements on, where relevant, the participation of (the staff of) the IT service providers in the financial entities’ security awareness programmes and digital operational resilience training.
Additional mandatory provisions for critical or important functions
In addition to the list above, contracts relating to IT services supporting critical or important functions of the financial entity should contain, the following elements:
- SLA with KPIs – service levels for the full services, including precise quantitative and qualitative performance targets
- Notice periods and reporting obligations – The obligation to report developments that may have material consequences for the ability of the IT service provider to provide the IT services effectively according to the service levels agreed.
- BCPs – The obligation to implement and test business contingency plans and to have appropriate IT security measures, tools and policies.
- Obligation to cooperate in TLPT – The obligation to cooperate in the threat-led-penetration-tests (TLPT) of the financial institution, if the institution has established that the relevant IT services are in scope of its TLPT.
- Audit right – The right to monitor, on an ongoing basis, the IT service provider’s performance, which right entails unrestricted rights of access, inspection and audit by the financial entity itself and its supervisors, including the obligation for the service provider to cooperate fully and the obligation for the financial entity to provide details on the audit or inspection in advance. There is also room to agree on alternative assurance if the rights of other clients of the IT service provider would be affected by an audit or inspection;
- Exit – Financial entities shall have the option to terminate the agreement without disruption to their business activities, without limiting their compliance with regulatory requirements, and without detriment to the continuity and quality of services provided to (end) customers. Besides, the agreement has to contain arrangements for the transition of the IT services and associated data to another supplier or to the financial institution itself.
Incidentally, such requirements to agreements are not entirely new for most financial entities. Pre-DORA IT outsourcing laws and regulations, such as the EBA and ESMA guidelines on outsourcing arrangements and the EIOPA guidelines for outsourcing to cloud service providers, already contain a range of similar requirements that are set to IT outsourcing agreements. Therefore, for IT contracts in which the EBA, EIOPA or ESMA guidelines were already taken into account, part of the topics will already be regulated. In that case a gap analysis and a supplement to the gaps will suffice. Nevertheless, we expect some work to be needed in all cases, considering that DORA contains stricter requirements that those in place so far, and on top of that, that more IT contracts will be ‘in scope’. The outsourcing guidelines mentioned above mainly (almost exclusively) concerned IT outsourcing of critical or important functions, whereas DORA sets requirements on all IT contracts.
For more information and background details on DORA and all the things IT contracts must contain if they are subject to DORA, please read our elaborate article on this topic that was published earlier in Tijdschrift voor Internetrecht (in Dutch).
Do you have questions about DORA or need help reviewing or (re)negotiating your IT contracts? We will be happy to help you!