Cloud exit strategy for banks under DORA

A cloud exit strategy is the documented plan for leaving a cloud provider without stopping the service that runs on it. For banks and payment firms in the EU it is a legal duty: Article 28(8) of DORA requires exit strategies for every ICT service that supports a critical or important function, and the plans have to be documented, tested and reviewed at intervals.

The plan answers a technical question with a supervisory deadline. Can the core banking system or the AI model on rented accelerators move to a second provider, or back in-house, while customers keep being served?

Storage drives packed for a data-center migration beside a server cabinet

What DORA requires

Article 28(8) names the scenarios an exit strategy has to cover: the provider fails, its service deteriorates, or the contract ends for one of the reasons listed in Article 28(7). In each case the firm must be able to leave without disrupting its business or its regulatory compliance, and without harm to the services its clients receive. The firm identifies an alternative, either another provider or its own infrastructure, and writes transition plans that move the service and the data in a controlled way.

The contract carries the other half. Article 30(3)(f) requires contracts for critical or important functions to contain exit strategies, in particular a mandatory adequate transition period during which the provider keeps delivering the service. The exit also shows up in the register of information, where every ICT arrangement is listed with the function it supports.

What the ECB and BaFin expect from an exit plan

The ECB published its Guide on outsourcing cloud services in July 2025. It is not legally binding, but the Joint Supervisory Teams use it as a benchmark. According to the summary by Jones Day, the guide expects exit strategies for all critical or important cloud services before go-live, with timelines, costs, resources, identified alternatives and transition periods, periodic tests with realistic costs, an independent review and an updated list of qualified alternative providers. Hogan Lovells counts seven additional termination triggers in the guide, among them a merger or sale of the provider and the relocation of the data center that hosts the bank.

In Germany, the BaFin supervisory notice on cloud outsourcing of February 2024 asks for exit plans built on scenarios that refer to the specific cloud services in use, including the unexpected permanent loss of those services. The plans are to be documented and tested, with the resources, time frames, responsibilities and support needed on both sides, and the bank should consider using different cloud providers.

Where exits fail in practice

Architecture decides whether an exit is possible at all. A managed database or an AI service that exists at one provider only has no equivalent elsewhere, so leaving means rewriting the application. Workloads packaged in containers and described as infrastructure as code can be rebuilt on a second platform and tested there, and then the exit plan becomes something a team can run. An AI model needs its own entry: the plan names the substitute model and says how prompts and the retrieval index move, a portability issue for AI infrastructure in banking.

The contract is the second weak point. Writing in IT Finanzmagazin, two Deloitte risk advisors point out that notice periods have to match the exit options in the strategy, and that individual terms are hard to negotiate with the large hyperscalers. The EU Data Act now gives every cloud customer a statutory floor, with a notice period of at most two months and a standard transition period of 30 days, with extensions possible where the regulation permits them. Switching charges end on January 12, 2027, with the timing explained under Data Act cloud switching. The vendor Upsun argues that running production on several clouds at once duplicates infrastructure and staff without guaranteeing portability, so multi-cloud does not remove the need for a plan.

A technical exit test needs data outside the current provider. Arvato Systems recommends independent backups and regular restore tests. Check metadata and permissions as well: an exported dataset is usable only when the target application can read it correctly and the intended access controls work.

The budget should include parallel operation during migration and the capacity of the future operations team. OpenMetal explains these costs alongside the technical move. Record who will run the target environment and which tests must pass before the old service can be shut down.

Exit planning for the 19 critical providers

On November 18, 2025 the European Supervisory Authorities designated 19 critical ICT third-party providers, among them Amazon Web Services, Google Cloud, Microsoft, Oracle, SAP and Deutsche Telekom. Direct EU oversight of these providers does not take the exit duty off the bank. As a last resort, a supervisor can require financial entities to suspend or end their use of a critical provider that ignores the overseer's recommendations, and a bank in that position needs an exit plan it has already tested.

Upcoming events on digital infrastructure

Is a cloud exit strategy mandatory for banks?

Yes, for every ICT service that supports a critical or important function. DORA Article 28(8) applies to banks, insurers, investment firms, payment and e-money institutions and crypto-asset service providers. For services that support other functions, the firm decides in proportion to the risk, and the register of information records which category each contract falls into.

What is the difference between an exit strategy and an exit plan?

The exit strategy is the firm's approach: which alternatives exist, which events trigger an exit and who decides. The exit plan belongs to one service or contract and lists the steps, the time line, the data migration, the costs and the people who carry it out. BaFin's notice uses the same split, with an exit strategy that identifies alternatives and exit plans written for the cloud services in use.

Does a multi-cloud setup replace an exit plan?

No. The ECB guide names hybrid or multi-cloud architectures as a resilience measure for critical functions, and BaFin asks banks to consider a second provider. Both still expect a documented, tested plan for leaving each provider, because a workload that runs at two providers can still depend on a service that only one of them offers.

How often should a cloud exit plan be tested?

DORA asks for plans that are tested and reviewed at intervals and sets no fixed frequency. The ECB guide expects periodic tests with realistic costs and an independent review, and it asks for disaster recovery tests at least once a year under several failure scenarios. A test that moves real data to the alternative environment says more than a desk review of the document.

Cloud exit strategy and Finance Loop

Finance Loop brings together the cloud architects and outsourcing officers of banks and payment firms who write and test exit plans, in its Digital Infrastructure & Sovereignty track. Finance Loop offers providers and banks a stage for a tested exit through a sponsored meetup or a webinar, and membership opens the network to people who work on the same questions.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.