SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal
still apply. The underlying assumption is that smaller entities can still generate consumer harm and opera - tional contagion, and that resilience expectations must remain credible across the entire market. 3.2 ICT Service Provider Contractual Requirements DORA’s contractual requirements are among its most operationally demanding elements because they transform what many institutions previously viewed as simple procurement constraints into formal gov - ernance obligations. The core risk DORA seeks to address is the gap between nominal compliance and actual resilience: updating templates and maintain - ing a register is easy; securing genuinely enforceable oversight rights over critical suppliers is not. DORA’s contractual framework therefore operates as a mech - anism to restore supervisory and operational leverage in areas where market power and standardised vendor terms have historically left financial entities vulnerable. The definition of an “ICT service” is intentionally broad. DORA captures digital and data services delivered on a continuous basis through ICT systems – such as cloud computing, software, data analytics, data cen - tres, electronic communications, and other ongoing digital dependencies. This breadth prevents institu - tions from artificially narrowing scope in an effort to reduce compliance workload. In practice, the real test is whether the service supports the continuous opera - tion of business processes, not whether it is labelled an “IT” service in the traditional organisational sense. As a result, compliance mapping becomes an enter - prise‑wide dependency review rather than a technol - ogy‑department inventory. Criticality is a governance judgement with supervisory implications. DORA requires institutions to distinguish between ICT services that support critical or impor - tant functions and those that do not, with enhanced contractual and oversight expectations for the former. Importantly, regulators do not pre‑classify criticality; the responsibility lies with the institution, which is fully accountable for its decision. This shifts incen - tives: under‑classifying a core banking platform, a hyperscaler, or a key managed security provider may reduce short‑term renegotiation effort, but it increases supervisory risk and signals weak ICT‑risk govern -
ance. DORA’s design effectively forces institutions to internalise the true resilience cost of choosing “com - mercial convenience.” Under DORA, contractual content becomes a resil - ience tool. For critical arrangements, contracts must include provisions that make oversight meaningful rather than symbolic. This includes sufficiently detailed service specifications and service levels to enable supervisory assessment; rights of access, inspection, and audit (including by regulators); incident‑reporting obligations aligned with the institution’s own timelines; business continuity and transition‑assistance commit - ments; and location transparency for data and service delivery to enable assessments against outsourcing and data‑protection requirements. The deeper point is not the clause list itself, but what it necessitates: institutions must renegotiate legacy agreements that were never designed to meet regulated resilience out - comes. Subcontracting (chain outsourcing) is treated as an operational exposure. DORA recognises that resil - ience risks can arise several layers down the supply chain. Where a primary provider subcontracts mate - rial components, institutions must ensure equivalent standards flow through – either directly or contractu - ally via the main provider. This creates particular chal - lenges for cloud arrangements that rely on extensive, often international, sub‑processor networks. The practical governance expectations are visibility (map - ping), enforceability (rights and obligations flowing through the chain), and a managed position for situ - ations where full control is unattainable (risk accept - ance, escalation, and disclosure where required). Concentration risk is treated as a systemic issue. DORA requires institutions to identify and manage ICT concentration risk, reflecting the reality that EU financial services increasingly depend on a small set of global technology providers and legacy core‑sys - tem vendors. DORA does not prohibit concentration, but it elevates it to a primary risk factor – something measurable, governable, and reportable – rather than an unintended consequence of digital‑transformation economics.
335 CHAMBERS.COM
Powered by FlippingBook