Skip to main content
DORA Auditor

Exit Strategy

Last updated: 1 authoritative sourceDORA Auditor Editorial Team

An exit strategy is the documented plan a financial entity keeps for ending an ICT third-party arrangement supporting a critical or important function without disrupting its business or its compliance with regulatory requirements. DORA Article 28(8) requires one for every such arrangement, covering both orderly termination and forced exit scenarios.

Detailed explanation

Outsourcing a critical function creates dependency, and DORA treats the ability to leave a provider, on the entity's own timeline or in a crisis, as a core resilience control rather than a contractual afterthought. Article 28(8) requires financial entities to prepare exit plans for ICT services supporting critical or important functions, covering both a managed transition (for example, at contract renewal or after a poor audit) and a disorderly exit forced by provider failure, insolvency, or a supervisory intervention such as a critical-provider oversight measure. A credible exit strategy identifies alternative providers or in-house substitution options, sets out data-portability and migration steps, and estimates the transition timeline and cost, so the entity is not negotiating these terms for the first time under pressure. Exit provisions also have to be reflected in the underlying contract itself, per Article 30, including data-return and deletion commitments once the arrangement ends. Supervisors treat a missing or untested exit plan, alongside weak concentration-risk assessment, as one of the clearest signs that third-party risk is not actually being managed, only recorded.

In context

This term relates to the ICT Third-Party Risk pillar and is grounded in DORA Article 28.

Related terms

Sources

  1. DORA Article 28(8), EUR-Lex