ESA technical standards on subcontracting of critical ICT services · Operative for the current register cycle
The permissible position on subcontracting critical or important functions is narrowed, and the entity must be able to identify the chain rather than the immediate provider alone.
Obligations that move
Every ICT arrangement is registered and classified against the critical-or-important test.
Scope widens from the contracting provider to the subcontracted chain supporting the same function.
Each critical arrangement contains the prescribed clause set.
Subcontracting consent and notification move from desirable to load-bearing, because the chain map depends on them.
Controls to retest
C11 · Third-party and outsourcing risk
Register completeness now tested against the chain, not the counterparty.
C25 · Legal risk and contractual enforceability
Legacy contracts without a notification right cannot produce the chain map.
Entities in scope
Irish designated activity company; UK public limited company (group policy alignment)
Evidence gap as it stands
Chain maps exist for cloud and market data. Screening services stop at the third party, and the contract carries no notification right to go further.
Accountable
Head of Third-Party Risk, with Group General Counsel on clause remediation
Institutional deadline
Chain maps complete one full cycle before the first register examination