AI Regulation Tracker · ECB · Guidance

What does ECB Guide on outsourcing cloud services say about AI in banking?

Published Jul 16, 2025 · Last reviewed Oct 5, 2026

The ECB published the final Guide on outsourcing cloud services to cloud service providers on 16 July 2025, after a public consultation that ended in July 2024 and drew 696 comments from 26 respondents. It states the ECB's supervisory expectations for banks it directly supervises and recommends good practices, and it clarifies how DORA's third-party rules apply to cloud; it does not introduce new rules beyond DORA and is not legally binding. Its main themes are governance and ex ante risk assessment, availability and resilience, data security and data location, exit strategies and termination rights, and independent monitoring and audit of cloud providers. Because AI at banks is overwhelmingly delivered through cloud platforms, the Guide is the practical standard the ECB's joint supervisory teams apply to hosted AI services.

OFFICIAL TEXT: bankingsupervision.europa.eu ↗ · IN FORCE · ECB

DocumentECB Guide on outsourcing cloud services — ECB Guide on outsourcing cloud services to cloud service providers
Issued byEuropean Central Bank — Banking Supervision (SSM)
TypeGuidance
StatusIn force
PublishedJul 16, 2025
Applies toInstitutions directly supervised by ECB Banking Supervision (significant institutions in the euro area and participating Member States); the same expectations apply when a non-cloud third-party provider relies on cloud services that underpin a critical or important function. Not legally binding
Official sourcebankingsupervision.europa.eu ↗
Use casesThird-party & vendor AI · Cybersecurity · Generative & agentic AI · Data & privacy · AI governance (general)

What are the key points of ECB Guide on outsourcing cloud services?

  • Status: final Guide published 16 July 2025; like other ECB Guides it 'does not lay down legally binding requirements' and does not introduce rules beyond DORA, but sets out how the ECB will assess compliance; it also separates DORA requirements from recommended good practices.
  • Scope (section 1.2): outsourcing of cloud services to cloud service providers by directly supervised institutions, read with the proportionality principle in Article 4 of DORA; expectations also apply where a non-cloud third-party provider relies on cloud services underpinning critical or important functions.
  • Governance (section 2.1): the management body bears ultimate responsibility for ICT risk (DORA Article 5(2)) and the institution stays fully responsible for outsourced cloud services under Article 28(1); good practice is to apply the same diligence as if the service were in-house.
  • Ex ante risk assessment (section 2.1.2): required before contracting under Article 28(4) of DORA; should cover concentration and lock-in risk (Article 29), and for critical or important functions the risks of long sub-outsourcing chains (Article 29(2)).
  • Availability and resilience (section 2.2): business continuity measures must account for the cloud provider's ability to terminate access, and the ECB recommends a holistic business continuity approach and assessment of the provider's disaster recovery plan.
  • Data security and location (section 2.3): security measures, risks from the location and processing of data, inclusion of outsourced assets in the institution's asset inventory, and identity and access management for cloud services.
  • Exit and termination (section 2.4): termination rights aligned with Article 28(7) of DORA, a comprehensive exit strategy and plans at suitable granularity, aligned with the termination terms in the contract; the ECB also recommends additional termination triggers such as a merger or sale of the provider or relocation of its head office or data centres.
  • Oversight and audit (section 2.5): independent monitoring of providers, incident reporting provisions in contracts (Article 19(5) of DORA keeps responsibility with the institution even where reporting is outsourced), and internal audit of the arrangements.

What did ECB Guide on outsourcing cloud services change for banks?

The ECB had flagged deficiencies in how banks manage outsourced ICT in its supervisory priorities for 2024-26 and now documents what it considers adequate. For AI, the Guide makes cloud-hosted model services subject to the same exit-plan, concentration, data-location and audit expectations as any other critical cloud dependency, and it applies the ECB's reading of DORA Articles 28-30 to the hyperscalers that supply most bank AI infrastructure.

What does the ECB expect of banks that outsource cloud services, including AI platforms?

The ECB's Guide on outsourcing cloud services (16 July 2025) expects directly supervised banks to treat cloud providers as ICT third parties under DORA: keep full responsibility, run an ex ante risk assessment covering concentration and lock-in, ensure business continuity if the provider cuts access, secure data and assess where it is processed, hold termination rights and a tested exit plan, and monitor and audit the provider independently. It is not binding and adds no new rules, but joint supervisory teams use it to judge whether a bank's cloud arrangements meet DORA. Hosted AI services are cloud services, so the same expectations apply to them.

RuleAuthorityWhat it requiresApplies
Section 2.1.1 — Full responsibilityECBKeep a governance framework for cloud outsourcing consistent with DORA Article 5 and CRD Article 74, with the management body ultimately responsible and roles clearly allocated.Published 16 Jul 2025
Section 2.1.2 — Ex ante risk assessmentECBAssess risks before contracting under DORA Article 28(4), including concentration and lock-in and, for critical or important functions, long sub-outsourcing chains.Published 16 Jul 2025
Section 2.2 — Availability and resilienceECBMaintain business continuity measures that cover severe disruption, including the cloud provider terminating service, and assess the provider's disaster recovery plan.Published 16 Jul 2025
Section 2.3 — Data security, location and accessECBImplement adequate data security measures, assess risks from data location and processing, record cloud assets in the asset inventory and control identity and access.Published 16 Jul 2025
Section 2.4.1 — Termination rightsECBSecure termination rights for the circumstances in DORA Article 28(7); the ECB recommends further triggers such as merger or sale of the provider or relocation of its head office or data centres.Published 16 Jul 2025
Sections 2.4.2-2.4.3 — Exit strategy and plansECBMaintain an overarching exit strategy and exit plans at appropriate granularity, aligned with contractual termination terms and with the provider's notice periods.Published 16 Jul 2025
Section 2.5 — Oversight, monitoring and auditECBMonitor cloud providers independently, secure incident reporting provisions in contracts (DORA Article 19(5)) and subject the arrangements to internal audit.Published 16 Jul 2025

The Guide is one of the ECB's supervisory guides, a category that states the ECB's interpretation without creating rules. Its legal anchors are DORA, which has applied since 17 January 2025, and the Capital Requirements Directive's governance and continuity provisions; the final version differentiates DORA requirements from the ECB's recommended good practices more clearly than the consultation draft did.

It is part of a wider ECB focus on operational resilience, including the 2026-28 supervisory priorities and ECB speeches on operational resilience in the age of AI. Banks that depend on a small number of hyperscalers for AI workloads are the case the Guide's concentration and exit sections were written for, and the largest providers are separately subject to ESA oversight as critical ICT third-party providers under DORA.

Because the Guide addresses ECB-supervised institutions, smaller banks should look to their national authority's expectations, but the DORA provisions it interprets apply to all EU banks.

WHAT THIS MEANS IN PRACTICE

  • Map every cloud-hosted AI workload to a provider, region and sub-processor and identify those supporting critical or important functions.
  • Document the ex ante risk assessment for each cloud arrangement, including concentration across business lines and sub-outsourcing chains.
  • Negotiate termination rights that go beyond the DORA Article 28(7) minimum where the ECB's good practice calls for it, and align notice periods with the exit plan.
  • Test exit and fallback plans for AI services, including data and model portability, not only for core infrastructure.
  • Assign independent monitoring of provider performance and incidents, and make sure contracts give the access, audit and incident-reporting rights needed.

Does the ECB cloud outsourcing guide apply to banks?

Yes, to banks directly supervised by ECB Banking Supervision. Less significant institutions are supervised by national authorities, which may apply the same approach, but the Guide's expectations are addressed to ECB-supervised institutions.

Is the ECB Guide on outsourcing cloud services binding?

No. Like other ECB Guides it does not lay down legally binding requirements, practices or rules. It explains how the ECB reads DORA and CRD requirements and recommends good practices; the underlying DORA obligations are binding.

When was the ECB cloud outsourcing guide published?

The final Guide was published on 16 July 2025, following a public consultation that ended in July 2024.

Does the ECB cloud guide cover AI services?

It does not mention AI specifically. It covers cloud services procured from cloud service providers, so AI platforms and model services delivered as cloud services (IaaS, PaaS or SaaS) are within its scope in the same way as other cloud services supporting banking functions.

How does the ECB cloud guide relate to DORA?

It clarifies the ECB's expectations for implementing DORA's ICT third-party risk requirements, in particular Articles 5, 6, 11, 19, 28 and 29, in a cloud context, and separates what DORA requires from what the ECB recommends as good practice.

DateDocumentStatus
Jul 7, 2026ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301) — Addressing AI-enabled cybersecurity threats — letter from the Chair of the Supervisory Board to CEOs of significant institutionsIn force
Jun 3, 2026Elderson speech: 'Strengthening operational resilience for the age of AI' (June 2026) — Strengthening operational resilience for the age of AI — speech by Frank EldersonFinal
Feb 24, 2026Machado speech: 'Technology is neutral, governance is not' (Feb 2026) — Technology is neutral, governance is not: AI adoption in the banking sector — speech by Pedro MachadoFinal
Feb 3, 2026Montagner speech: 'Encouraging innovation, managing risks' (Feb 2026) — Encouraging innovation, managing risks: the ECB's approach to digital transformation — speech by Patrick MontagnerFinal
Nov 20, 2025Supervision Newsletter: AI use cases for credit scoring and fraud detection (Nov 2025) — AI's impact on banking: use cases for credit scoring and fraud detection (Supervision Newsletter, November 2025)Final
Nov 18, 2025SSM supervisory priorities 2026–28 — ECB Banking Supervision: SSM supervisory priorities for 2026–28In force

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning