DORA outsourcing

We assess DORA outsourcing arrangements to strengthen classification, governance and contractual compliance

DORA outsourcing: assessing what is actually outsourced

View as Markdown
9 mins read • Legal Writer • FINANCIAL REGULATION • 13 July 2026

Financial undertakings today work with a wide range of external providers. Some provide technology, others perform parts of the business, and many arrangements contain both components. A clear method is therefore needed to assess whether a service or provider arrangement is critical or important under DORA or the outsourcing framework.

A sound starting point is to describe what the arrangement actually covers. Once the firm understands what the provider does in practice, it becomes easier to determine whether the assessment mainly concerns an ICT service, an outsourced function or an arrangement involving both.

For financial undertakings, this type of classification becomes a central part of work on financial regulation, as the assessment affects governance, contracts, risk management, monitoring and documentation.

The purpose is not to create a theoretical comparison of regulatory frameworks. The purpose is to provide a practical approach to understanding the provider arrangement, assessing its significance for the business, and ensuring that the classification is reflected in contracts and governance.

Information security starts with the provider’s actual role

The first question should be what the provider actually does for the financial undertaking. Does the provider supply a technical service? Does the provider perform a function or process for the firm? Or does the arrangement consist of both technology and operational delivery?

That description needs to be practical. It is not enough to rely on the contract title, the provider’s category in the procurement system or an internal label. The assessment becomes more accurate when the firm describes how the service is used in the business and which part of the commercial activity, control environment or regulatory process is affected.

For example, a provider may supply a system, platform, cloud service or security solution. Another provider may handle customer matters, perform controls, support regulatory compliance or manage parts of an operational process. In some cases, both occur within the same contract.

The difference between a function and an IT service

A central part of the assessment is distinguishing between a function and an IT or ICT service. Put simply, a function concerns what the business does, while an IT service concerns the technical capability used by the business.

A function is an activity, process or service that would otherwise be performed by the financial undertaking itself. This may include regulatory compliance, internal audit, customer service, credit assessment or the management of certain operational processes.

Where such a function is outsourced, the outsourcing assessment becomes relevant. The firm then needs to analyse the significance of the function for the business, the risk profile, the control environment and the ability to comply with regulatory obligations.

An IT or ICT service instead concerns technology, systems, operations, data processing, communication, cloud infrastructure or other digital capability. This may include a core banking system, payment platform, case management system, transaction monitoring system, or communication and security service.

Where an ICT service is involved, the DORA track becomes relevant. The firm then needs to analyse how the service supports the business, the role it plays in digital operational resilience, and its significance for critical or important functions.

The assessment becomes clearer when function and technology are separated

In financial services, function and technology are often closely connected. This makes the assessment practical rather than theoretical. A transaction monitoring system is a technical solution, while also supporting a central regulatory compliance process. It therefore becomes an ICT service that may be critical or important under the DORA framework.

It is therefore valuable to divide the analysis. First, the technical service is described. The business process or processes supported by the service are then described. If the provider also performs parts of the process, this is documented as a separate part of the assessment.

This gives the firm a more nuanced view of the arrangement. It becomes clearer which elements relate to technology, which relate to business delivery, and how these elements together affect risk, responsibility and governance.

The DORA assessment starts with the ICT service

Once the firm has identified an IT or ICT service, the significance of that service for the business needs to be analysed. The question is not only what the provider supplies from a technical perspective, but which function or process the service supports.

Many financial undertakings are heavily dependent on digital services. This means that the DORA analysis often becomes a natural part of provider governance. At the same time, classification requires a separate assessment of the service’s significance. An IT service is within the scope of DORA, but does not automatically need to be treated as critical or important.

The assessment should therefore focus on practical consequences. Which processes use the service? Which customer flows are affected? Is the service significant for transactions, reporting, risk management, regulatory compliance or information security? How would the business be affected by an interruption?

An administrative IT service may become highly significant if it is used in a central process. Conversely, a technical service may have more limited significance if it is used in a restricted context and effective alternatives or manual procedures are available.

The outsourcing assessment starts with the function

For outsourcing, the practical starting point is to identify whether the provider performs a process, service or activity that would otherwise be performed by the financial undertaking itself.

Where a function, or part of a function, is outsourced, the firm needs to assess the significance of that function. This concerns operational responsibility, control and continuity. The assessment should take into account how central the function is to the regulated business, whether deficiencies may affect regulatory compliance, and how the firm ensures transparency, monitoring and governance.

Other relevant questions include how easily the function can be brought back in-house or transferred to another provider, the impact an interruption would have on customers and the business, and how responsibility is allocated between the firm and the provider.

A clear outsourcing assessment helps the firm formulate the right contractual requirements and establish effective monitoring. It also enables management, risk, compliance, legal, IT and the business to work from the same understanding of what has actually been outsourced.

The same provider arrangement may require several assessments

A provider arrangement may contain both a technical component and operational delivery. This is common in financial services, where digital platforms are used for processes that also have regulatory significance.

For example, a provider may supply an accounting platform and also assist with performing the accounting. Another provider may supply a credit assessment system and at the same time perform steps that form part of the firm’s credit process.

In such cases, the analysis becomes more useful if the firm divides the arrangement into components. The technical element is analysed as an ICT service. The operational delivery is analysed by reference to whether a function, or part of a function, has been outsourced. The firm then assesses how the parts interact and the overall impact of the arrangement on the business.

This produces a classification that reflects reality and can be translated into contracts, governance and ongoing monitoring.

Information security classification in three practical steps

A simple method is to work in three steps. It works both for new provider arrangements and when existing contracts are reviewed.

  • Describe what the provider actually does and how the service is used in the business.
  • Identify whether the arrangement concerns an ICT service, an outsourced function or an arrangement with several elements.
  • Assess the impact that an interruption, deficiency or incorrect performance would have on the business, customers and the firm’s regulatory obligations.

After these steps, the firm can move on to more detailed questions on classification, contractual requirements, reporting, incident management, exit planning and documentation.

The method also makes the work more consistent. It can be used in procurement processes, contract negotiations, provider registers and recurring reviews of existing arrangements.

Quality questions that strengthen the classification

Once the initial assessment has been completed, the firm can quality assure the analysis through a number of control questions. These help ensure that the classification is practically useful.

  • Is it clear which business process the service supports?
  • Is it clear whether the provider only supplies IT or also performs parts of the process?
  • Is the dependency on the service described in concrete terms?
  • Are the consequences of interruptions, deficiencies or incorrect performance documented?
  • Is the classification reflected in the contract and in internal monitoring?
  • Is there a procedure for updating the assessment when the use of the service changes?

The questions make the classification more robust. They also help keep the contract, risk assessment and internal governance aligned.

Classification must be reflected in contracts and governance

A well-executed classification only gains practical significance when it is translated into contracts and governance. It affects, for example, the requirements imposed on the provider, how the service is monitored and which internal functions need to be involved.

The classification may affect contractual requirements, reporting, incident management, audit and access rights, exit planning, continuity requirements, information security, subcontractors, allocation of responsibility and documentation.

It may also affect how the firm organises its internal responsibilities. Some matters sit close to IT and information security. Others sit close to risk, compliance, legal or the business. A clear classification makes it easier to allocate responsibility and create monitoring that works over time.

It is also valuable to view the classification as a living assessment. When the use, scope or significance of the service changes, the assessment should be reviewed. This allows contracts and governance to develop in step with the business.

Start simply and build the assessment step by step

An effective analysis of DORA outsourcing starts with a practical question: what is actually being outsourced or purchased? Once the answer is clear, it becomes easier to distinguish between a function and an IT service, assess the significance for the business, and select the right requirements for contracts, monitoring and documentation.

The key question is therefore what the firm has actually outsourced, what role the service plays in the business, and what consequences an interruption or deficiency would have. With that structure, the classification becomes more useful for legal, risk, compliance, IT, information security and the business.

At Morling Consulting, our financial regulation lawyers help financial undertakings structure provider arrangements, classifications and contracts in a way that works both from a regulatory and operational perspective for clients across Europe.

Speak to a financial regulation lawyer

Do you need to classify a provider arrangement under DORA or outsourcing rules? Contact us and we will assess the arrangement and regulatory requirements

"*" indicates required fields