// analysis
The invisible suppliers of European banking risk

Cloud, payments and subcontracting: European banks’ shared dependencies. ECB figures, DORA oversight and the practical limits of recovery plans.
Customers choose a bank. They rarely choose the companies that host its services, carry its data or supply its software. Different banks can depend on the same infrastructure. That shared dependency gives incidents a route across institutions whose balance sheets and teams are otherwise separate.
In their September 23, 2026 risk report, the European Banking Authority, insurance supervisor EIOPA and markets supervisor ESMA identify external dependencies as a vulnerability to monitor. They also describe a European financial system that remains resilient. Their warning calls for attention to the infrastructure supporting financial activity; it does not announce an imminent banking collapse.
Cloud takes a larger share of IT budgets
The clearest figure comes from the ECB. In a March 24, 2026 speech, Supervisory Board member Anneli Tuominen says cloud service-related expenses rose from around 4% of banks’ total IT budgets in 2021 to 17% in 2025.
Cloud services supply computing resources remotely, including processing, storage and software. The ECB uses the rising spending share as an indicator of growing reliance on a small number of providers. Its July 2025 guide also recognises possible benefits, including scalable capacity, security technologies and backup arrangements.
The indicator measures how spending is allocated. It does not measure the number of banks using a provider, that provider’s share of payments or the proportion of banking operations outsourced. The speech does not disclose the sample and methodology needed to reconstruct a detailed statistical series.
A shared outage can cut across diversified banks
Consider a scenario in which different banks use the same supplier for an essential function. An outage at that supplier could disrupt several institutions at once. The banks’ own servers might work and their capital positions remain sound while particular services become unavailable.
The financial consequences depend on the function affected. A brief interruption to a secondary tool differs from the loss of a service needed to process transactions before a deadline. Backup arrangements, outage duration and the ability to switch providers determine the extent of disruption. The European supervisors identify this concentration risk; their report does not estimate losses from a general cloud outage.
Diversification therefore needs to be examined down to shared technical dependencies. In a subcontracting scenario, two separate contracts might ultimately rely on the same hosting company. Spreading applications across several locations operated by one supplier can also leave dependencies on that supplier intact. The actual service chain and the failure scenarios covered matter.
Public digital services face related questions. Our investigation into France Identité’s contracts examines the ability to resume a service built and maintained across multiple suppliers.
Technical and financial dependencies have different mechanisms
The joint supervisors’ report looks beyond cloud services. It identifies ICT providers outside the European Economic Area, non-EU payment solutions, and infrastructures involved in clearing, repo and credit ratings. The EEA includes the EU, Iceland, Liechtenstein and Norway, so “non-EU” and “non-EEA” describe different geographical boundaries.
Clearing organises the calculation and, depending on the infrastructure, the management of obligations between counterparties. A repo provides financing against securities with an agreement to repurchase them. Credit ratings assess creditworthiness. These financial functions and an IT hosting contract have distinct mechanisms and supervisory frameworks. Our analysis of repo explains its role in access to liquidity.
The supervisors also highlight banks’ funding needs in US dollars, sterling and Swiss francs. That exposure concerns access to a currency and its funding. Appearing on the same dependency map does not make it an IT outage risk.
According to the authorities, dependencies outside Europe add exposure to other jurisdictions and geopolitical events. Geography alone cannot rank the resilience of each arrangement. Concentration, the importance of the service and how readily it can be replaced also matter. The report does not provide an exhaustive public map connecting every bank to all its suppliers.
DORA adds oversight of shared providers
The Digital Operational Resilience Act, or DORA is the EU regulation on digital operational resilience in finance. It has applied since January 17, 2025. Its framework covers ICT risk management, reporting of major incidents, testing and relationships with ICT service providers for financial entities within its scope.
DORA adds European oversight of selected critical suppliers. Financial entities’ registers of information on their ICT contracts feed into designation. Supervisors assess a provider’s systemic importance, the functions it supports and the substitutability of its services, as their November 18, 2025 announcement explains.
The list published that day contains 19 providers, including European and non-European businesses supplying infrastructure, software and data services. The count concerns critical ICT third-party providers, or CTPPs designated for the European financial sector. It counts neither banks nor all their suppliers. That remains the list offered on the official oversight page consulted for this article.
The ECB describes the framework as fully operational from January 2026. The January 14 agreement with UK authorities, including the Bank of England, PRA and FCA, establishes cooperation, information sharing and coordination of oversight. The equivalence assessment concerns the confidentiality and professional secrecy arrangements needed to exchange information.
This oversight complements financial entities’ responsibility to manage their own ICT risks, as the EBA explains. Designation does not guarantee uninterrupted service from a provider.
An exit plan has to work
The ECB cloud guide distinguishes DORA requirements from the good practices it recommends. The guide itself does not introduce new legally binding obligations. Its operational logic is specific: prepare to transfer a critical service or bring it in-house, with a credible timetable, resources and technical options.
Retrieving data may not be enough to restart an application. Proprietary technologies, interfaces and specialist skills can complicate migration. The guide recommends estimating transition times, identifying alternative providers and testing the feasibility of exit plans. It also addresses subcontracting chains.
In her March 2026 speech, Tuominen observes that some banks still lag in renegotiating contracts and adapting business continuity arrangements. She also says 38% of major incidents reported by banks in 2025 had IT changes as their root cause. That category covers projects, migrations and updates. The figure does not allocate incidents between internal origins and external providers.
There is also a reporting boundary to respect. The ECB explains that DORA extends reporting to major ICT incidents, beyond the cyber incidents covered by the previous framework. Treating those series as directly comparable would be misleading.
Work on non-ICT services is still under way
A recent development broadens the picture. On September 18, 2026, the EBA announced its final guidelines on third-party risk for non-ICT services. They seek to align the management of those dependencies more closely with the framework for ICT services, particularly where critical or important functions are supported.
As of September 30, the official policy page marks them not yet applicable, pending translation. The final text leaves the application date to be determined and provides two years from that date for reviewing and documenting existing arrangements supporting critical or important functions. If review or documentation is still incomplete at that point, the text calls for the supervisor to be informed. A firm calendar deadline would therefore be premature.
When assessing a bank, practical questions follow: which service could stop, which other institutions share the dependency, and how long would recovery take? A capital ratio describes the ability to absorb losses. Supplier mapping and recovery tests illuminate the ability to keep operating. These perspectives complement each other.
Sources and documents
- EBA, EIOPA and ESMA: risk update, September 23, 2026, JC 2026 29
- ECB: Anneli Tuominen, March 24, 2026, cloud budgets and ICT incidents
- ECB: guide on outsourcing cloud services, July 2025
- European supervisors: critical provider designation, November 18, 2025
- European supervisors: list of 19 designated providers, November 2025
- European supervisors and UK regulators: cooperation agreement, January 14, 2026
- EBA: DORA oversight page, accessed September 30, 2026
- EBA: DORA application and registers of information
- EBA/GL/2026/09: final guidelines on third-party risk for non-ICT services, September 2026
- EBA: guidelines status, 2026 version, accessed September 30, 2026
- EFTA: geographical scope of the European Economic Area
Method and limitations
Analysis as of September 30, 2026. Cloud budget and incident figures are attributed to the ECB’s March 24 speech. The September joint report identifies sectoral dependencies; it does not supply an exhaustive supplier map for each bank or a loss estimate for a general outage.
The critical provider count was checked against the official November 2025 list and the oversight page accessed on September 30. The non-ICT guidelines’ status and transition were checked against the policy page and paragraphs 18–20 of the final text. Those documents do not specify an application date.
The spending chart uses a common 0–20% scale. The dependency network illustrates three fictional banks, with no identified contracts or probabilities. Effects on continuity, liquidity or losses depend on the function, duration and recovery options. No market price, valuation ratio or hypothetical loss amount is presented as an observed figure.
This analysis is not investment advice.
// cite this analysis
l0g, “The invisible suppliers of European banking risk”, l0g.fr, published September 30, 2026, updated September 30, 2026, https://l0g.fr/en/analysis/invisible-suppliers-european-banking-risk/
$ cd ../analysis