Subcontracting of ICT Services
Subcontracting of ICT services occurs when a company's direct technology provider hands off part of the service to one or more further providers, rather than delivering it entirely itself. This means the organization relying on the service depends not only on its direct provider but also on subcontractors it may not have a contract with. In the EU financial sector, this arrangement is subject to specific regulatory expectations under the Digital Operational Resilience Act (DORA).
Under DORA, subcontracting of ICT services arises when an ICT third-party service provider engages one or more further providers (ICT subcontractors) to deliver part of an ICT service supplied to a financial entity. It is a form of Nth-party (fourth-party and beyond) dependency, distinct from the direct third-party relationship between the financial entity and its ICT provider: the financial entity typically has no direct contractual privity with subcontractors further down the chain. The Joint Regulatory Technical Standards (RTS) developed to supplement DORA set out requirements and conditions specifically for the use of subcontracted ICT services supporting critical or important functions (CIFs); arrangements that do not support CIFs may fall outside the scope of these heightened conditions. The scope of this term is confined to the subcontracting relationship and its governance (for example contractual chain-of-service requirements, oversight, and monitoring of subcontractors), and it does not by itself address the broader operational resilience, information security, or concentration-risk assessment of the direct ICT provider. These requirements are jurisdiction- and sector-specific, applying to in-scope EU financial entities and their ICT providers, and should not be assumed to apply globally or to non-financial sectors.
Why it matters
When a financial entity contracts with an ICT provider, the service it ultimately receives may be delivered in part by subcontractors with which the entity has no direct contractual relationship. This creates a fourth-party and Nth-party dependency: the organization relies on providers it may not directly govern, monitor, or even fully identify. A disruption, security failure, or performance problem several links down the chain can still impair the ICT service the financial entity depends on, even though the entity's contractual leverage extends only to its direct provider. This gap between where dependency exists and where contractual control ends is the central concern the term addresses.
Under the Digital Operational Resilience Act (DORA), this arrangement is subject to specific regulatory expectations for in-scope EU financial entities. The Joint Regulatory Technical Standards developed to supplement DORA set out requirements and conditions specifically for subcontracted ICT services supporting critical or important functions (CIFs). This reflects a regulatory judgment that heightened oversight is warranted where the subcontracted service underpins functions whose disruption could materially affect the entity's operations. Arrangements that do not support CIFs may fall outside these heightened conditions, so the significance of a given subcontracting chain depends on what function it supports.
It is important to keep the scope of this term contained. Governing the subcontracting relationship, through chain-of-service contractual requirements, oversight, and monitoring, does not by itself resolve the broader operational resilience, information security, or concentration-risk questions attached to the direct ICT provider. These requirements are jurisdiction- and sector-specific, applying to in-scope EU financial entities and their ICT providers, and should not be assumed to apply globally or to non-financial sectors.
Who it's relevant to
Inside Subcontracting of ICT Services
Common questions
Answers to the questions practitioners most commonly ask about Subcontracting of ICT Services.