← Back to DORA Library
EUIn ForceFinal

RTS on Subcontracting (EU) 2025/532

Commission Delegated Regulation (EU) 2025/532 of 24 March 2025 supplementing Regulation (EU) 2022/2554 with regard to regulatory technical standards specifying the elements that a financial entity has to determine and assess when subcontracting ICT services supporting critical or important functions

European Commission
Updated Jul 2, 2025
vFinal

Abstract

Regulatory Technical Standards under DORA (Article 30(5)) specifying the elements financial entities must consider and assess when ICT third-party service providers subcontract ICT services supporting critical or important functions. Covers proportionality based on risk profile and complexity, group application, due diligence and risk assessment prerequisites, contractual conditions for permitted subcontracting, requirements to manage and approve material changes in subcontracting chains, and termination rights where subcontracting increases risk beyond tolerance or breaches agreed conditions.

Key Takeaways

  • Requires financial entities to consider size, risk profile, and complexity factors (e.g., subcontracting chain length, data locations, concentration, transferability) when permitting subcontracting for ICT services supporting critical or important functions.
  • Mandates pre-contract due diligence and risk assessment to ensure the ICT third-party provider can identify subcontractors, provide necessary information, and flow down rights and obligations (including access, audit, and inspection) across the subcontracting chain.
  • Sets contractual requirements defining which services are eligible for subcontracting, monitoring/reporting obligations, data-location elements, continuity expectations, and security standards to be imposed on subcontractors.
  • Introduces governance for material changes to subcontracting arrangements, including advance notification, reasonable notice periods, and approval/objection mechanisms.
  • Establishes termination triggers where a provider implements non-permitted subcontracting or material changes without required approval or despite objections.

Keywords

EU 2025/532Commission Delegated RegulationDORARegulation (EU) 2022/2554Article 30(5)ICT subcontractorssubcontracting chaincritical or important functionsmaterial changesaccess audit inspection rightstermination rights

Need DORA-Aligned AI Architecture?

We build AI systems that satisfy DORA requirements from day one. Audit trails, governance, exit readiness - built in, not bolted on.

Schedule Architecture Reviewviktor@intellectumlab.com | Response within 24 hours