The ECB guide on outsourcing cloud services
The ECB's Guide on outsourcing cloud services to cloud service providers sets out what the European Central Bank expects from the banks it supervises directly when they move systems to the cloud. The ECB finalized it on July 16, 2025, after a public consultation that drew 696 comments from 26 respondents. The guide is not legally binding and adds no rules beyond DORA. It explains how the ECB reads DORA's third-party requirements and which practices it treats as good.
Its weight comes from use. The Joint Supervisory Teams take the guide as a benchmark in their assessments, and according to Jones Day they are expected to ask for documented evidence in the 2026 supervisory cycle.
Scope and risk assessment
The guide covers infrastructure, platform and software as a service in public, private, community and hybrid clouds. It also reaches providers that are not cloud firms themselves but run a critical or important function on cloud infrastructure, so an AI service or a payment platform bought as software falls under the same expectations as a rented server. The management body keeps the final responsibility for ICT risk.
Before signing, the bank assesses each cloud arrangement for lock-in, concentration, multi-tenancy, data protection, geopolitical risk and chains of subcontractors. Anneli Tuominen, member of the ECB's Supervisory Board, named the reason in the press release: banks rely on cloud services from a handful of providers.
Data location and encryption
The guide sets no limit on the number of storage locations. It expects banks to keep data in approved jurisdictions, chosen with an eye on legal and political risk, and to check with tracing tools where the data actually sits, as Hogan Lovells summarizes. The pages on data residency and the CLOUD Act cover the two questions behind that list: where the data is and which state can demand it.
Data should be encrypted in transit and at rest and, where feasible, in use, which is the field of confidential computing. The keys a provider uses for a bank's data should be unique to that bank, and key management needs audit procedures of its own.
Resilience, exit and termination
For critical or important functions, the guide suggests hybrid architectures or several cloud or backup providers whose data centers do not overlap. Disaster recovery plans are tested at least once a year under several failure scenarios, and the bank tests the provider's recovery plans itself instead of relying on certificates alone.
Exit strategies have to exist before a critical service goes live, with timelines, costs, staff, identified alternatives and transition periods, and they are tested at intervals with an independent review. The guide adds termination rights for events such as a change in the applicable law or the relocation of the data center that hosts the bank. The page on cloud exit strategy sets out how DORA, the ECB and BaFin fit together on this point.
Audit and oversight
A bank may not outsource the verification of compliance itself. Internal audit cannot rely solely on third-party certifications or SOC reports, so an attestation under BSI C5 or ISO 27001 is evidence to read, not a substitute for the bank's own work. The ECB encourages joint audits by groups of supervised banks, with at least one technical expert from each institution, and monitoring tools of the bank's own next to those the provider offers.
Upcoming events on digital infrastructure
Is the ECB cloud outsourcing guide binding?
No. Like other ECB guides it lays down no legally binding requirements and adds nothing to DORA. In practice the Joint Supervisory Teams compare a bank's cloud set-up against it, so a gap is likely to come up in a supervisory dialogue.
Which banks does the ECB guide apply to?
It is written for the credit institutions under direct ECB supervision in the Single Supervisory Mechanism, the significant institutions. Smaller banks in Germany are supervised by BaFin and the Bundesbank, whose own notice on cloud outsourcing from February 2024 covers much of the same ground.
How does the ECB guide relate to DORA?
DORA and its technical standards set the law. The guide marks which statements repeat DORA requirements and which are the ECB's recommended practices, a split the final version draws more clearly than the consultation draft. It also explains how proportionality applies to smaller arrangements.
The ECB cloud guide and Finance Loop
Finance Loop is based in Frankfurt, the seat of the ECB, and brings together the people at banks who answer the Joint Supervisory Teams on cloud questions and the people at providers who have to deliver the evidence. Finance Loop covers the guide in its Digital Infrastructure & Sovereignty track, and a provider or advisory firm can present its reading of it to banks through a sponsored webinar.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.