Back to glossaryLaw & regulation

Outsourcing of critical functions

Prudential regime permitting the outsourcing of an essential activity while keeping full responsibility with the undertaking, subject to prior notification and supervisory access to the provider.

Definition

Outsourcing claims handling, IT or the actuarial function is permitted; offloading the matching responsibility is not. The regime rests on four mutually reinforcing obligations. The undertaking remains fully responsible for meeting all of its obligations, and the supervisor addresses it, never the provider. Outsourcing must not impair the quality of the governance system, unduly increase operational risk, or undermine the supervisor's ability to verify compliance. Any outsourcing of a critical or important activity must be notified in advance, as must a material change during the contract. The contract must finally guarantee the supervisor and auditors effective access to the provider's premises and data, including where the provider is established outside the Union, a condition that in practice runs into the large cloud providers. DORA hardened that last requirement for information technology providers by imposing minimum contractual content and an exhaustive register of information, and by placing providers deemed critical under direct European oversight.

Example

Article 49 of Directive 2009/138/EC, supplemented by the DORA regulation applicable since January 17, 2025. A European insurer migrating its policy administration system to a cloud provider established in the United States must notify the operation to its supervisor, record the contract in the DORA register of information, and obtain by contract an on-site audit right the provider rarely grants without sector-level negotiation.

Related terms
Also known as

externalisation, outsourcing, fonction importante ou critique, politique d'externalisation