Banking Law And Critical Ict Provider Supervision Spain .

Banking Law and Critical ICT Provider Supervision in Spain

Spain's regime for banking-law supervision of critical ICT providers is best understood as a combination of:

  1. Spanish banking and outsourcing law;
  2. EU prudential supervision under the SSM;
  3. DORA — Regulation (EU) 2022/2554 on digital operational resilience;
  4. Spanish Banco de España supervisory powers; and
  5. the new EU oversight regime for “critical ICT third-party service providers” (CTPPs).

A key point is that DORA has fundamentally changed the legal position of cloud, software, data-centre, payment-processing and other ICT providers serving financial institutions. Since 17 January 2025, DORA has applied, so the analysis should no longer be based solely on traditional Spanish outsourcing rules.

1. The Spanish legal framework

For banks, the starting point is Law 10/2014 on the regulation, supervision and solvency of credit institutions, together with Royal Decree 84/2015.

Article 22 of Royal Decree 84/2015 permits a credit institution to delegate services/functions to a third party, but only if the delegation:

  • does not hollow out the bank's regulated activity;
  • does not weaken its internal controls;
  • does not impair Banco de España/ECB supervision; and
  • does not transfer the bank's regulatory responsibility to the outsourcing provider.

For essential functions, the regulation is substantially stricter. The bank must maintain appropriate contractual and governance arrangements and the supervisor can impose restrictions according to the criticality of the function.

Banco de España's Circular 2/2016, as subsequently amended, adds detailed requirements concerning outsourcing policies, board oversight, risk assessment, audit, contingency planning, access rights and supervisory access.

A particularly important principle is:

Outsourcing the function does not outsource the bank's regulatory responsibility.

That principle is now reinforced by DORA.

2. DORA: the central legislation

The principal modern instrument is Regulation (EU) 2022/2554 — Digital Operational Resilience Act (DORA).

Banco de España expressly identifies DORA as part of the Spanish framework for ICT in the financial sector.

DORA applies to a wide range of financial entities, including:

  • credit institutions;
  • payment institutions;
  • electronic-money institutions;
  • investment firms;
  • insurance/reinsurance undertakings;
  • certain financial-market infrastructures; and
  • other regulated financial entities.

It regulates five interconnected areas:

ICT risk management → ICT incident management → resilience testing → information/intelligence sharing → ICT third-party risk.

The fifth area is particularly important for critical ICT providers.

3. Who is a “critical ICT third-party service provider”?

DORA distinguishes between an ordinary ICT third-party service provider and a provider designated as a critical ICT third-party service provider (CTPP).

Examples could include large providers of:

  • cloud computing;
  • data hosting;
  • infrastructure;
  • cybersecurity;
  • network services;
  • software/platform services;
  • data processing;
  • other ICT services on which multiple financial institutions depend.

The criticality assessment is not simply based on the provider's turnover.

The EU framework considers factors such as:

  • systemic importance;
  • number and importance of financial entities using the provider;
  • substitutability;
  • impact of failure;
  • degree of concentration;
  • dependence of financial entities on the provider.

DORA's framework has been supplemented by delegated legislation specifying the criteria for designation of CTPPs. Banco de España's regulatory page records the Commission's Delegated Regulation (EU) 2024/1502, which specifies criteria for designating ICT third-party providers as critical.

4. The major legal innovation: direct oversight of the ICT provider

This is the most important distinction from traditional Spanish outsourcing law.

Traditional model

Historically:

Banco de España → bank → ICT provider

The supervisor primarily supervised the bank, and the bank had to ensure that its outsourcing arrangement permitted effective supervision.

Spanish law expressly required that outsourcing not impair Banco de España's supervisory powers.

DORA model

For a designated CTPP:

European Supervisory Authorities → CTPP

while simultaneously:

Banco de España / ECB → financial institution

This creates a form of direct EU-level oversight of the technology provider itself.

The relevant European Supervisory Authority is designated as the Lead Overseer.

Depending on the financial sector involved, this may involve:

  • EBA;
  • ESMA; or
  • EIOPA.

The Lead Overseer can examine whether the CTPP's ICT risk-management arrangements are adequate.

5. What can the Lead Overseer do?

The oversight framework is considerably stronger than ordinary contractual supervision.

The Lead Overseer can exercise powers including:

A. Information gathering

It can require the CTPP to provide information relevant to its ICT-risk management.

B. Investigations

The supervisory authority can investigate the provider's ICT systems and controls.

C. Inspections

The oversight regime permits on-site inspections.

D. Recommendations

The Lead Overseer may issue recommendations concerning:

  • ICT security;
  • resilience;
  • governance;
  • risk management;
  • business continuity;
  • incident management;
  • subcontracting;
  • concentration risks.

E. Corrective measures

Where the provider fails to comply, the DORA framework allows supervisory intervention.

This is important because the provider is no longer merely a commercial supplier to a bank. Once designated critical, it becomes an object of EU financial-sector regulatory oversight.

6. Subcontracting is a major issue

A critical ICT provider may itself rely on another ICT provider.

This creates the classic:

Bank → Cloud Provider A → Subcontractor B → Subcontractor C

problem.

DORA therefore requires financial institutions to understand the ICT supply chain supporting essential or important functions.

The 2025 Commission Delegated Regulation specifically addresses this issue. It requires consideration of:

  • length and complexity of the subcontracting chain;
  • location of subcontractors;
  • where data are processed and stored;
  • concentration;
  • substitutability;
  • geopolitical risk;
  • financial and operational capacity;
  • audit/access rights;
  • continuity implications.

 

The regulation expressly states that reliance on subcontractors does not remove the financial entity's ultimate responsibility for its legal and regulatory obligations.

7. Spanish law already anticipated many of these principles

This is important in an examination or research paper.

Before DORA, Spanish law already imposed stringent requirements concerning outsourcing.

Banco de España Circular 2/2016 required, among other things:

  • a board-approved outsourcing policy;
  • periodic review;
  • risk assessment;
  • internal-audit review;
  • supervisory access;
  • contractual audit rights;
  • contingency plans;
  • exit arrangements;
  • control of subcontracting;
  • avoidance of excessive dependence on a provider.

 

The 2022 amendments expressly addressed subcontracting chains and the location where data are stored and processed.

Consequently, DORA should not be viewed as completely replacing Spanish outsourcing law. Rather, it Europeanises, harmonises and substantially strengthens the existing supervisory model.

8. The “no escape from responsibility” principle

This is one of the most important principles for banking law.

Suppose a Spanish bank outsources its core banking platform to a cloud provider.

The bank cannot defend a regulatory breach by saying:

“The cloud provider caused the failure.”

The regulator's response is essentially:

The bank chose the provider and remains responsible for its regulated business.

This principle appears directly in Spanish law.

Article 22 of Royal Decree 84/2015 provides that delegation does not diminish the bank's responsibility for complying with the obligations attached to its authorisation and operation.

DORA's implementing legislation similarly emphasises that outsourcing does not reduce the ultimate responsibility of the financial entity.

9. Contractual requirements

A bank's ICT contract should therefore not be treated as an ordinary commercial SaaS contract.

For an important/critical function, the agreement should address:

IssueRegulatory importance
Audit rightsVery high
Regulatory accessMandatory/critical
Incident notificationMandatory
Business continuityMandatory
Disaster recoveryMandatory
SubcontractingStrictly controlled
Data locationRisk assessment
Exit strategyEssential
Data portabilityImportant
Service continuityEssential
Security requirementsEssential
Cooperation with regulatorsEssential
Termination rightsImportant
Concentration riskImportant

Spanish supervisory rules already require direct and unrestricted access for the competent authority to relevant information held by the provider, including the ability to verify systems and applications at the provider's premises.

10. Exit strategy and concentration risk

Two concepts are especially important under modern ICT regulation.

A. Exit risk

Imagine that a Spanish bank uses one cloud provider for:

  • customer databases;
  • payments;
  • authentication;
  • mobile banking;
  • disaster recovery.

If the contract ends, the bank may technically have a contractual right to terminate—but practically be unable to move its systems.

That is a digital operational resilience problem.

The regulatory question therefore becomes:

Can the bank realistically migrate to another provider without causing unacceptable disruption?

Spanish supervisory rules have already required contracts to permit withdrawal and to address reasonable withdrawal costs.

B. Concentration risk

If dozens of European banks depend on the same cloud provider, a single technological failure could become a financial-system-wide event.

This explains why DORA does not rely exclusively on individual bank supervision.

It introduces direct oversight of critical ICT providers.

11. Banco de España's role

Banco de España remains extremely important.

Its role includes supervision of relevant Spanish financial institutions and certain payment-system/technology arrangements.

For example, Banco de España's 2026 delegation decision expressly refers to supervisory powers concerning:

  • payment-system operators;
  • payment schemes;
  • payment processors;
  • technological/technical service providers; and
  • ICT risk-management obligations under Spanish/EU law. 

Banco de España also maintains specific DORA reporting arrangements concerning the register of contracts with third-party ICT service providers.

Its 2024 supervisory report records that Banco de España participated in the EU-wide dry run for ICT third-party providers, illustrating the practical transition toward the DORA regime.

12. Payment institutions: an important Spanish example

The Spanish framework is particularly clear for payment institutions.

Royal Decree 736/2019 regulates outsourcing of important operational functions, including IT systems.

Where an important operational function is outsourced, the entity must provide Banco de España with information concerning:

  • the outsourcing arrangement;
  • the contract;
  • its risk assessment;
  • identity of the provider; and
  • other information requested by Banco de España.

Banco de España can impose limitations or oppose the outsourcing where the legal requirements are not satisfied.

This demonstrates that Spanish law already treated ICT outsourcing as a prudential issue, rather than merely a contractual issue.

13. Case law: an important qualification

There is currently a limited body of reported case law specifically interpreting DORA's CTPP regime.

This is unsurprising because DORA only became applicable on 17 January 2025.

Therefore, a good legal analysis should not invent “DORA case law.”

Instead, the relevant jurisprudence comes from EU banking-supervision cases concerning:

  • allocation of supervisory powers;
  • ECB/Banco de España-type supervisory relationships;
  • judicial review of prudential decisions;
  • proportionality;
  • effective supervision;
  • division between national and EU authorities.

Several cases are particularly useful by analogy.

14. Case: Landeskreditbank Baden-Württemberg v ECB

Case C-450/17 P, ECLI:EU:C:2019:372

This is one of the most important cases for understanding the architecture of EU banking supervision.

The issue concerned whether a German development bank should be directly supervised by the ECB under the Single Supervisory Mechanism (SSM).

The Court of Justice upheld the EU supervisory framework and rejected the bank's challenge to its classification.

Importance for ICT-provider supervision

The case demonstrates an important principle:

EU financial supervision can legitimately operate through differentiated levels of supervision where EU legislation establishes the relevant competence.

That principle is highly relevant to DORA.

DORA similarly creates a differentiated architecture:

financial entity → national/ECB prudential supervision

and

critical ICT provider → EU Lead Overseer supervision.

Thus, Landeskreditbank helps explain why the EU can impose a direct supervisory layer even where the underlying financial institution is principally supervised through another authority.

15. Case: Berlusconi / Fininvest v ECB

C-219/17

The Court considered the division of responsibility between national authorities and the ECB in the context of a prudential decision involving a qualifying holding in a bank.

The Court held that the Court of Justice has jurisdiction to review the legality of the ECB's final decision, including the legality of the national preparatory acts on which that decision is based.

Why this matters for ICT supervision

It illustrates a fundamental feature of EU banking supervision:

national administrative action + EU supervisory decision ≠ two completely independent legal silos.

The supervisory process can be integrated.

That is relevant where:

  • Banco de España supplies information;
  • an EU authority undertakes supervisory assessment;
  • an EU-level decision is adopted concerning a critical ICT provider.

The legality of the supervisory chain must remain subject to effective judicial review.

16. Fininvest/Berlusconi v ECB — 2024

Joined Cases C-512/22 P and C-513/22 P

In September 2024, the Court of Justice overturned the earlier position concerning the ECB's 2016 decision opposing Berlusconi's ownership position in Banca Mediolanum, holding that the circumstances did not constitute a new acquisition requiring the relevant EU-law assessment.

This case is particularly useful for two propositions:

1. Supervisory powers must have a valid legal basis

A financial supervisor cannot simply extend an existing power to circumstances that fall outside the statutory trigger.

2. Non-retroactivity matters

Regulatory powers must be applied within the temporal and substantive limits established by EU legislation.

These principles will become increasingly important in litigation concerning DORA enforcement.

17. Likely future DORA litigation

Although direct DORA case law is still developing, several areas are likely to generate litigation.

A. Whether an ICT provider was correctly designated “critical”

A provider might argue that the designation criteria were incorrectly applied.

B. Proportionality of supervisory measures

A CTPP could challenge an intrusive supervisory requirement as disproportionate.

C. Subcontracting restrictions

Providers may challenge requirements concerning:

  • subcontractor selection;
  • data location;
  • third-country subcontractors;
  • concentration;
  • audit rights.

D. Confidentiality and trade secrets

A provider may argue that disclosure of technical architecture or security information infringes:

  • trade secrets;
  • confidentiality;
  • intellectual-property rights.

E. Extraterritorial questions

Cloud providers often operate globally.

This creates difficult questions concerning:

  • third-country law;
  • data access;
  • government requests;
  • conflicting regulatory obligations;
  • sovereignty;
  • operational resilience.

F. Judicial review

Following Fininvest/Berlusconi, the precise division between:

national competent authority → EU supervisory authority → regulated entity/provider

will be an important procedural question.

18. A useful hypothetical

Consider:

Spanish Bank A outsources its core banking infrastructure to Cloud Provider X.

Cloud Provider X serves 200 European banks.

A major outage disables:

  • payments;
  • online banking;
  • ATM services;
  • customer authentication.

Under traditional Spanish outsourcing law

Banco de España asks:

  1. Did Bank A conduct adequate due diligence?
  2. Did the board approve the outsourcing?
  3. Was the function essential?
  4. Was the contract adequate?
  5. Could Banco de España audit the provider?
  6. Did Bank A maintain a contingency plan?
  7. Could the bank exit the relationship?

Under DORA

Additional questions arise:

  1. Is X an ICT third-party provider?
  2. Is X a critical ICT third-party provider?
  3. What other European banks depend on X?
  4. Is there systemic concentration?
  5. What subcontractors does X use?
  6. Where are data processed?
  7. What is X's incident-management capacity?
  8. Can X demonstrate operational resilience?
  9. Can the Lead Overseer conduct inspections?
  10. Can the financial institutions realistically migrate away from X?

This is the fundamental shift from outsourcing risk to systemic ICT concentration risk.

19. Legal relationship — simplified diagram

                 EUROPEAN UNION                       │                       ▼             DORA Regulation 2022/2554                       │          ┌────────────┴─────────────┐          │                          │          ▼                          ▼ Financial Institutions       Critical ICT Providers          │                          │          │                          ▼          │                  Lead Overseer          │                (EBA/ESMA/EIOPA)          │                          │          ▼                          ▼ ECB / Banco de España       Direct ICT oversight          │          ▼ Spanish bank          │          ▼ ICT Provider          │          ▼ Subcontractors / cloud chain

 

20. Key legal principles for an examination

If this is for a banking law / financial regulation exam, I would remember these seven principles:

Principle 1 — Outsourcing does not transfer responsibility

The bank remains responsible.

Principle 2 — Supervisory access cannot be outsourced away

The contract must allow regulators effective access.

Principle 3 — Criticality determines regulatory intensity

The more important the ICT function, the stronger the controls.

Principle 4 — ICT risk is prudential risk

A cyber or cloud failure can affect:

liquidity + solvency + continuity + consumer protection + financial stability.

Principle 5 — Subcontracting creates chain risk

The bank must understand the relevant ICT supply chain.

Principle 6 — Concentration is a systemic issue

Multiple banks depending upon the same provider can create systemic vulnerability.

Principle 7 — DORA adds direct oversight of critical ICT providers

This is the major innovation compared with the older Spanish outsourcing framework.

21. Conclusion

The Spanish position can therefore be summarised as follows:

Spanish banking law historically regulated ICT outsourcing indirectly through the regulated financial institution. DORA adds a European layer of direct oversight for ICT providers designated as critical.

Before DORA, the principal regulatory concern was:

“Has the bank outsourced safely?”

Under DORA, the question becomes broader:

“Is the entire financial system resilient against the failure of the ICT ecosystem on which it depends?”

Spanish law remains highly relevant because Banco de España continues to supervise Spanish financial institutions and certain payment/technology arrangements. At the same time, the DORA CTPP framework shifts part of the regulatory focus directly onto the major ICT providers themselves. Banco de España's current materials expressly incorporate DORA and its delegated/implementing measures into the Spanish supervisory framework.

The most useful case-law authorities for the supervisory architecture, rather than DORA-specific interpretation, are Landeskreditbank Baden-Württemberg v ECB, C-450/17 P, and the Fininvest/Berlusconi litigation, C-219/17 and joined C-512/22 P/C-513/22 P.

Core authorities to cite: DORA (Regulation (EU) 2022/2554); Royal Decree 84/2015, Art. 22; Banco de España Circular 2/2016, especially Normas 43–43 quater; Royal Decree 736/2019, Art. 15; and the DORA delegated regulations on CTPP designation and ICT subcontracting.

LEAVE A COMMENT