.png)
Following on from our fifth post on business continuity and disaster recovery, part six looks at what happens when continuity measures are no longer enough: termination.
Business continuity is about keeping a service running through disruption. Termination is about the point at which the regulated entity decides the relationship needs to end, whether that is because the provider has failed, the risk profile has changed or there is simply a better option available to help the entity meet its regulatory obligations. It is also the point at which all those earlier protections, including audit, reporting and continuity, are either proven to work or shown to fall short.
For fintechs and other regulated financial services businesses, termination rights sit at the heart of the outsourcing agreement. Get them right and the regulated entity keeps a genuine ability to move on without disrupting the service it provides to its own customers. Get them wrong and it could find itself locked into a provider it no longer trusts, with no clean way out.
The regulatory hook is set out in paragraph 75(q) of the EBA Guidelines on Outsourcing Arrangements (EBA/GL/2019/02) (the “Guidelines”), which requires an outsourcing agreement to include the termination rights specified in Section 13.4. Section 13.4 itself is made up of just two paragraphs, 98 and 99. But, as with audit and continuity, that short wording leaves plenty of room for negotiation between the parties.
Section 13.4 does two separate things.
First, paragraph 98 requires the agreement to expressly allow the regulated entity to terminate, in accordance with applicable law, including in a defined set of situations:
Second, paragraph 99 requires the agreement to make it possible to transfer the outsourced function to another provider or bring it back in-house. To do that, the written arrangement should:
Put simply, paragraph 98 is about having the right to leave. Paragraph 99 is about being able to leave in an orderly way. Both matter. A contract that delivers one without the other is unlikely to be much use to the regulated entity.
In response to a question about how the Guidelines apply, the EBA confirmed that Section 13.4 is aimed at outsourcing arrangements for critical or important functions. However, entities may choose to apply the same requirements to other arrangements on a risk-based basis, depending on the nature of the function and the risks involved.
The reason is one that runs through this whole series: outsourcing does not transfer regulatory responsibility.
A regulated entity that outsources a critical or important function remains accountable to its regulator for that function. That includes its ability to exit the arrangement if it needs to. If the entity cannot terminate a failing provider, or can only do so by accepting a disorderly collapse of the service, it cannot credibly say that it is in control of the function. The right to terminate, and the ability to do so without breaking the service, are part of what makes the outsourcing arrangement capable of being supervised in the first place.
That is also why termination cannot be considered in isolation. It connects directly to several neighbouring provisions in the Guidelines.
Paragraph 75(m) requires the agreement to ensure that the regulated entity can still access the data it owns if the provider becomes insolvent, enters resolution or discontinues its business. This safeguard prevents termination, or provider failure, from leaving the entity stranded without access to its own data.
For regulated entities, paragraph 75(o) requires a clear reference to the national resolution authority’s powers, particularly under Articles 68 and 71 of Directive 2014/59/EU (the Bank Recovery and Resolution Directive), including a description of the contract’s “substantive obligations”. In practice, this recognises that a resolution authority’s statutory powers may affect how ordinary contractual termination rights operate when an entity is in resolution. In other words, a counterparty cannot simply walk away at the worst possible moment.
Termination rights also only work when combined with the exit-strategy requirements in paragraphs 107 and 108. These require the entity to develop documented - and, where appropriate, tested - exit plans, identify alternative providers or in-house solutions, and define the objectives, roles, resources and trigger indicators for an exit. The contract provides the right and the mechanics to leave. The exit strategy is the entity’s own plan for actually using them.
Proportionality runs through all of this. The depth of the termination and transition machinery should reflect how critical the function is, with the most demanding provisions reserved for critical or important outsourced functions.
As with audit and continuity, the Guidelines set the floor and leave most of the detail to the parties. Section 13.4 says that the entity must be able to terminate and transfer the function out in an orderly way. It does not say how long the notice period should be, how long the transition period should run, what the provider must actually do during it or who should pay for any of it.
Four issues tend to create most of the friction:
As with the earlier posts in this series, each side comes to these questions from a different starting point.
For the regulated entity, the priority is having termination rights it can actually rely on when needed, alongside a transition process that keeps the function running while it moves.
When it comes to the triggers, the entity will want the full paragraph 98 list clearly reflected and will usually push further. It will want the right to terminate for a material or persistent breach, with only a short cure period, or no cure period at all, for breaches that cannot realistically be fixed or that relate to data security or regulatory compliance. It will also want a clear right to terminate following a change of control of the provider, sub-outsourcing that materially increases risk or a deterioration in the provider’s financial condition.
Crucially, it will want to preserve the regulator-driven termination right in paragraph 98(e). This allows the entity to terminate where its competent authority instructs it to do so, for example, where the authority can no longer effectively supervise the entity because of the arrangement. The entity will want this to be an absolute right that the provider cannot easily resist or delay.
The entity will also usually insist on a right to terminate for convenience on reasonable notice. The Guidelines do not require this, but it is the clearest way to ensure that the entity is never structurally locked in. It also supports the exit strategy that the entity is separately required to maintain.
On transition, the entity’s focus is keeping the service running while it moves. It will want a transition period that is clearly defined and long enough for the provider to continue delivering the function at the agreed service levels. During that period, the provider should actively cooperate with any successor provider, return or migrate the entity’s data in a usable format, and provide reasonable knowledge transfer and documentation.
The entity will also want the price of exit and transition assistance, if any, agreed in advance. This stops the provider from holding the exit hostage to a new negotiation at the worst possible time. Regulated entities may also push for these costs to be included within the existing service fees, although providers are likely to resist where the exit assistance goes beyond their standard service offering.
Finally, the entity will want the data-access safeguard in paragraph 75(m) to be genuinely robust, so that the provider’s insolvency, resolution or discontinuation does not cut it off from its own data.
Providers generally accept that regulated customers need termination and exit rights. Their concerns are more likely to be around breadth, open-ended obligations and costs that have not been agreed.
On the triggers, a provider will resist termination rights that can be used on thin or subjective grounds. It will want meaningful cure periods for breaches that can genuinely be remedied, materiality qualifiers for triggers such as change of control or sub-outsourcing, and objective thresholds rather than customer discretion wherever possible. The provider is not usually resisting the paragraph 98 list itself, it can hardly argue with that. The concern is the gold-plating around it.
Termination for convenience is a common sticking point. A provider that has priced a multi-year deal on the basis of a minimum term is likely to resist a broad convenience right. Alternatively, it may seek a minimum commitment, a notice period long enough to redeploy resources or early-termination charges that recover its unamortised investment. This is a legitimate commercial concern, rather than resistance for resistance’s sake, and it is often where much of the negotiation is focused.
On transition, the provider accepts that it must support an orderly exit, as paragraph 99 requires, but it will want that obligation to have clear limits. It is likely to want the transition period capped, the scope of exit assistance defined rather than open-ended and, importantly, exit and transition services charged at agreed rates instead of being provided free of charge. A provider will also resist any obligation to continue providing the service indefinitely where the customer has stopped paying or is itself in breach.
On liability and survival, the provider will want clarity about which obligations continue after termination and for how long. It will resist survival clauses that leave it exposed to open-ended obligations long after the relationship has ended.
In practice, these positions are closer than they may first appear, and the framework in paragraphs 98 and 99 tends to guide the parties towards a workable middle ground.
For the triggers, a sensible landing point uses the full paragraph 98 list as the minimum, keeps the regulator-driven right absolute and treats the remaining triggers proportionately. That usually means immediate termination for serious, incurable, data-related or compliance breaches, with a short and clearly defined cure period for breaches that can genuinely be fixed. Change-of-control and sub-outsourcing triggers are generally qualified by materiality rather than removed altogether.
Termination for convenience is frequently accepted, but balanced with a minimum term, an appropriate notice period or graduated early-termination charges. Those charges should recover genuine unamortised costs rather than operate as a penalty.
On transition, the practical position preserves the substance the entity needs: continued service at agreed levels throughout a defined transition period, active cooperation with any successor, the return or migration of data in a usable format, and reasonable knowledge transfer. In return, the period is capped, the scope of assistance is defined and exit services are charged at pre-agreed rates. This means neither side has to negotiate pricing under pressure at the point of exit.
Agreeing the price of exit at the outset is one of the most valuable things the parties can do, precisely because it removes leverage at the moment when it could otherwise be most dangerous.
As with the substitute-assurance mechanism we discussed in relation to audits, and the tested-continuity capability we covered last time, the important thing is that the right works in practice. A termination right that cannot be exercised without effectively collapsing the underlying function — or an exit obligation with no agreed price — is not much of a protection at all.
Getting these provisions right often requires more than a standard supplier contract. Fintech outsourcing agreements need to balance regulatory expectations, the entity’s need for a genuine exit and the provider’s legitimate interest in recovering its investment and placing reasonable limits around its obligations.
And, just as with continuity, credible exit machinery is not purely a cost for the provider. A provider that offers a clean and clearly defined exit gives regulated customers the confidence they need to sign in the first place. More often than not, knowing they can leave well is part of what makes customers willing to stay.
Termination provisions are easy to dismiss as end-of-contract boilerplate. In regulated outsourcing, they are anything but.
Paragraph 75(q), read alongside Section 13.4, makes both a genuine right to terminate and a genuine ability to transfer the function out in an orderly way mandatory features of any agreement supporting a critical or important function. The drafting then determines whether the regulated entity can actually use those rights.
Two questions come up in almost every negotiation.
First, can the regulated entity terminate when it genuinely needs to- including following a breach, a material change or an instruction from its regulator - without being blocked by cure periods or thresholds that are too generous to the provider?
Second, can it leave in an orderly way, with a transition period, exit assistance, data return and pre-agreed exit pricing that keep the function running while it moves to an alternative?
Neither objective needs to conflict with the provider’s legitimate interest in cure rights, clearly bounded obligations and the recovery of its investment. As with audit, reporting and continuity, a well-balanced termination and exit clause can work for both sides.
In our next post, we will turn to sub-outsourcing under Section 13.1 (paragraphs 76 to 80) of the Guidelines: what happens when a provider hands part of the outsourced function to its own sub-contractor, and how the regulated entity keeps sight of, and control over, the chain that follows.
If you are negotiating or reviewing a fintech outsourcing agreement, Founders Law’s fintech regulatory lawyers can help you assess your termination rights, exit and transition provisions, and wider outsourcing compliance. Get in touch with our team to discuss how we can help.