Regulation explainerManaged Services

DORA, EBA, PRA and HIPAA rules for outsourced operations, clause by clause

When a regulated firm hands an operation to a provider, it stays accountable for the result. DORA sets binding contract terms for ICT services in the EU financial sector, the EBA, EIOPA and the UK PRA add expectations for outsourcing more broadly, and HIPAA governs US health data that vendors handle. This explainer maps each instrument to the clauses and oversight a managed-services contract needs.

Reviewed 7 min read

On this page
  1. Who is in scope and why managed operations count
  2. The instruments a regulated buyer has to map
  3. Dates and versions to confirm before signing
  4. DORA Article 30: what every contract needs and what critical functions add
  5. Mapping requirements to clauses, with the AI-specific additions
  6. Ongoing oversight once the contract is signed
  7. Questions and answers
  8. Sources

Who is in scope and why managed operations count

The Digital Operational Resilience Act, Regulation (EU) 2022/2554, has applied since 17 January 2025 to a long list of EU financial entities, including credit institutions, payment and e-money institutions, investment firms, and insurance and reinsurance undertakings1. Its rules on ICT third-party risk cover any arrangement for ICT services, which the regulation defines broadly as digital and data services provided through ICT systems on an ongoing basis.

A managed service in which software agents process claims, reconciliations or KYC files on the provider's platform is very likely to include ICT services, even where people do part of the work. Parts of a service that are not ICT, such as a team handling paper post, fall under outsourcing rules instead. In US healthcare, a provider that creates, receives, maintains or transmits protected health information for a covered entity is a business associate and needs a written agreement.

Every one of these regimes keeps responsibility with the regulated firm. DORA states plainly that financial entities using ICT third-party services remain fully responsible for complying with their obligations (Article 28)1. The contract and the oversight around it are how that responsibility is exercised.

The instruments a regulated buyer has to map

Digital Operational Resilience Act (Regulation (EU) 2022/2554)

European Union

Applies whenAn EU financial entity uses ICT services from a third party, including AI platforms and operations delivered through the provider's systems1.

  • Manage ICT third-party risk within the ICT risk management framework, under a written strategy and policy (Article 28).
  • Keep a register of information on all ICT service arrangements, using the templates in Implementing Regulation (EU) 2024/29562.
  • Include the contractual provisions of Article 30, with additional terms where the service supports a critical or important function.
  • Put exit strategies in place for ICT services supporting critical or important functions (Article 28(8)).

Commission Delegated Regulation (EU) 2024/1773

European Union

Applies whenAn ICT service supports a critical or important function of a financial entity in DORA's scope3.

  • Adopt a policy on contracts for such services that the management body reviews.
  • Assess risks and carry out due diligence before contracting, then monitor performance and update the assessment.
  • Document and test an exit plan for each contract.

EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02)

European Union (banking and payments)

Applies whenA credit institution, investment firm, payment or e-money institution outsources a function, including non-ICT work; the EBA has finalised replacement guidelines covering non-ICT third-party risk4.

  • Assess whether the function is critical or important before outsourcing it.
  • Keep a register of outsourcing arrangements and inform the competent authority of planned critical or important outsourcing.
  • Contract for access, audit and information rights, conditions on sub-outsourcing and an exit strategy.

Solvency II outsourcing rules (Directive 2009/138/EC, Article 49)

European Union (insurance)

Applies whenAn insurer or reinsurer outsources a function or activity6. EIOPA's separate cloud outsourcing guidelines are listed as ending on 17 January 2025, when DORA began to apply to ICT arrangements5.

  • Remain fully responsible for outsourced functions and activities.
  • Do not outsource critical or important operational functions in a way that impairs the system of governance, unduly increases operational risk or hampers supervision.
  • Notify the supervisor before outsourcing critical or important functions.

PRA Supervisory Statement SS2/21, Outsourcing and third party risk management

United Kingdom

Applies whenA PRA-regulated bank, building society, PRA-designated investment firm or insurer outsources a function or relies on another third party7.

  • Assess materiality and notify the PRA of material outsourcing.
  • Cover data security, access, audit and information rights, and sub-outsourcing in written agreements.
  • Maintain business continuity and exit plans for material arrangements, including an unplanned or stressed exit.

HIPAA Privacy and Security Rules, 45 CFR § 164.504(e)

United States (health)

Applies whenA provider handles protected health information on behalf of a covered entity or another business associate8.

  • Sign a business associate agreement limiting use and disclosure of protected health information.
  • Safeguard electronic health information under the Security Rule and report breaches and other unauthorized uses.
  • Flow the same terms down to subcontractors, and return or destroy the information at termination where feasible.

Dates and versions to confirm before signing

DORA Article 30: what every contract needs and what critical functions add

Contract areaAll ICT service contracts (Article 30(2))Critical or important functions add (Article 30(3))
Service descriptionA clear description of all functions and services, and whether subcontracting is allowed and on what conditionsFull service level descriptions with precise quantitative and qualitative performance targets
Locations and dataWhere services are provided and data processed, with notice of changes, and provisions on data protectionNotice periods and reporting duties for developments that could materially affect the service
Return of dataAccess, recovery and return of data in an easily accessible format on insolvency, resolution, discontinuation or terminationExit strategies, including a mandatory adequate transition period
Incidents and continuityAssistance with ICT incidents related to the service, at no extra cost or at a cost agreed in advanceImplementation and testing of business contingency plans
Supervision and auditFull cooperation with competent and resolution authoritiesUnrestricted rights of access, inspection and audit for the firm, its appointees and the authority
Termination and testingTermination rights with minimum notice periods, and participation in security awareness and resilience trainingParticipation in the firm's threat-led penetration testing where it applies

Paraphrased from Article 30 of Regulation (EU) 2022/25541. Use the article's own wording when drafting.

Mapping requirements to clauses, with the AI-specific additions

RequirementClause to draftAddition for AI-run operations
Register of informationThe provider supplies the data fields your register needs and notifies subcontractor changesModel vendors and hosting regions that support the service appear as subcontractors
Access, audit and informationRights for you, your auditors and your regulator to inspect premises, systems, records and staffAccess to prompts, configurations, model versions, evaluation results and decision logs
Incident notificationNotification fast enough for you to meet your own duty to report major ICT incidents (DORA Article 19)A material quality failure in automated decisions counts as a notifiable incident under the contract
SubcontractingConditions, approval or objection rights, and flow-down of obligationsSwitching the underlying model or hosting provider is treated as a subcontracting change
Exit and transitionExit plan, transition assistance, data return format and a transition periodReturn of prompts, configurations, any training data you supplied, and documentation to rebuild the workflow
US health dataA business associate agreement covering permitted uses, safeguards, breach reporting, subcontractors and terminationAn explicit statement on whether health information may be used to improve models; by default, it should not be

Ongoing oversight once the contract is signed

0 of 6 checked

Questions and answers

Does DORA apply if the managed service uses people as well as AI?

Usually, for the ICT parts. If the provider delivers the service through its own systems, platforms or software agents, those elements are ICT services under DORA even though people also work on the cases. Purely manual elements fall under outsourcing rules instead, so many contracts have to satisfy both sets of requirements.

Is an AI-run operations service a critical or important function?

That is your firm's assessment, not the provider's. Under DORA, a function is critical or important if disrupting it would materially impair financial performance, the soundness or continuity of services, or compliance with authorisation conditions. Claims handling, payments operations and KYC often meet that test; a marketing reporting service usually does not.

Do UK firms need to follow DORA?

Firms regulated only in the UK follow the PRA's SS2/21, FCA requirements and the UK operational resilience rules rather than DORA. UK groups with EU-regulated subsidiaries may need contracts that satisfy both, which is manageable because the regimes ask for broadly similar clauses on audit, data, continuity and exit.

Can a HIPAA business associate train AI models on patient data?

Only within what the business associate agreement and the Privacy Rule permit. A business associate may use protected health information only as the agreement allows, so using it to improve models for other customers needs explicit, lawful permission. Most covered entities should prohibit it by default and decide case by case.

Sources

  1. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) — EUR-Lex · checked 10 October 2026
  2. Commission Implementing Regulation (EU) 2024/2956: standard templates for the register of information — EUR-Lex · checked 10 October 2026
  3. Commission Delegated Regulation (EU) 2024/1773: policy on ICT services supporting critical or important functions — EUR-Lex · checked 10 October 2026
  4. Guidelines on third party risk management (non-ICT services) — European Banking Authority · checked 10 October 2026
  5. Guidelines on outsourcing to cloud service providers — EIOPA · checked 10 October 2026
  6. Directive 2009/138/EC on the taking-up and pursuit of the business of insurance and reinsurance (Solvency II) — EUR-Lex · checked 10 October 2026
  7. SS2/21 Outsourcing and third party risk management — Prudential Regulation Authority · checked 10 October 2026
  8. 45 CFR § 164.504 Uses and disclosures: organizational requirements — Electronic Code of Federal Regulations · checked 10 October 2026
  9. The EBA publishes its final Guidelines on the management of third-party risk — European Banking Authority · checked 10 October 2026

More in Managed Services

Back to Managed Services

Next step

Check an outsourcing contract against DORA before you sign

Send the draft service schedule and tell us which functions you consider critical or important. We will mark where the AI-specific terms on audit access, model changes, incidents and exit are missing, so your legal team can close the gaps.

Review a contract schedule