Solutions

Managing Sub-Outsourcings and ICT Subcontracting

Transparency, control and compliance across the entire ICT supply chain

Get a demo

Why subcontracting is a challenge

In practice, risks often arise less from the primary service provider and more from its subcontractors.

Lack of oversight

  • Missing complete mapping of primary service providers and subcontractors in line with DORA, EBA Guidelines and MaRisk
  • Unclear allocation to critical or important functions
  • Changes within the supply chain are not systematically captured

Lack of transparency

  • Dependencies between primary service providers and subcontractors are not clearly identifiable
  • Concentration and operational resilience risks remain undetected
  • Responsibilities along the supply chain are unclear

Stringent regulatory requirements

  • Insufficient traceability of risk assessments and approval decisions
  • Documentation is not audit-ready or not up to date
  • Increased risk of findings by supervisory authorities and internal audit
Credit card mockups

How Leno manages subcontracting and ICT sub-outsourcing

Leno enables financial institutions to centrally and systematically manage subcontracting arrangements throughout their entire lifecycle.

Completely recording of all subcontractors

  • Mapping of Primary Service Providers → Subcontractor → Additional Outsourcing Layers
  • Allocation to critical and important functions
  • Complete change history for all subcontracting arrangements

Integrated risk assessment for subcontractors

  • Assessment of:
    • Criticality
    • Concentration risks
    • Information security risks
    • Data Protection
    • Operational Outage and Dependency Scenarios
  • Linked with existing ICT risk assessments.

Continuous monitoring and updates

  • Regular, audit-proof updates of risk assessments
  • Automated Transfer to the Outsourcing Register and the Information Register
  • Tracking of changes across the ICT supply chain
Credit card mockups

Further relocations are documented with basic functions, static workflows or individual solutions — without complete transparency across multi-stage supply chains.

Why Leno manages relocations and ICT services more effectively

Features
Andere Tools
Compliance
Generische Funktionen für DORA, MaRisk & EBA-Leitlinien
Vollständige Compliance mit automatisierten Informationsregsiter
Flexibilität
Statisch oder nur mit Programmierung
Konfigurierbar ohne Code
Modul-Integration
Getrennte Einzellösungen
Alles in einer Plattform, nahtlos verknüpft
Startgeschwindigkeit
Lange Implementierung
Sofort einsatzbereit mit Templates
KI-Funktionen
Oft nicht vorhanden
Oft nicht vorhanden

Other Tools

Basic functions, static workflows and separate individual solutions.
Full compliance, configurable, integrated and AI-supported.
Test for free
Monitoring and documentation
Andere
Subcontracting is documented but not actively managed or monitored.
Structured management of subcontracting including risk assessment, approval and continuous monitoring.
Transparency across ICT supply chains
Andere
Limited visibility into subcontractors, often only the first outsourcing layer.
Full transparency across multi-layer ICT supply chains, including third and fourth-party providers.
Compliance & regulation (DORA, EBA, MaRisk)
Andere
Generic compliance features without a specific focus on subcontracting
Targeted management of subcontracting aligned with DORA, EBA Guidelines and MaRisk.
Audit & audit ability
Andere
High manual effort to prepare audit-relevant evidence
Audit-ready documentation of all decisions at the push of a button.
Responsiveness to changes
Andere
Often not available
Continuous monitoring of subcontracting arrangements with clear ownership and up-to-date information.
Flexibilität
Andere Tools sind statisch oder nur mit Programmierung
Leno ist konfigurierbar ohne Code
Modul-Integration
Andere Tools bilden getrennte Einzellösungen
Leno ist eine All-in-One-Plattform, nahtlos verknüpft
Startgeschwindigkeit
Andere Tools erfodern lange Implementierung
Leno ist sofort einsatzbereit mit Templates
KI-Funktionen
In anderen Tools oft nicht vorhanden
Leno verfügt über integrierte KI für Analyse & Automatisierung

Key Questions on Sub-Outsourcings and ICT Subcontracting

What you should know about sub-outsourcings and ICT subcontracting


When does sub-outsourcing or subcontracting of ICT services occur?

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

An outsourcing occurs when a service provider completely or partially outsources services that it provides for a financial institution to a third party. This applies regardless of whether the outsourcing is permanent or temporary. If information and communication technology (ICT) services are affected by this outsourcing, this is referred to as ICT subcontracting.

Do all subcontractors have to be approved?

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Not every subcontractor needs formal approval — the risk relevance is decisive. Subcontractors that provide services related to critical or important functions or influence significant ICT risks must be assessed and approved in advance. For non-critical services, simplified documentation may be sufficient.

How deep does the documentation have to go?

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

The documentation must be so deep that risks from sub-outsourcings are fully comprehensible and controllable. As long as a further transfer can result in a risk that is relevant to the institution, evaluation, basis for decision-making, approval and monitoring must be documented. It must be possible for supervisors and auditors at all times to see which further transfers exist, which risks have been assessed and how these are managed.

How does Leno help with exams?

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Leno provides all audit-relevant information on further transfers centrally, up to date and comprehensibly. Risk analyses, approvals, decisions and changes in the ICT supply chain are documented in a structured manner and can be retrieved at any time in an audit-proof manner. In this way, institutions can provide internal auditors, auditors and supervisors with rapid and consistent information without manually compiling information.

Is a contract with the main service provider sufficient?

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

From a regulatory perspective, financial institutions are also expected to have transparency and control over subcontractors that are used as part of onward transfers. It is not only the contract that is decisive, but the actual monitoring of the entire ICT supply chain. The institution remains fully responsible even with subcontractors and must be able to assess risks, document approvals and understand changes.

Vereinbaren Sie einen Termin

Demo buchen
Vereinbaren Sie noch heute einen Termin, um Leno kennenzulernen.