# Practical Outsourcing Portal Control Matrix

Prepared by: OI
Date: 2026-06-25
Scope: outsourcing and third-party oversight for an Italian bank operating in the UK.
Status: regulatory analysis for Compliance/Legal/authorised owner review; not legal advice.

Source hierarchy used:
- Binding law/rules: FCA Handbook, PRA Rulebook materials, EU DORA where applicable to EU/Italian group entities, Bank of Italy supervisory provisions where binding in Italian perimeter.
- Supervisory expectations/guidance: PRA SS2/21, FCA FG16/5, EBA Guidelines, Bank of Italy supervisory circular/guidance where applicable.
- Practical interpretation: portal fields, evidence and operating controls below.

Key source files:
- PRA SS2/21: `/data/workspace/outsourcing-initiative/01-source-regulation/uk/pra-ss2-21-outsourcing-third-party-risk-management-march-2026-update.pdf`
- FCA SYSC 8: `/data/workspace/outsourcing-initiative/01-source-regulation/uk/fca-handbook-sysc-8-outsourcing.html`
- FCA SYSC 15A: `/data/workspace/outsourcing-initiative/01-source-regulation/uk/fca-handbook-sysc-15a-operational-resilience.html`
- FCA FG16/5: `/data/workspace/outsourcing-initiative/01-source-regulation/uk/fca-fg16-5-cloud-other-third-party-it-services.pdf`
- EBA GL/2019/02: `/data/workspace/outsourcing-initiative/01-source-regulation/eu/eba-gl-2019-02-guidelines-on-outsourcing-arrangements.pdf`
- EBA GL/2019/04: `/data/workspace/outsourcing-initiative/01-source-regulation/eu/eba-gl-2019-04-ict-security-risk-management.pdf`
- Bank of Italy Circular 285: `/data/workspace/outsourcing-initiative/01-source-regulation/italy/bank-of-italy-circular-285-51-update-full-text.pdf`
- UK CTP regime: `/data/workspace/outsourcing-initiative/01-source-regulation/uk/boe-pra-fca-ps16-24-critical-third-parties.pdf`

## Control matrix

| # | Regulatory requirement / expectation | Source reference | Binding status | Portal field(s) | Evidence required | Owner | Frequency | Gap / remediation action |
|---:|---|---|---|---|---|---|---|---|
| 1 | Maintain a complete outsourcing/third-party register with sufficient detail for governance, oversight and regulatory review. | PRA SS2/21, chapters on outsourcing register; EBA GL/2019/02, Title IV, register of information; DORA Art. 28(3) for ICT third-party register of information; FCA SYSC 8. | PRA/FCA rules and supervisory expectations; EBA guidance; DORA binding for EU in-scope entities. | Unique arrangement ID; supplier; service; legal entity; country; start/end date; materiality; ICT/cloud flag; business owner; risk owner. | Portal export; register completeness attestation; reconciliation to contracts/AP/procurement list. | Outsourcing Referent / Procurement / Operational Risk. | Quarterly, plus event-driven update. | Add mandatory register fields; run quarterly reconciliation against contract repository and payment/vendor master. |
| 2 | Classify whether the arrangement is outsourcing, third-party service, ICT service, cloud, intra-group, or non-outsourcing. | PRA SS2/21 scope and definitions; EBA GL/2019/02 definitions and assessment; FCA SYSC 8; DORA Art. 3 and Art. 28. | Mixed: rules/guidance depending source. | Outsourcing classification; ICT service flag; cloud flag; intra-group flag; regulated activity support flag. | Classification memo or checklist; approval record. | Business Owner with Compliance/Operational Risk challenge. | On onboarding and material change. | Implement classification workflow before contract execution; prevent incomplete records moving to approved status. |
| 3 | Assess materiality / criticality / critical or important function before outsourcing and keep assessment current. | PRA SS2/21, material outsourcing; EBA GL/2019/02, critical or important functions; FCA SYSC 8; DORA ICT criticality concepts; Bank of Italy Circular 285 relevant outsourcing/internal control provisions. | PRA/FCA rules/expectations; EBA/BoI supervisory framework; DORA binding for ICT. | Materiality rating; critical/important function flag; rationale; date; approver. | Materiality assessment, impact analysis, committee approval. | Business Owner / Operational Risk / Compliance. | On onboarding; annual review; on service or risk change. | Add scoring model and mandatory rationale; evidence approval before go-live. |
| 4 | Identify important business services or critical operations supported by the outsourced service. | PRA operational resilience framework and SS2/21; FCA SYSC 15A; BoE/PRA/FCA CTP policy PS16/24. | Binding FCA/PRA operational resilience rules where applicable; supervisory expectations. | Important business service link; process map; impact tolerance dependency; CTP dependency flag. | Service mapping; impact tolerance assessment; dependency map. | Operational Resilience Owner / Business Owner. | Annual resilience cycle; material change. | Link each material outsourcing to business service mapping in portal. |
| 5 | Perform pre-outsourcing due diligence proportionate to materiality and risk. | PRA SS2/21 due diligence; EBA GL/2019/02 Title IV pre-outsourcing analysis; FCA FG16/5 for cloud/IT. | Supervisory expectation/guidance; FCA/PRA rules may apply to systems/controls. | Due diligence completed; due diligence date; due diligence outcome; risk rating. | Supplier DDQ; financial stability review; control reports; security review; references; sanctions/adverse media where applicable. | Procurement / Business Owner / TPRM / Information Security. | Before contract; refreshed periodically by risk tier. | Create due diligence evidence checklist; block approval if evidence missing. |
| 6 | Ensure senior management/governing body retains accountability for outsourced activities. | PRA SS2/21 governance; EBA GL/2019/02 governance framework; FCA SYSC senior management/systems and controls. | Rules and supervisory expectations. | Accountable executive; SMF/senior manager where relevant; committee approval; delegated authority. | Governance paper; approval minutes; RACI; accountability map. | Senior Management / Governance Secretariat. | On approval; annual attestation. | Record accountable owner and committee approval reference in each material record. |
| 7 | Maintain an outsourcing policy/procedure covering lifecycle controls. | PRA SS2/21 governance; EBA GL/2019/02 outsourcing policy; Bank of Italy Circular 285 governance/internal control framework. | Supervisory expectations/rules depending entity. | Policy version; procedure link; control applicability; exceptions. | Approved outsourcing policy; procedure; training record; exception log. | Compliance / Operational Risk / TPRM. | Annual policy review. | Add portal control mapping to policy clauses and evidence artefacts. |
| 8 | Obtain required internal approvals before entering or materially changing outsourcing. | PRA SS2/21; EBA GL/2019/02 governance; FCA SYSC 8. | Rules/expectations. | Approval status; committee; approval date; approver; conditions. | Approval paper; minutes; risk acceptance; conditions closure. | Business Owner / Committee Secretariat. | On onboarding/material change. | Configure workflow gates and require approval attachments before active status. |
| 9 | Notify regulators where required for material outsourcing or significant changes. | PRA SS2/21 notification expectations; FCA/PRA rules and supervisory expectations; EBA GL/2019/02 notification expectations for competent authorities; DORA register/competent authority reporting where applicable. | Rules/expectations depending entity and trigger. | Notification required Y/N; regulator; notification date; submission reference; response/acknowledgement. | Notification assessment; submitted notification; regulator acknowledgement. | Compliance / Regulatory Affairs. | Event-driven. | Add notification decision tree and mandatory evidence field for material arrangements. |
| 10 | Contract must clearly describe outsourced services, service levels and responsibilities. | PRA SS2/21 written agreement expectations; EBA GL/2019/02 contractual phase; FCA SYSC 8; DORA Art. 30 ICT contractual provisions. | Rules/expectations; DORA binding for EU ICT contracts. | Contract reference; service description; SLA/KPI fields; responsibility matrix. | Executed contract; SLA schedule; statement of work; RACI. | Legal / Business Owner / Procurement. | On contract execution; renewal/change. | Create clause checklist and require service schedule upload. |
| 11 | Include audit, access and information rights for the firm, auditors and regulators. | PRA SS2/21 access/audit/information rights; EBA GL/2019/02 access/audit rights; FCA FG16/5 access to premises/data; DORA Art. 30. | Rules/expectations; DORA binding for EU ICT. | Audit rights clause present; regulator access clause; evidence location; limitations/exceptions. | Contract clauses; audit plan; SOC/ISAE reports; regulator access wording. | Legal / Compliance / Internal Audit. | Contracting; annual evidence review. | Flag any contracts with restricted audit/access rights; remediate at renewal or side letter. |
| 12 | Control sub-outsourcing/subcontracting, including prior notice/approval and flow-down of obligations. | PRA SS2/21 sub-outsourcing; EBA GL/2019/02 sub-outsourcing; FCA FG16/5; DORA Art. 30 and subcontracting RTS context. | Rules/expectations; DORA binding for EU ICT. | Sub-outsourcing allowed Y/N; critical subcontractors; notice period; approval rights; locations. | Contract clause; subcontractor list; approval/notification records; risk assessment. | Business Owner / Procurement / Legal. | On onboarding; each subcontractor change; annual review. | Add mandatory subcontractor inventory and change notification tracking. |
| 13 | Assess and record data location, processing location and cross-border risk. | PRA SS2/21 data/security; FCA FG16/5 data residency/security; EBA GL/2019/02; DORA ICT third-party risk; GDPR/DPA separate legal framework. | Rules/expectations; data protection law separately binding. | Data type; personal/confidential data flag; data location; processing country; transfer mechanism. | Data flow map; DPIA if required; security review; contract data clauses. | Data Protection Officer / InfoSec / Business Owner. | On onboarding; material data/location change; annual review. | Add data residency and transfer fields; require DPO sign-off for personal data. |
| 14 | Ensure confidentiality, integrity and availability controls for outsourced services. | PRA SS2/21; FCA FG16/5; EBA GL/2019/04 ICT/security; DORA ICT risk management. | Mixed rules/expectations; DORA binding for EU ICT. | Security classification; control assurance status; encryption; access control; vulnerability management. | Security assessment; ISO/SOC reports; penetration test summary; remediation plan. | Information Security / Supplier Owner. | Before go-live; annual or risk-based refresh. | Link InfoSec approval and residual risk acceptance to portal status. |
| 15 | Ensure incident notification and escalation obligations are contractually defined and operationally tested. | PRA SS2/21; FCA FG16/5; EBA GL/2019/04; DORA incident reporting framework. | Rules/expectations; DORA binding for EU ICT incidents. | Incident notification timeframe; escalation contacts; last incident; breach log. | Contract clause; incident playbook; test records; incident reports. | Business Owner / Operational Resilience / InfoSec. | Annual test; every incident. | Add incident notification SLA field and test evidence upload. |
| 16 | Maintain business continuity and disaster recovery requirements for outsourced services. | PRA SS2/21 BCP/DR; FCA FG16/5; EBA GL/2019/02 business continuity; SYSC 15A operational resilience. | Rules/expectations. | BCP requirement; RTO/RPO; last DR test; test result; open issues. | Supplier BCP/DR plan; test certificate/report; issue remediation. | Operational Resilience / Business Owner. | Annual or risk-tiered. | Require annual BCP/DR evidence for material arrangements. |
| 17 | Maintain exit strategy and exit plan for material/critical outsourcing. | PRA SS2/21 exit plans; EBA GL/2019/02 exit strategies; FCA FG16/5 exit planning; DORA Art. 28/30 for ICT exit concepts. | Rules/expectations; DORA binding for EU ICT. | Exit plan required Y/N; exit plan date; substitutability; alternative provider; exit complexity. | Exit plan; data return/deletion plan; transition plan; cost/time estimate; test/walkthrough evidence. | Business Owner / Procurement / Operational Resilience. | On onboarding; annual review; renewal. | Add exit plan maturity rating; require plan for all material outsourcing. |
| 18 | Monitor supplier performance and risk during the life of the arrangement. | PRA SS2/21 ongoing monitoring; EBA GL/2019/02 monitoring; FCA SYSC 8. | Rules/expectations. | SLA status; KPI score; risk rating; last review date; issues count; breaches. | Service review minutes; SLA reports; risk review; issue log. | Business Owner / Supplier Manager. | Monthly/quarterly by risk tier. | Implement overdue review alerts and issue ageing dashboard. |
| 19 | Track audit findings, control issues and remediation against outsourced arrangements. | PRA SS2/21 governance/monitoring; EBA GL/2019/02 internal audit; FCA systems and controls. | Rules/expectations. | Audit findings; issue owner; due date; status; severity. | Internal audit reports; supplier audit reports; remediation evidence. | Internal Audit / Business Owner / Operational Risk. | Per audit cycle; monthly issue tracking. | Integrate issue log into portal and escalate overdue high-risk items. |
| 20 | Assess concentration risk at supplier, group, geography, technology and cloud provider level. | PRA SS2/21 concentration risk; EBA GL/2019/02 concentration risk; FCA FG16/5 cloud concentration; BoE/PRA/FCA CTP regime. | Supervisory expectations/rules depending context. | Supplier group; service category; cloud provider; country; critical dependency count; substitutability. | Concentration report; supplier group mapping; cloud dependency map. | TPRM / Operational Risk / Procurement. | Quarterly/semi-annual. | Build dashboard by supplier group and critical service dependencies. |
| 21 | Treat intra-group outsourcing with appropriate risk assessment and contractual discipline; do not assume lower risk automatically. | PRA SS2/21 intra-group; EBA GL/2019/02 intra-group outsourcing; Bank of Italy group governance context. | Supervisory expectations. | Intra-group flag; group entity; SLA; arm’s-length controls; group reliance. | Intra-group agreement; SLA; group control attestation; escalation route. | Business Owner / Group Outsourcing / Legal. | On onboarding; annual. | Require intra-group contracts and equivalent evidence to external providers. |
| 22 | Record and manage cloud-specific risks and contractual controls. | FCA FG16/5; PRA SS2/21 cloud/third-party; EBA GL/2019/02; DORA ICT third-party risk. | Guidance/expectations; DORA binding for EU ICT. | Cloud service model; deployment model; CSP; region; shared responsibility; encryption; exit. | Cloud risk assessment; architecture/security review; CSP terms; shared responsibility matrix. | Technology Owner / InfoSec / Cloud Governance. | On onboarding; material architecture change; annual. | Add cloud-specific field set and require InfoSec/cloud architecture sign-off. |
| 23 | Ensure outsourcing does not impair regulators’ ability to supervise the firm. | PRA SS2/21; FCA SYSC 8/FG16/5; EBA GL/2019/02; DORA Art. 30; Bank of Italy supervisory framework. | Rules/expectations. | Regulator access clause; jurisdiction/legal impediment assessment; audit limitations. | Legal memo; contract clause; jurisdiction assessment. | Legal / Compliance. | Contracting; jurisdiction change. | Flag providers/locations with legal access constraints for Compliance review. |
| 24 | Maintain clear termination rights for poor performance, regulatory issues, material breach, insolvency and control failures. | PRA SS2/21 contractual requirements; EBA GL/2019/02 contractual rights; FCA FG16/5; DORA Art. 30. | Rules/expectations; DORA binding for EU ICT. | Termination rights present; notice periods; exit assistance; step-in/transition rights. | Contract termination clauses; exit assistance schedule. | Legal / Procurement / Business Owner. | Contracting; renewal. | Add contract clause tracker and remediation plan for weak termination rights. |
| 25 | Manage changes to outsourced services, including technology, location, subcontractors and service scope. | PRA SS2/21; EBA GL/2019/02; FCA FG16/5; DORA ICT change/subcontracting controls. | Rules/expectations. | Material change flag; change date; approval; risk reassessment; notification required. | Change request; risk assessment; approval; updated contract/SOW. | Business Owner / Change Management / Compliance. | Event-driven. | Create material change workflow with re-assessment triggers. |
| 26 | Ensure independent assurance/internal audit can review outsourcing framework and material arrangements. | EBA GL/2019/02 internal audit; PRA SS2/21 governance; FCA systems and controls; Bank of Italy internal control framework. | Rules/expectations. | Last audit date; audit scope; rating; findings; next audit. | Internal audit plan/report; management actions; closure evidence. | Internal Audit. | Risk-based audit cycle. | Add audit coverage field and link findings to supplier records. |
| 27 | Maintain documented risk acceptance and exceptions for non-compliant clauses or controls. | PRA SS2/21 proportionality/governance; EBA GL/2019/02 governance; FCA systems and controls. | Supervisory expectations/rules. | Exception ID; risk acceptance owner; expiry date; compensating controls. | Risk acceptance memo; committee approval; compensating control evidence. | Operational Risk / Compliance / Senior Owner. | On exception; review before expiry. | Add expiring exceptions report and escalation process. |
| 28 | Align portal with DORA register of information for ICT third-party arrangements where EU group/DORA applies. | DORA Art. 28(3) and related ITS/RTS context. | Binding EU Regulation for in-scope EU entities. | DORA ICT service ID; LEI/entity; function; ICT provider; subcontractor chain; country; substitutability; exit. | DORA register extract; group template; competent authority submission evidence where applicable. | Group DORA Owner / ICT Risk / Outsourcing Referent. | At least annual and on change; per group submission timetable. | Map portal fields to DORA register template; identify missing data. |
| 29 | Identify whether provider may fall within or interact with UK Critical Third Party regime. | BoE/PRA/FCA PS16/24; FCA CTPS; PRA CTP rules/instruments. | UK statutory/rule regime for designated CTPs; firms still manage dependencies. | CTP provider flag; designated CTP Y/N; critical service dependency; regulator publications monitored. | CTP assessment; provider designation evidence; resilience information. | Operational Resilience / Compliance / Supplier Owner. | Quarterly monitoring; on regulator designation. | Add CTP watchlist field and monitor BoE/PRA/FCA publications. |
| 30 | Retain accessible evidence for the full outsourcing lifecycle. | PRA SS2/21 documentation/register; EBA GL/2019/02 documentation; FCA SYSC 8; Bank of Italy internal control/documentation expectations. | Rules/expectations. | Evidence repository link; evidence owner; retention period; last evidence QA. | Contract; DD; approvals; monitoring packs; audit; exit plan; issue logs. | Outsourcing Referent / Records Management. | Continuous; annual QA. | Define minimum evidence pack and run completeness QA by materiality tier. |

## Recommended portal field set

Minimum fields to make the portal regulator-ready:

1. Arrangement ID
2. Supplier legal name and supplier group
3. Intra-group/external flag
4. Service description
5. Business owner
6. Accountable executive / senior manager
7. Legal entity/branch using the service
8. Outsourcing classification
9. Materiality / criticality rating
10. Critical or important function flag
11. ICT service flag
12. Cloud flag and cloud model
13. Important business service supported
14. Jurisdiction / data location / processing location
15. Contract reference and effective/expiry dates
16. SLA/KPI reference
17. Due diligence completion date and outcome
18. Information security approval status
19. Data protection approval status
20. Audit/access/regulator access clause status
21. Sub-outsourcing permission and subcontractor list
22. BCP/DR RTO/RPO and last test date
23. Exit plan status and last review date
24. Regulatory notification required/submitted
25. Concentration risk category
26. Latest service review date
27. Open issues/audit findings
28. Risk acceptance/exception status
29. DORA register mapping fields where applicable
30. Evidence completeness rating

## Immediate remediation priorities

1. Make materiality, ICT/cloud flag, audit/access clause status, sub-outsourcing status and exit plan status mandatory for all active records.
2. Add a contract clause checklist for audit/access, regulator access, sub-outsourcing, incident notification, BCP/DR, data location, termination and exit assistance.
3. Reconcile portal records against contract repository and supplier payment list to identify missing arrangements.
4. Build a DORA register field mapping for EU/Italian group ICT third-party services.
5. Create monthly oversight dashboard: overdue reviews, expired contracts, missing exit plans, missing audit/access clauses, open high-risk findings, concentration exposures.
