What rules apply when an investment firm outsources critical or important functions?
Which functions count as critical or important, the conditions for outsourcing them, the extra test for portfolio management outside the EU, and how DORA now governs ICT services.
By the ExamPass CY editorial teamLast reviewed 6 min read
Topic 4 of 12 · all topics in this chapter
On this page
- Short answer
- Outsourcing at a glance
- Which functions count as critical or important?
- What conditions apply to outsourcing a critical function?
- What extra rules apply to portfolio management abroad and to ICT services?
- How to think about it
- Common mistakes
- New EBA guidelines on non-ICT third-party risk
- Legal references
- Practise this topic
Short answer
A function is critical or important if its failure would materially impair the firm's compliance, financial performance or continuity of service. A firm that outsources one stays fully responsible: senior management cannot delegate its responsibility, obligations to clients do not change and the licence conditions stay intact. The provider must be able and authorised to do the work, the firm must keep the expertise to supervise it, and a written agreement secures access, inspection and immediate termination rights. Since 17 January 2025 DORA adds rules for ICT services.
Outsourcing at a glance
| Point | Rule |
|---|---|
| Critical or important | A defect or failure would materially impair compliance with authorisation conditions and obligations, financial performance, or the soundness or continuity of services |
| Not critical or important | Advisory and other services outside the investment business (legal advice, staff training, billing, security of premises and staff); standardised services such as market information and price feeds |
| Responsibility | Stays fully with the firm: no delegation of senior management's responsibility; client relationship and obligations unchanged; authorisation conditions not undermined |
| Provider | Ability, capacity, resources, organisation and any authorisation required, to perform reliably and professionally |
| Firm's controls | Keeps expertise and resources to supervise and manage the risks; can terminate with immediate effect where clients' interests require |
| Written agreement | Rights of instruction, termination, information, inspection and access to books and premises; sub-outsourcing only with the firm's written consent |
| Portfolio management outside the EU | Provider authorised and effectively supervised at home, plus a cooperation agreement between the supervisors |
| ICT services (DORA) | From 17 January 2025: register of all ICT contracts filed with CySEC annually by 28 February; timely notice of planned ICT contracts supporting critical or important functions (and when a function becomes critical or important) |
Source: Delegated Regulation (EU) 2017/565, Articles 30–32; Law 87(I)/2017, Article 17(5); Regulation (EU) 2022/2554, Article 28; CySEC Circulars C604 and C700.
Which functions count as critical or important?
A function is critical or important where poor performance or a breakdown would materially weaken the firm's ability to keep meeting its authorisation conditions and other obligations, its financial results, or the soundness or continuity of the services it provides.
Two groups are excluded. The first is advisory services and other services that are not part of the firm's investment business, such as legal advice, training of staff, billing, and guarding the firm's premises and people. The second is buying standardised services, for example market information or price feeds. These are not treated as critical or important functions, so the extra conditions for outsourcing critical or important functions do not apply to them.
Terms used in this note
- Outsourcing
- An arrangement under which a provider performs a process, service or activity that the firm would otherwise carry out itself.
- Sub-outsourcing
- The provider passing on part of an outsourced function to another provider; allowed only with the firm's written consent.
- Cooperation agreement
- An agreement between CySEC and a non-EU supervisor, required before portfolio management is outsourced to a provider in that country.
What conditions apply to outsourcing a critical function?
The firm remains fully responsible for all its obligations. The outsourcing may not result in senior management delegating its responsibility, may not change the firm's relationship with and obligations to its clients, and may not undermine or alter the conditions of its authorisation. Law 87 adds that the firm must take reasonable steps to avoid undue additional operational risk and must not materially impair the quality of its internal control or CySEC's ability to supervise it.
The firm must use due skill, care and diligence in choosing and managing the provider, which must have the ability, capacity, resources, organisation and any authorisation needed to do the work reliably and professionally. The firm keeps enough know-how and resources in-house to oversee the outsourced function and manage the risks, can terminate the arrangement with immediate effect when that is in its clients' interests without harming continuity, and ensures cooperation with the authorities, access to data and premises for itself, its auditors and CySEC, confidentiality, and tested contingency and backup plans.
Rights and obligations are set out in a written agreement that keeps the firm's rights to give instructions, terminate, obtain information, inspect, and enter premises and see the books. The provider may sub-outsource only with the firm's written consent. Within a group, the firm may take into account how far it controls or influences the provider. CySEC can ask for all the information it needs about outsourced activities.
What extra rules apply to portfolio management abroad and to ICT services?
Outsourcing functions related to portfolio management for clients to a provider outside the EU is allowed only if the provider is authorised or registered for that service in its home country and effectively supervised there, and an appropriate cooperation agreement exists between CySEC and that supervisor. The agreement must at least let CySEC obtain information on request, access relevant documents, learn promptly of breaches and cooperate on enforcement, and supervisors publish the list of such agreements.
Since 17 January 2025, ICT services, including outsourced ICT functions, are also governed by the Digital Operational Resilience Act. The firm remains fully responsible, keeps a register of all its contracts for ICT services, files it with CySEC every year by 28 February (reference date 31 December), informs CySEC in good time of planned contracts for ICT services that support critical or important functions, and includes the mandatory terms in all its ICT contracts, with additional terms for those supporting critical or important functions. Since October 2023 CySEC has also applied the European Banking Authority's outsourcing guidelines to CIFs subject to an initial capital requirement of €150,000 or €750,000.
How to think about it
Responsibility stays with the firm even when the work leaves it. First ask whether the function is critical: would its failure hurt compliance, finances or continuity? If so, check the provider, keep the know-how to supervise it, write everything down, keep the keys (access, inspection, immediate termination) and approve any sub-outsourcing in writing. For portfolio management outside the EU, add supervision at home and a cooperation agreement; for anything ICT, add DORA.
Common mistakes
Believing outsourcing transfers regulatory responsibility. The firm remains fully responsible for the outsourced function.
Treating price feeds or legal advice as critical functions. Standardised services and services outside the investment business are excluded.
Allowing the provider to sub-outsource freely. Sub-outsourcing needs the firm's written consent.
Limiting termination to the end of the contract. The firm must be able to end it immediately when clients' interests require.
Legal references
- Commission Delegated Regulation (EU) 2017/565 (MiFID II organisational requirements and operating conditions), as amended (opens in a new tab)
Article 30 (critical or important functions) · Article 31 (outsourcing conditions) · Article 32 (portfolio management outside the EU)
- The Investment Services and Activities and Regulated Markets Law of 2017 (Law 87(I)/2017), consolidated Greek text on CyLaw (amendments up to Law 183(I)/2025) (opens in a new tab)
Article 17(5) (outsourcing of operational functions)
- Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) (opens in a new tab)
Articles 28–30 (ICT third-party risk)
- CySEC Circular C700 on DORA reporting (register of information and incident reports) (opens in a new tab)
- CySEC Circular C604 on the EBA Guidelines on outsourcing arrangements (opens in a new tab)
Practise this topic
Test what you just read
The Chapter 3 pack has 155 exam-style questions, 12 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 53 free Chapter 3 flashcards →