Outsourcing and cloud use in German banks
A German bank moving a system to the cloud answers to three layers at once: section 25b KWG and MaRisk in national law, the EBA guidelines on outsourcing arrangements at European level, and DORA for everything that counts as an ICT service. Knowing which layer governs which supplier is the whole job, because DORA took the ICT part and left the rest where it was.
Section 25b KWG and the outsourcing register
Section 25b of the Kreditwesengesetz is the German outsourcing provision. An institution outsourcing activities and processes stays responsible for compliance with its statutory duties, has to agree the rights and duties needed for that, and may not outsource in a way that leaves it unable to be managed properly or that makes supervision impossible.
Alongside it, section 24(1) number 19 KWG requires an institution to notify and to keep records of its outsourcing arrangements. The institution maintains an outsourcing register, and this register is not the DORA register of information: it is driven by materiality and covers outsourced activities, while the DORA register covers all ICT service contracts on a fixed EU data model. A German bank keeps both.
MaRisk AT 9 and the materiality assessment
The outsourcing module AT 9 of MaRisk turns the statutory duty into process. Its central step is the risk analysis that decides whether an outsourcing is material, carried out with the involvement of the affected units before the arrangement is entered into and reviewed when circumstances change.
Everything downstream depends on that one answer. A material outsourcing needs contract contents MaRisk specifies, inclusion in the institution's risk management and internal audit coverage, an exit scenario, and a named outsourcing officer with a central function. The assessment is also the document BaFin reads first, so an analysis that concludes immateriality without naming what would change the answer tends to get tested.
The EBA guidelines, and which parts DORA superseded
The EBA guidelines on outsourcing arrangements, EBA/GL/2019/02, have applied since September 30, 2019 to credit institutions, investment firms, payment institutions and e-money institutions. They set the governance expectations: board oversight of outsourcing, the register with fuller content for critical or important functions, pre-contractual due diligence, contract contents with quantitative and qualitative performance targets, full audit and access rights, and documented exit plans.
DORA then took the ICT services out of that frame. For an ICT service the contract contents and the third-party risk discipline come from Articles 28 to 30 of DORA, which ICT third-party risk management covers. The EBA guidelines keep governing outsourcing that is not an ICT service, so a bank outsourcing a credit administration process applies them and a bank buying a cloud platform applies DORA.
The empty shell test
One EBA requirement has no numeric threshold and decides cases anyway: an institution may not outsource so much that it becomes an empty shell without the substance to remain authorized. The test asks whether the firm retains the people, the knowledge and the systems to direct the provider, judge its output and take the business back.
It bites where a small institution outsources its core banking, its payments processing and its IT operations to the same group of providers and keeps two people to manage them. Each contract may pass its own review while the firm as a whole no longer runs itself, and that is the picture the supervisor assesses.
The notification duty to BaFin
BaFin wants to hear about material outsourcing, and it wants to hear in advance of the intention to outsource a critical or important function. The notifications run electronically through BaFin's reporting platform MVP, under the procedure for outsourcing notifications, which is separate from the yearly register of information submission.
Firms conflate the two routes and file one instead of both. The register of information is an annual data collection on all ICT contracts; the outsourcing notification is an event-driven filing about a specific arrangement. Missing the second is the more visible failure, because it surfaces when the supervisor learns of an arrangement from the register and not from the institution.
Cloud concentration and the supervisory concern
The sector's cloud footprint sits with a small number of providers, and supervisors treat that as a financial stability question and not a procurement one. The European Systemic Risk Board has analyzed systemic cyber risk including the dependence on a limited set of providers, and the designation of critical ICT third-party providers under DORA is the regulatory answer to the same observation.
For an individual bank the practical consequence is the substitutability question. A provider the whole sector uses is not more reliable for being popular, and an exit plan whose destination is the one other hyperscaler does not reduce the sector's concentration at all. What cloud computing is covers the technical side.
The C5 catalog German banks ask providers for
German institutions ask cloud providers for a C5 attestation. The Cloud Computing Compliance Criteria Catalogue, published by the Federal Office for Information Security, defines a criteria set a provider is audited against by an independent auditor, with the result issued as an attestation report.
Its use in practice is to shorten due diligence, not to replace it. C5 covers the provider's controls and includes the environment parameters that state what the provider does not do, so the bank still has to assess the part of the control set that sits on its own side of the shared responsibility line. A C5 report accepted without reading those parameters leaves the gap in the bank's own control.
Intragroup outsourcing, which is in scope
Outsourcing to a parent, a subsidiary or a shared service center of the same group is outsourcing. The EBA guidelines treat it as in scope and expect the conditions to be set at arm's length, and MaRisk requires the same risk analysis as for an external provider.
Firms treat it as internal and skip the steps, which produces the recurring findings: no written agreement, no service levels, no exit scenario because nobody imagines leaving the group, and audit rights nobody documented because the auditor is in the same building. The supervisory view is that a group entity can fail or be sold, and the contract has to work in that case.
What does section 25b KWG require?
That an institution outsourcing activities and processes remains responsible for its statutory duties, agrees the rights and instruction powers it needs to discharge them, and does not outsource so extensively that it can no longer be properly managed or that BaFin can no longer supervise it. The operational detail comes from the MaRisk outsourcing module AT 9, and the notification and record-keeping duty from section 24(1) number 19 KWG.
Do the EBA outsourcing guidelines still apply after DORA?
Yes, for outsourcing that is not an ICT service. DORA governs ICT third-party risk, so for a cloud platform or a software service the contract contents and the risk discipline come from DORA Articles 28 to 30. The EBA guidelines continue to govern other outsourcing, and German law in section 25b KWG and MaRisk AT 9 applies underneath both. A bank therefore classifies each supplier before it chooses the rulebook.
When is an outsourcing material?
When the institution's own risk analysis concludes that a failure or deficiency in the outsourced activity would materially impair its business, its compliance with regulatory duties or its risk situation. MaRisk AT 9 sets no list, which puts the weight on the documented analysis, carried out before the contract and repeated when the service or the provider changes. The answer determines the contract contents, the audit coverage and whether BaFin has to be notified.
Is a cloud service always an outsourcing?
Not automatically. The question is whether the institution has the provider carry out activities and processes that it would otherwise perform itself. Infrastructure for a system the bank runs, a software service that performs a regulated process, and a tool a single team uses for analysis sit at different places on that line. What has changed is that the classification matters less than it used to, because an ICT service that is not an outsourcing is still inside DORA's third-party risk regime and still enters the register of information.
Outsourcing and cloud in banking and Finance Loop
Finance Loop is the meeting place for the outsourcing officers, cloud architects and ICT risk controllers working on these arrangements in German banks. Finance Loop events bring them together with the supervisors who read the notifications and with the providers whose attestations are on the table.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.