Global Law Experts Logo
fintech-security-resilience.jpg

Find a Global Law Expert

Specialism
Country
Practice Area
awardsr

Awards

Since 2010, the Global Law Experts annual awards have been celebrating excellence, innovation and performance across the legal communities from around the world.

DORA Negotiations: Key Contractual Content in ICT Contracts

posted 2 months ago

DORA
The Digital Operational Resilience Act (“DORA”) requires that Financial Entities ensure that their ICT contracts include specific provisions that support business continuity, risk management, and regulatory compliance amongst other conditions imposed by DORA.

As a result, for any ICT Service Provider that wishes to retain captured Financial Entities as clients, some level of acceptance as regards integrating DORA related new contractual obligations must be accepted.

In this article, we shall explore some key essential themes for ICT Service Providers to consider when negotiating ICT contracts with Financial Entity clients.

1.Detailed Service Level Agreements

Having properly detailed Service Level Agreements (“SLAs”) is a requirement in terms of DORA. Thus, those ICT Service Provider who only make available basic SLAs, or perhaps no SLAs at all, will need to be able to supply a more developed SLA meeting DORA’s expectations.

In this regard, DORA and the related literature issued to date, is not very prescriptive in terms of what an SLA should contain. For advanced ICT Service Providers who were already used to making available detailed SLAs, it is thus typical that few changes, if any, are actually envisaged to their SLA in view of DORA.

Any properly developed SLA that meets DORA expectations is envisaged to include at least:

  • Service uptime and availability targets to ensure continuous service;
  • Incident response times for outages and service failures;
  • Resolution time and relative objectives or categorisations; and
  • Penalties for non-compliance ensuring that the ICT Service Provider takes operational resilience seriously.

As regards penalties for defaults on an SLA, ICT Service Providers may particularly wish to note that DORA does not preclude that so-called “service credits” are negotiated as the relative (sole) penalty.

2. Risk Management and Security

DORA places significant emphasis on risk management and cybersecurity. ICT contracts should accordingly cover obligations for risk assessments to identify and mitigate risks/vulnerabilities, security incident reporting mechanisms, compliance with industry standards and related obligations.

While compliance with international security standards such as ISO 27001 does not in itself translate to DORA compliance, in practice, it is probable that ICT Service Providers who can show certification with such standards or can at least commit thereto, are best placed to provide Financial Entities with the reassurances that such would typically expect.

3. Audits

Financial Entities subject to DORA are expected to have the ability to audit ICT Service Providers and thus accepting some level of audit rights towards Financial Entity will be inevitable for ICT Service Providers.

Key provisions to consider when negotiating include:

  • Access/audit rights of the Financial Entity to review operational resilience measures, including onsite and remote access, prior notice and timing;
  • Reporting obligations;
  • Regulatory access rights ensuring the Financial Entities’ financial authorities can inspect/audit the ICT Service Provider on DORA relevant matters where required.

4. Subcontracting Restrictions and Oversight

A level of subcontracting tends to be inherent in the service delivery of most ICT Service Providers. In turn, often the chain of subcontractors can be quite lengthy in that the subcontractors may also use further subcontractors. Accordingly, the DORA related expectations on subcontracting and oversight tend to be particularly key and sensitive topics for an ICT Service Provider when negotiating with Financial Entities.

Conditions on the disclosure and appointment of subcontractors arise from DORA. Financial Entities need to also be prepared and have controls against the introduction of new risks in view of changes to the subcontracting chain.

Reporting obligations on the Financial Entities’ subcontracting chain also apply.

Financial Entities may seek to retain control of the subcontracting chain, and approval processes for subcontracting should thus be carefully considered and negotiated.

A level of back-to-back flow-down of obligations by ICT Service Providers unto their subcontractors tends to be inevitable for the ICT Service Provider to be able to commit to the respective commitments towards its Financial Entity clients.

5. Business Continuity and Exit Strategies

Operational resilience in terms of DORA extends beyond service uptime commitments in an ICT contract’s SLA. It also includes preparedness for disruptions and exit planning on contract termination.

Elements such as business continuity planning requirements, ensuring the ICT Service Provider have contingency measures, should be carefully considered and negotiated, as are as termination assistance clauses requiring support to ensure a smooth transition, data portability and deletion, ensuring financial entities

ICT contracts are in view of DORA expected to cover elements such as business continuity planning requirements, ensuring financial entities can retrieve or securely erase their data when switching providers as well as relative minimum notice periods.

When it comes to business continuity, ICT Service Providers tend to consider their Business Continuity Policy a “trade secret”. Sharing of a copy of the Business Continuity Policy does not to date emerge as a direct obligation under DORA and thus, providing some alternative visibility can be considered for negotiations by ICT Service Providers.

6. Legal Compliance Clauses

Often times, Financial Entities may be pushing for contracts having wording that states that both parties’ are committing to DORA compliance. As such, ICT Service Providers may wish to recall that DORA compliance is a legal obligation of the Financial Entity, and not directly of the ICT Service Provider.

Push back against such language may thus be considered as not just needed for better negotiations but also as needed to reflect the legal reality.

7. Commercial

In practical terms, for an ICT Service Provider to be able to commit to the various expectations that Financial Entities require in terms of DORA, various effort, time and resources need to be committed to by the ICT Service Provider. Thankfully, to date, the DORA related literature does not preclude that assistance is charged for.

Thus, ICT Service Providers may wish to negotiate the inclusion of commercial related elements on any inputs/assistance that Financial Entities may need in their DORA related contractual updates.

Conclusion

The above are just some of the key themes that need to be considered when negotiating updates to ICT contracts in view of DORA.

Critically, ICT Service Providers may wish to note that they are somewhat dependent on their Financial Entity customers’ classification in their regard since ultimately, which content needs to be included within an ICT contract by the Financial Entity depends on whether the Financial Entity deems the ICT services being provided by the ICT Service Provider as supporting critical, or important functions or otherwise.

Indeed, the bulk of the contractual content which must be included is enshrined within DORA article 30. DORA’s article 30(2) effectively sets out de minimis requirements applicable irrespective of the ICT Service Provider’s categorisation, while DORA’s article 30(3) applies as regards those ICT Service Provider’s supporting a critical or important function of the Financial Entity.

Further envisaged detail as to the contractual content is however found in the Regulatory Technical Standards (“RTS”) issued by the European Supervisory Authorities (“ESAs”) especially the key for ICT Service Providers being the RTS concerning the subcontracting of ICT services supporting critical or important functions (the “Subcontracting RTS”).

Recently, the proposed draft Subcontracting RTS was refused by the EU Commission. Updates to ICT contracts with a view to ensuring the Financial Entity’s DORA compliance should thus be approached with yet even more caution, given the current state of flux.

Should you wish to read further about the RTS’s rejection, you may access here.

This is the third article in our series “The DORA Edge: Empowering ICT Providers in Financial Services”.

For information or assistance please contact us at info@gtg.com.mt

Author: Dr Terence Cassar

Author

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0

Join

who are already getting the benefits
0
Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox. Naturally you can unsubscribe at any time.

Online Casino Reviews

  • Freeroll Poker Tournaments For Real Money
  • Australian Online Casino Real Money
  • Best Slot App To Win Real Money
  • Online Casino Real Money Australia
  • Best Paying Online Pokies
  • Wizard Of Oz Online Slots
  • All Slots Casino Mobile
  • Best Online Poker App Real Money
  • Best Online Casino To Play Roulette
  • Is Online Casino Legal
  • Online Casino That Accepts Paypal
  • Play Roulette For Real Money
  • Slot Apps To Win Real Money
  • Real Money Slots Online Usa
  • Safe Online Casino
  • Wizard Of Oz Slots
  • Real Online Pokies Nz
  • Biggest Online Casino In The World
  • Online Casino Pay With Paypal
  • Online Casino That Accept Paypal
  • Online Casino Canada Real Money
  • 3 Card Poker Online Real Money
  • Online Slots Real Money Canada
  • Best Online Poker Sites For Real Money
  • Real Money Poker App Android Usa
  • How To Make Money From Online Casino Bonuses
  • Real Money Poker App Iphone
  • How To Play Blackjack Online For Real Money
  • Best Slots To Play
  • Top 10 Online Pokies
  • Best Poker Apps Real Money
  • Online Casino Legal
  • Best Payout Online Casino Uk
  • Win Money Online Slots
  • Online Poker Nj Real Money
  • How To Win Online Slots
  • Casino Gaming License
  • Play Real Pokies Online
  • Blackjack Sites For Real Money
  • Real Money Casino Games For Android
  • Best New Online Slots
  • Flaming 777 Slots Games
  • Online Blackjack With Live Dealers
  • How To Play Online Slots
  • Facebook Casino Games Real Money
  • Online Casino With No Minimum Deposit
  • How To Beat Online Slots
  • Online Casino License
  • The Big Payback Slots
  • Royal Vegas Online Casino Withdrawal
  • Online Casino Minimum Deposit 5
  • Online Pokies Real Money Australia
  • Las Vegas Usa Online Casino
  • Real Money Poker App Android
  • Wheel Of Fortune Slots
  • Game Of Thrones Slots
  • Online Poker Real Money Usa Legal
  • Best Online Casino European Roulette
  • Blackjack Online Real Money Paypal
  • Online Video Poker Real Money Usa
  • How To Create An Online Casino
  • Lucky Nugget Online Casino Mobile
  • How To Withdraw Money From Online Casino
  • Platinum Play Online Casino Download
  • Online Casino For Usa Players
  • Best Online Casino Usa Real Money
  • Online Roulette Real Money Usa
  • Best Real Money Poker Sites
  • Android Slots Real Money
  • How To Start An Online Casino Business
  • How To Start An Online Casino
  • How To Start An Online Gambling Site
  • Best Online Casino For Blackjack
  • Play Baccarat Online For Money
  • Online Pokies New Zealand
  • Best Slots To Play At Golden Nugget
  • Slots Of Vegas Online Casino
  • Best Online Pokies Site
  • How To Beat Online Roulette
  • New Zealand Online Pokies
  • Online Poker Mobile Real Money
  • Which Online Slots Payout The Most
  • Is Online Casino Legal In India
  • Online Casino Software For Sale
  • Best Online Casino For Craps
  • Hard Rock Casino Slots
  • Win Real Money Online Pokies
  • Online Casino With Highest Payout Percentage
  • Poker Apps With Real Money
  • Online Roulette Real Money Review
  • Full Tilt Poker Real Money
  • Online Casino 5 Dollar Minimum Deposit
  • Online Roulette With Real Money
  • Best Online Roulette For Real Money
  • I Migliori Casino Online Italiani
  • Best Payout Online Slots
  • How To Play Baccarat Online
  • Play Casino Card Game Online
  • Play Blackjack Online For Real Money
  • Best Paying Online Slots
  • Casino License Cost
  • Online Poker Real Money California
  • Safe Online Casino Australia
  • Online Roulette Australia Real Money
  • Online Poker Real Money Texas
  • Online Roulette Real Money Paypal
  • Online Slots Australia Real Money
  • Golden Nugget Online Casino Review
  • Casino Games To Win Real Money
  • Online Pokies Australia Real Money
  • Online Gambling Blackjack Real Money
  • Win Real Money Playing Slots
  • How To Win Roulette Online
  • Aristocrat Pokies Online Real Money
  • Hollywood Casino Online Slots
  • Play Online Keno For Real Money
  • What's The Best Online Casino
  • Triple Double Diamond Slots
  • Play Roulette Online With Real Money
  • Roulette Online For Real Money
  • Play Roulette Online Real Money
  • Best Online Pokies Real Money
  • Big Red Pokies Online
  • How To Win At Online Blackjack
  • What Is The Best Online Roulette Site
  • Real Money Online Pokies
  • Spin To Win Slots
  • Ruby Slots Online Casino
  • Wheel Of Fortune Online Casino
  • Spin Palace Flash Casino Online
  • Online Poker Real Money App
  • Online Casino With Paypal Deposit
  • How To Win At Online Roulette
  • Can You Win Real Money On Slot Apps
  • Is Ignition Casino Safe
  • Online Casino Blackjack Real Money
  • Online Casino Win Real Money Usa
  • How To Make Money Online Casino
  • Online Casino Real Money Reviews
  • Slot Games To Win Real Money
  • Jackpot City Online Casino Download
  • Online Pokies Real Money
  • Casino War Online Real Money
  • Online Casino No Minimum Deposit
  • Play Wheel Of Fortune Slots Online
  • Best Online Casino Game To Win Money
  • Online Casino Without Wagering Requirements
  • Online Slots For Real Money Usa
  • Legal Online Casino Australia
  • How Do Online Slots Work
  • Best Online Casino For Us Players
  • Online Play Casino Roulette Game
  • Online Blackjack Real Money Australia
  • Real Casino Games Real Money Online
  • Online Slot Machines Real Money Paypal
  • The Best Online Casino For Roulette
  • What Online Casino Pays Out The Most
  • Start Your Own Online Casino
  • Legal Online Casino
  • Online Live Roulette Casino Game
  • Playing Blackjack Online For Real Money
  • Online Penny Slots Real Money
  • Best Online Blackjack For Money
  • How To Win Online Roulette
  • Real Money Poker Sites Usa
  • Best Time To Play Slots
  • Online Keno For Real Money
  • Best Payout Online Slots Uk
  • Online Slots Real Money Reviews
  • Best Online Pokies Nz
  • What States Allow Online Gambling
  • Best Real Money Poker App
  • Online Slots To Win Real Money
  • Real Money Slots App Iphone
  • Jackpot City Flash Casino Online
  • Ignition Casino Legit
  • All Star Slots Casino
  • How To Play Online Casino
  • Real Time Gaming Slots
  • Online Video Poker Real Money
  • How To Play Roulette Online For Money
  • How To Win On Online Slots
  • Age Of Gods Slots
  • Online Real Casino Money Games
  • Best Online Slots To Play
  • Online Poker California Real Money
  • Is Jackpot City Casino Legit
  • How To Win At Online Slots
  • Play Poker For Real Money
  • Safe Online Pokies Australia
  • Best Way To Play Slots
  • How To Play Casino Online
  • Play Online Roulette For Money
  • Online Casino Australia Real Money
  • Which States Allow Online Gambling
  • Play Keno Online Real Money
  • How To Win Online Blackjack
  • Online Blackjack With Real Dealers
  • How To Open Online Casino
  • What Are The Best Online Slots To Play
  • Big Win Casino Slots
  • Spin Palace Online Casino Australia
  • Best Slots To Win On
  • Casino Slots Win Real Money
  • Slots Magic Online Casino
  • Blackjack Online For Real Money
  • Slot Machine App Win Real Money
  • Online Casino Not Paying Out
  • Slots That Pay Out Real Money
  • Online Pokies Australia Reviews
  • Online Casino Minimum Deposit 1
  • Jackpot City Online Casino Review
  • Live Dealer Baccarat Online Casino
  • Online Casino Apps For Android
  • Online Casino Paypal Deposit Australia
  • Online Casino With Live Dealer
  • How To Play Blackjack Online
  • Slots To Win Real Money
  • Wheel Of Fortune Online Slots
  • Play Quick Hit Slots Online
  • Can You Count Cards In Online Blackjack
  • Palace Of Chance Online Casino
  • How To Play Roulette Online
  • Good Slots To Play
  • Which Online Casino Pays Out The Most
  • Heart Of Vegas Casino Slots
  • Best Online Casino For Canadians
  • Australian Online Pokies Real Money
  • Mohegan Sun Online Casino Nj
  • Online Casino Live Games Best Uk
  • Best Online Casino Australia Reviews
  • Play Pokies Online Real Money
  • Best Online Casino For Usa Players
  • How To Win Online Casino
  • Play Blackjack For Real Money
  • Best Slots On Bovada
  • Online Keno Real Money Usa
  • Online Slots Real Money Paypal
  • Best Poker Sites For Real Money
  • Safe Casino Sites
  • The Best Online Slots
  • Play Keno For Real Money
  • Real Online Pokies Australia
  • Queen Of The Nile Slots
  • Mummys Gold Casino Online Casino
  • Play Keno Online For Real Money
  • Best Poker Websites Real Money
  • Lucky Nugget Online Casino Download
  • Best Online Casino For Roulette
  • Play Roulette For Money Online
  • Video Slots Mobile Casino
  • Best Time To Play Online Slots
  • Best Real Money Online Poker
  • Play Blackjack Online With Friends
  • Play Baccarat Online For Real Money
  • Is Silver Oak Casino Legit
  • Big Fish Casino Real Money
  • Can You Win Real Money On Caesars Slots
  • Game Of Thrones Slots Casino
  • Best Online Slots Payout Percentage
  • Play Online Pokies For Real Money
  • Play Pokies Online Australia
  • High 5 Casino Real Slots
  • The Best Online Pokies
  • Online Pokies That Accept Paypal
  • Heart Of Vegas Slots
  • How To Play Online Roulette
  • Best Poker App Real Money
  • Best Online Casino Fast Payout
  • Best Slots At Wind Creek Casino
  • Online Casino 10 Minimum Deposit
  • Play Roulette Online For Money
  • Us Real Money Poker Sites
  • How To Win In Online Casino
  • Best Online Pokies Australia Review
  • Where To Play Roulette Online For Real Money
  • How To Beat Online Casino Slot Machines
  • Highest Payout Online Slots
  • Best Paying Online Casino Slots
  • Golden Tiger Online Casino Review
  • Online Casino With Live Dealers
  • Play Roulette Online For Real Money
  • Best Slots To Play At Casino
  • Slot Machine Games Win Real Money
  • Most Popular Online Casino Games
  • Casino Slots App Real Money
  • Online Casino Real Money Canada
  • Online Real Money Pokies
  • Online Roulette Game Real Money
  • Online Casino Roulette Real Money
  • Best Place To Play Roulette Online
  • Online Casino Book Of Ra Paypal
  • Online Blackjack With Real Money
  • Play Online Blackjack For Real Money
  • Is There A Slot Machine App For Real Money
  • Royal Vegas Online Casino App
  • Best Casino Slots To Play
  • Most Popular Online Slots
  • Best Way To Win At Slots
  • Slots You Can Win Real Money
  • Play Roulette Online Real Money Usa
  • Online Casino Real Money Paypal
  • Online Casino Australia Legal
  • Treasures Of Troy Slots
  • Online Casino For Us Players
  • Where Can I Play Blackjack Online For Real Money
  • Online Casino Paypal Book Of Ra
  • Online Roulette For Real Money
  • Best Online Blackjack Real Money
  • Poker App For Real Money
  • Jackpot Magic Slots Facebook
  • Best Online Casino Real Money Usa
  • Best Online Casino New Zealand
  • The Four Kings Casino And Slots
  • How To Play Slots Online
  • Best Online Pokies Australia
  • Usa Online Slots Real Money
  • Real Money Casino Android App
  • Online Slot Machines That Pay Real Money
  • Online Pokies Real Money Nz
  • Online Pokies Real Money App
  • Play Igt Slots Online
  • Best Casino Slots To Win Money
  • Online Casino Business For Sale
  • Play N Go Slots
  • Poker Apps For Real Money
  • Lucky Slots Real Money
  • All Slots Online Casino
  • Best Online Pokies Real Money Australia
  • Online Pokies Win Real Money
  • Best Online Casinos For Roulette
  • Pay Slots For Real Money
  • Best Online Poker Real Money
  • Slots App Win Real Money
  • Play Online Roulette For Real Money
  • Is Ignition Casino Legit
  • Wheel Of Fortune Slots Online
  • Lotsa Slots Real Money
  • Video Poker Online Real Money
  • Online Slots Usa Real Money
  • Play Blackjack Online Real Money
  • Jackpot City Online Pokies
  • Video Slots Online Casino
  • Is 888 Casino Legit
  • Online Slot Games That Pay Real Money
  • Prepaid Visa Card Online Casino
  • How To Stop Online Gambling
  • Best Slots To Play Online
  • Online Blackjack For Real Money
  • Slot Apps For Real Money
  • Mobile Slots Win Real Money
  • Newsletter Sign Up

    About Us

    Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

    Social Posts

    See More:

    Contact Us

    Stay Informed

    Join Mailing List

    GLE