← Back to insights

The Cloud Contract Names One ICT Provider. Where Is the DORA Subcontracting Chain?

Recover DORA subcontracting evidence for an ICT service supporting a critical or important function: chain, locations, data, notice, objection and exit rights.

A DORA contract record maps a critical function through the direct ICT provider to material subcontractors and change controls
#DORA#ICT Subcontracting#Third-Party Risk#Cloud Contract#Financial Services

Signals to watch

  • A financial entity can name the direct cloud or ICT provider but cannot identify subcontractors underpinning a critical or important function
  • A material subcontracting change is approaching while the contract has no usable notice, approval or objection workflow
  • Service location, data-processing location, concentration and transferability evidence remain split between procurement, security and the provider

A DORA subcontracting gap exists when a financial entity knows its direct ICT provider but cannot show which subcontractors actually support a critical or important function, where they operate or process data, and how a material chain change can be assessed before it takes effect. The remedy is not a vendor list. It is a contract-linked chain record with evidence for risk, notice, objection and exit.

That is the project a DORA contract-remediation or third-party-risk provider’s business-development lead should look for in authorised financial-services, procurement and cloud-risk Telegram groups. A generic post about “fourth-party risk” is not enough. A named service, a critical or important function, an incomplete chain and a contract event create a reason to investigate. Seeing it after the notice period ends may leave the financial entity reviewing a change that has already been implemented.

The direct contract is only the first edge

Regulation (EU) 2022/2554, the Digital Operational Resilience Act (DORA), places requirements on contractual arrangements for ICT services supporting critical or important functions. Delegated Regulation (EU) 2025/532 specifies what a financial entity must determine and assess when those services or material parts are subcontracted.

The delegated regulation explains why a direct-provider spreadsheet is insufficient: ICT delivery can depend on a long or complex chain, and information gaps can limit the entity’s ability to identify, assess and manage risk. It directs attention to subcontractors that effectively underpin the relevant service, including those whose disruption would impair security or continuity.

The management body’s ultimate responsibility does not move down the chain. Even an intra-group subcontractor can count as an ICT subcontractor under the regulation.

Draw the chain from the function outward

Start with the business function, not the cloud brand.

Function → contracted ICT service → direct provider → material service component → subcontractor → delivery and data locations

For each edge, attach the contract clause or provider evidence that proves it. The resulting record should answer:

  • which critical or important function the ICT service supports;
  • which service or material part is subcontracted;
  • who provides that part and whether further subcontracting exists;
  • where the service is actually delivered;
  • where data are processed and stored;
  • what data are shared;
  • whether a small number of subcontractors creates concentration;
  • whether the service can be transferred; and
  • what a disruption would do to security, continuity and availability.

These are not interchangeable location fields. A subcontractor’s registered office, the place engineers work and the country where data are stored can be different.

Example: the hidden dependency is not always another cloud

Consider an illustrative composite message sequence; it does not describe a customer:

“Core onboarding runs with Provider A. Contract says EU hosting.”

“Provider’s new fraud engine uses another vendor. Security has the name, procurement doesn’t have the processing location.”

“Change goes live next month. Our addendum says they will notify material changes, no period written.”

The discussion contains a named function, direct provider, new subcontracted component, location gap and approaching change. It does not prove that the function has been formally classified as critical or important, that the new vendor supports a material part, what data are shared, whether further subcontractors exist, or which contract clauses govern approval and termination.

The provider can propose a bounded evidence review: link the function classification, service description, new component, subcontractor and proposed start date; then compare them with the contract’s notice and decision provisions. It cannot decide risk tolerance from the group thread.

The change-control branch has four gates

Delegated Regulation (EU) 2025/532 requires the contract to provide a reasonable notice period during which the financial entity can approve or object to proposed material changes. The ICT third-party provider may implement the change only after the entity has approved it or has not objected by the end of the period.

Turn that rule into four gates:

  1. Notice received: the proposed change, affected service and intended start date are documented.
  2. Information sufficient: the entity can identify the subcontractor, locations, data, controls and chain consequences needed for its assessment.
  3. Risk decision recorded: an authorised owner approves, objects or requires mitigation against the entity’s risk tolerance.
  4. Implementation checked: the provider’s actual change matches the decision and does not precede the permitted point.

The regulation also addresses termination rights where risk exceeds tolerance or subcontracting controls are not followed. A generic clause saying “we may use affiliates” does not demonstrate that the financial entity can operate these gates.

Contract evidence and the register of information must agree

The chain should not live only in an addendum. DORA’s register of information captures ICT third-party arrangements, while the subcontracting assessment explains the material chain and risk. If the contract says EU delivery, the register names one provider and the current provider notice names a third-country processor, the difference needs an owner and date.

The DORA register-of-information remediation article shows how an identifier or arrangement breaks across register records. A federal secure-software supplier request is a different evidence job; see the secure-software attestation request. Pricing and access options describe the Telegram discovery product.

TOP Prospect can retain and group relevant fragments from Telegram groups a user deliberately connects and is authorised to access. It can preserve original text, source, time, summary, ranking reason and cross-group support for human review. It cannot access contracts, classify a function, identify an undisclosed subcontractor, approve a material change, assess risk tolerance or terminate an agreement.

The chain evidence card

The article’s original contribution is one card with four evidence bands:

BandWhat must be linkedFailure exposed
ServiceFunction, ICT service and material componentSupplier name without business criticality
ChainDirect provider, subcontractors, further chain and locationsHidden operational or data dependency
ControlDue diligence, monitoring, audit/access and information rightsContract right that cannot be exercised
ChangeNotice, decision, implementation and exit recordMaterial change arriving before risk review

A project is ready for scoping when the entity can identify which band is incomplete and provide the governing contract. Without that contract link, “map our fourth parties” is still an open research request.

Key facts

  • DORA Article 30 covers key contractual provisions for ICT services, including services supporting critical or important functions.
  • Delegated Regulation (EU) 2025/532 specifies the subcontracting assessment for those services or material parts.
  • The financial entity’s management body retains ultimate responsibility; subcontracting does not transfer it away.
  • Risk assessment considers chain length and complexity, service and data locations, shared data, concentration, transferability and continuity impact.
  • The contract must contain a reasonable notice period for approval or objection to material changes.
  • Material changes may be implemented only after approval or no objection by the end of the notice period.

FAQ

Does using an ICT subcontractor transfer DORA responsibility away from the financial entity?

No. Delegated Regulation (EU) 2025/532 states that subcontracting cannot reduce the ultimate responsibility of the financial entity’s management body to manage risk and meet its obligations.

Which subcontractors need the closest attention?

The Regulation focuses on subcontractors that provide ICT services supporting critical or important functions or material parts of them, particularly those whose disruption would impair security or service continuity.

Must the contract allow time to approve or object to material changes?

Yes. The contractual arrangement must contain a reasonable notice period for the financial entity to approve or object, and the provider may implement a material change only after approval or no objection by the end of that period.

Can the financial entity terminate when a change exceeds its risk tolerance?

The Regulation provides for action before the notice period ends and termination rights in specified circumstances, including where the outcome of the risk assessment exceeds risk tolerance or required controls are not followed.

The commercial Signal is not “uses subcontractors.” It is a named critical service whose chain, control or change record cannot be reconciled before a real contract event.

Frequently asked questions

Does using an ICT subcontractor transfer DORA responsibility away from the financial entity?

No. Delegated Regulation (EU) 2025/532 states that subcontracting cannot reduce the ultimate responsibility of the financial entity’s management body to manage risk and meet its obligations.

Which subcontractors need the closest attention?

The Regulation focuses on subcontractors that provide ICT services supporting critical or important functions or material parts of them, particularly those whose disruption would impair security or service continuity.

Must the contract allow time to approve or object to material changes?

Yes. The contractual arrangement must contain a reasonable notice period for the financial entity to approve or object, and the provider may implement a material change only after approval or no objection by the end of that period.

Can the financial entity terminate when a change exceeds its risk tolerance?

The Regulation provides for action before the notice period ends and termination rights in specified circumstances, including where the outcome of the risk assessment exceeds risk tolerance or required controls are not followed.

Sources and further reading

RESEARCH & DEFINITIONS

How a Signal worth attention is found

See how Top Prospect finds and organizes Signals worth checking, keeps the original Telegram context, removes duplicates, and helps you decide what to review first. You decide whether to follow up and what to do next.

Open the methodology and core definitions

START WITH ONE MONITORED GROUP

Try the workflow free for seven days.

Open the product, connect one authorized group, and describe the Signal you want to find. If you need help choosing the scope, ask us on Telegram.

Back to homepage