The impact of contracts on financial institutions and IT service providers

The risks incurred by the financial sector linked to the use of information and communication technologies (ICT) are increasingly increasing. Regulation (EU) 2022/2554 of the European Parliament and of the Council of December 14, 2022 on digital operational resilience in the financial sector (known as DORA) provides for a set of measures aimed at identifying, preventing, managing and reducing these risks, relying in particular on the contractual system to be put in place between third-party ICT service providers and financial entities.

Why a regulation?

Information technologies have gradually become widespread in the financial sector. With these, new risks have emerged, for financial entities increasingly exposed to cyberattacks and ICT-related incidents such as denial of service attacks. Faced with these risks, no overall regulatory approach had yet been considered until the DORA Regulation.

Who is DORA for?

It concerns all players in the banking and financial sector, insurance and asset management, market infrastructures, regulated information players (all of these players being designated by “the entities financial services”) as well as providers providing ICT services to these regulated players.

What is he talking about ?

DORA provides for obligations aimed at identifying, preventing, managing and reducing the risks linked to the use of ICT, both on an organizational and contractual level for all of these actors. This system is supplemented by the creation of an ad hoc supervision regime concerning ICT service providers, in particular when it comes to critical third-party providers. These service providers will not only be subject to rules as part of their contractual relationships with entities subject to DORA, but they will also be supervised by the European Supervisory Authorities (the ESAs).

The risk linked to the third-party provider

DORA applies to contractual agreements between third-party ICT service providers and financial entities. DORA introduces the concept of “third-party provider risk” and integrates “outsourcing” agreements within the meaning of the EBA guidelines on these issues. Thus, before DORA, two criteria were taken into account to consider that a function was outsourced:

  • the recurrence of the service provided by the third party and;
  • the fact that the outsourced function would or could reasonably be performed by the financial entity. This last criterion was not included in DORA.

From now on, it will therefore be sufficient for the service provided by the third party to be recurring to consider that a function is outsourced. The scope of DORA is therefore broader and could include more varied services such as remote monitoring, access to the internet and mobile networks or data analysis.

What clauses?

DORA requires due diligence covering the entire contractual timeline between financial entities and ICT service providers, namely from risk analysis to termination of the contract. These measures include:

  • the general principles that financial entities must follow to assess and manage the risks associated with their relationships with third-party ICT service providers; And
  • the main contractual stipulations to be included in agreements relating to the use of ICT services.

The clauses that must appear in all contracts relating to ICT services (art. 30 DORA) relate to the description of the services provided, the places where the services will be provided and the data stored and processed, the stipulations relating to the protection of personal data, the description of service levels, the obligation to assist financial entities in the event of an ICT-related incident, the obligation to cooperate with competent authorities and resolution authorities, or to the clauses governing termination. Other clauses must be inserted when the service constitutes a critical or important function.

Think about the “Pen Test” clauses

The DORA Regulation provides examples of risk management measures that could be integrated into contracts concluded with IT service providers: security audits, security scans, requests for information, etc.

To take a concrete example, the famous intrusion tests (“penetration tests”) already included in certain IT security contracts will have to see their scope extended so as to integrate all the components of resilience. Thus, the scope of testing may refer to open source analyses, network security assessments, source code review, etc.

  • Only micro-enterprises or companies under simplified regime should not be affected by threat-based tests.
  • Independent testing organizations must be qualified within the meaning of the Regulation. A certificate of conformity must be established at the end of the tests.
  • These tests must be carried out at least every 3 years, with the financial entity itself carrying out self-tests (internal audits) on a targeted scope, in the meantime.
  • Therefore, the terms specific to these “Pen Tests” must be drafted in sufficient detail and consistent with the DORA Regulation.

Be ready for January 17, 2025

The entry into force of DORA is scheduled for January 17, 2025. ESAs must prepare regulatory technical standards (RTS), implementing technical standards (ITS) and technical opinions (concerning draft regulations or directives delegates where applicable) in order to complete certain principles provided for in the regulation.

The AES published the first game of final versions of four RTS on January 17, 2024 and relating to:

  • ICT risk management tools, processes and policies;
  • The policy for the use of ICT services supporting critical or important functions;
  • The information register on ICT service providers;
  • The classification of major ICT incidents and significant cyber threats.


Others are still under consultation (until March 4, 2024)

  • The content and reporting models of major ICT incidents and significant cyber threats;
  • Advanced testing for digital operational resilience;
  • Conditions applicable to the subcontracting of ICT services that support critical or important functions;
  • The conditions relating to the exercise of supervision of critical ICT service providers and in particular the information they are required to submit, including information regarding subcontracting agreements.

Objective: compliance

We understand that compliance will not happen in the blink of an eye. This is why it is now urgent for financial entities to identify the stock of contracts impacted by DORA, the modification of existing clauses and the modification of contractual documentation. Remembering the precedent of outsourced activities in 2021, financial entities will have to carefully monitor the proper application of the obligations arising from DORA for all stakeholders, under penalty of sanction, namely:

  • fines of up to 1% of their total annual turnover;
  • the temporary suspension, in whole or in part, of the use or deployment of a service provided by the critical third-party ICT service provider (art. 42.8), or even;
  • termination of the contract with the critical ICT service provider.

Which is far from anecdotal.

Pascal Agostiassociate lawyer, doctor of law
Caprioli & Associés, Member of JurisDéfi.

Expert opinions are published under the full responsibility of their authors and do not commit the editorial staff in any way.

Selected for you