
Following on from our fourth post on reporting, monitoring and governance, part five turns to business continuity and disaster recovery (“BCDR”).
If reporting is about staying informed while everything is working, business continuity is about what happens when it isn’t. It’s the part of a fintech outsourcing agreement that can determine whether a disruption affecting the service provider becomes a manageable inconvenience or a major regulatory incident for the regulated entity.
For fintechs and other regulated financial services businesses, effective business continuity and disaster recovery planning is a vital part of regulatory compliance and a key consideration when negotiating any outsourcing agreement.
The regulatory hook itself is short. Paragraph 75(l) of the EBA Guidelines on Outsourcing Arrangements (EBA/GL/2019/02) (the “Guidelines”) requires the outsourcing agreement to oblige the provider to implement and test business contingency plans or, in practice, BCDR plans.
That might sound straightforward, but the brevity is deceptive. As with audit and reporting, almost all of the real negotiation happens in the space the Guidelines leave open.
Recent history makes the point better than any drafting note. The AWS outage of October 2025 knocked out online banking and payment services, affecting businesses from Lloyds and Halifax to Coinbase and PayPal, all because of a single regional fault. Then, in November 2025, a configuration bug in Cloudflare’s systems made large parts of the internet, financial platforms included, unreachable for hours.
Neither was an extraordinary failure. Each was a relatively mundane change that went wrong through a single provider on which a great many regulated entities silently depend. It’s a useful reminder of why cloud outsourcing and third-party risk management matter so much for fintechs and financial services businesses.
Paragraph 75(l) does two things:
What it doesn’t do is prescribe recovery times, testing methodologies, evidence standards or the regulated entity’s role in any of this. Those decisions are left to the parties.
These EBA outsourcing agreement requirements are particularly important for fintechs, payment institutions, electronic money institutions and other regulated firms that rely on third-party providers to deliver critical or important functions.
Why does that matter? For the same reason it mattered when we looked at audit rights: outsourcing does not transfer regulatory responsibility.
A regulated entity that outsources a critical or important function remains accountable to its regulator for the resilience of that function. If the provider’s recovery capability is untested or opaque, the regulated entity cannot credibly demonstrate that the function will survive a serious disruption. However smoothly the service runs day to day, that ultimately creates a compliance exposure.
It’s also worth remembering that paragraph 75(l) is only the contractual half of the picture.
Paragraphs 48 and 49 separately require the regulated entity to maintain and periodically test its own business continuity plans covering the outsourced function. These plans must account for the service degrading, the provider failing or becoming insolvent and, where relevant, political risk in the provider’s jurisdiction.
In other words, the contract secures the provider’s capability. The entity’s own plans must assume that capability could one day fail.
Paragraph 75(l) also has a close companion in paragraph 75(m). This requires the agreement to ensure that the regulated entity can still access its own data if the provider becomes insolvent, enters resolution or discontinues its business operations. We’ll return to that safeguard in our posts on termination and exit.
Proportionality runs through all of this. The depth of the obligations should reflect the criticality of the function, with the most demanding provisions reserved for critical or important outsourced functions.
Continuity also doesn’t sit in isolation. It is one strand of a much wider operational resilience framework and only works when read alongside the neighbouring obligations, including monitoring and reporting rights, service levels, termination and exit rights and the exit-strategy requirements. Those exit provisions are the ultimate fallback when continuity simply cannot be assured.
After all, a recovery-time objective means very little without a service level to measure it against. And a tested plan means very little without a workable exit if the provider still cannot deliver.
The EBA Outsourcing Guidelines set the floor: contingency plans must exist and they must be tested.
Everything else is contractual, and three issues tend to create most of the friction:
As with audit and reporting, each side approaches these questions differently.
For the regulated entity, the priority is having a recovery capability it can genuinely stand behind in front of its regulator. That comes down to two things: control over the plans and visibility of the testing.
When it comes to control, regulated entities want the recovery standard hard-wired into their outsourcing contracts, rather than left to the provider’s discretion.
In practice, that means BCDR plans that are:
The aim is to make sure the plans keep pace with how the service is actually delivered, rather than becoming fossilised at the point the contract is signed.
Regulated entities will also push for recovery objectives, how quickly the service must be restored and the point to which data must be recovered to be clearly defined and binding. A plan that promises to restore the service “eventually” is not especially helpful when a critical function is down.
On visibility, entities want regular testing, with annual testing generally treated as the baseline for critical functions, and genuine sight of the outcome within a defined period.
A testing obligation that the entity cannot verify provides very little assurance. The stronger position is an obligation to share test results proactively within a defined window after each test. That way, a failed or qualified test surfaces automatically rather than staying buried until somebody asks about it.
This also dovetails with the reporting framework covered in our previous post.
Providers tend to push back on both fronts, and paragraph 75(l) gives them some room to do so. It requires contingency plans to exist and be tested, but it does not require customer sign-off on those plans or dictate exactly what must be disclosed.
On control, a provider serving lots of customers cannot realistically operate a bespoke continuity framework tailored to every customer, subject to each customer’s approval and updated frequently across its entire book.
Its preferred position will usually be a single, standardised and well-tested capability. It will resist customer approval rights and recovery commitments that are tighter than those it operates across the platform, reflecting the operational reality of shared infrastructure.
On visibility, providers may also resist disclosing detailed, unredacted test results that could reveal information about their wider platform or other customers.
Instead, they generally prefer to make results available on reasonable request, often in summary form. The distinction between proactive disclosure and disclosure only on request may sound small, but it is quietly important. It determines whether the entity learns about a resilience weakness before or after it matters.
In reality, these positions aren’t as far apart as they might first appear.
When it comes to the plans themselves, a workable landing point preserves the substance the regulated entity genuinely needs: defined and binding recovery objectives, plans built to a recognised standard and a right to see them.
At the same time, it accepts that a large provider is likely to maintain a common framework. Where approval rights are conceded, these are often softened into a right to review the plans and require reasonable changes, rather than giving the entity an open-ended veto.
Of course, much of this will depend on the respective bargaining power of the regulated entity and the provider.
On testing, a sensible compromise combines:
As with the substitute-assurance mechanism we discussed in relation to audits, the important thing is that the assurance is real.
Getting these provisions right often requires more than a standard supplier contract. Fintech outsourcing agreements need to balance regulatory expectations, operational resilience and the commercial realities of shared technology infrastructure.
The regulated entity needs confidence that its outsourced functions are genuinely resilient. But the provider has just as much to gain from offering that assurance as the entity has from receiving it.
A provider that can point to a tested, well-governed recovery capability turns resilience into a selling point rather than a concession. It can shorten customer due diligence, open the door to regulated customers who cannot contract without it and protect the provider’s own reputation when something does go wrong.
A serious outage is likely to bruise the provider at least as badly as its customers. Credible continuity is therefore a shared commercial interest, not simply a cost to be conceded reluctantly.
Business continuity provisions can be easy to wave through as boilerplate. They are anything but.
Paragraph 75(l) makes a tested contingency capability a mandatory feature of any agreement supporting a critical or important function. The drafting then determines whether that capability is one the regulated entity can actually rely on.
Two questions come up in almost every negotiation.
First, does the regulated entity have enough control over the recovery standard, including binding recovery objectives, to stand behind it with its regulator?
Second, does it have genuine and timely visibility of the testing, so it knows whether the plan really works and is likely to work when a failure occurs?
Neither objective needs to conflict with the provider’s need for a standardised and sustainable framework. As with audit and reporting, a well-calibrated continuity clause can work for both sides.
In our next post, we’ll continue working through the mandatory framework by turning to termination rights: the provisions that decide what happens when continuity measures aren’t enough and the regulated entity needs to exit the contract.
If you’re negotiating or reviewing a fintech outsourcing agreement, Founders Law’s fintech regulatory lawyers can help you assess your BCDR provisions, operational resilience requirements and wider outsourcing compliance. Get in touch with our team to discuss how we can help.