The Central Bank of Ireland’s outsourcing register isn’t primarily for the firm’s own use — it’s the raw material the Central Bank uses to assess concentration risk across the sector. Most firms complete it as an administrative exercise. That’s not what it’s for.
The Central Bank’s Cross-Industry Guidance on Outsourcing came into immediate effect in December 2021, following the CP138 consultation. It applies proportionately to any Regulated Financial Service Provider using outsourcing as part of its business model — a broad net, since the Central Bank treats outsourcing on a genuinely cross-sectoral basis rather than sector by sector. This is a reading of the register and concentration-risk expectations specifically, since that’s the part most technology functions underestimate.
Who this is for
- The CTO or head of technology risk responsible for maintaining an outsourcing register that will be read by the Central Bank, not just kept internally.
- The compliance officer preparing a firm’s first Outsourcing Register submission via the Central Bank Portal.
- The board member reviewing outsourcing risk who wants to know what “concentration risk” means beyond the phrase itself.
The register exists to feed a bigger picture
Firms whose PRISM Impact Rating is Medium-Low or above must submit their completed outsourcing register through the Central Bank Portal, with the reporting frequency and timeline communicated through supervisory channels. But the Central Bank has been explicit about why: the additional data it requests beyond the EBA’s baseline outsourcing guidelines exists specifically to support its own analysis of concentration risk and interconnectedness across the financial sector, at both institution level and sectoral level. A register completed to the letter of the template, but without understanding that it’s being read alongside every other regulated firm’s register, misses what the exercise is actually for.
Free · 4 minutes
Do you know what could take the business down — and have you priced it?
Fourteen questions on concentration, third-party dependence, resilience, and incident readiness — the exposures a board is accountable for whether or not it can see them. Banded finding on screen, full sheet by email.
Two levels of concentration risk, and only one is yours to assess
The Central Bank distinguishes individual-level from systemic-level concentration risk. At the individual level, firms are expected to actively assess: what services are being outsourced to a particular supplier, and — where visible — whether other financial services firms outsource to the same provider, and whether that provider has the capacity to maintain service to all of them under stressed conditions. At the systemic level, the Central Bank accepts that individual firms have limited market intelligence about their own contribution to sector-wide concentration — but firms are still expected to be aware that this risk exists and to understand the Central Bank’s role in monitoring it centrally, building its own picture as the register data accumulates over time.
The practical implication: a technology function’s third-party risk assessment shouldn’t stop at “is this vendor financially stable and operationally sound.” It should extend to the honest question of how many other regulated Irish firms likely depend on the same core infrastructure or SaaS provider — a question that’s often answerable just from knowing which platforms dominate a given category in the Irish market.
Sub-outsourcing and intragroup arrangements carry the same weight
The Guidance is explicit that outsourcing to intragroup entities — a parent company, a shared-services affiliate — carries risks comparable to third-party outsourcing, even where it also brings benefits like centres-of-excellence expertise. Sub-outsourcing chains present a related but distinct problem: parties can be spread across different physical and geographical locations in ways that hinder both the regulated firm’s own visibility and the Central Bank’s supervisory oversight, and concentration can develop in sub-outsourced providers a firm has no direct sight of at all. A register that only tracks the firm’s direct contractual counterparties, without mapping what sits one or two layers further down the chain, is incomplete by the Central Bank’s own standard.
What the register actually needs to capture
Beyond the basic vendor and service description, the Central Bank’s template expects additional general information specifically to support its concentration risk assessment — including business continuity plans, exit strategies, and details of other outsourcing arrangements the firm has in place, giving the regulator context for how a single provider failure would ripple across a firm’s broader dependency structure, not just the one arrangement in question.
What a defensible outsourcing risk framework includes
- A documented, board-approved outsourcing policy, reviewed at least annually or on material business-model change.
- A criticality assessment methodology aligned to EBA Guidelines on Outsourcing GL/02, applied consistently across all arrangements — including intragroup ones.
- A register that maps sub-outsourcing chains at least one layer deep, not just direct contractual counterparties.
- An explicit concentration risk assessment for each critical or important arrangement, including a reasoned view — even where imperfect — of whether the same provider serves comparable firms in the Irish market.
- Documented, tested exit strategies for every critical or important arrangement, not a contractual termination clause assumed to be sufficient on its own.
Notification obligations, and where firms over-rely on the provider’s own testing
Beyond the register itself, firms must notify the Central Bank of planned critical or important outsourcing arrangements in advance, and of material changes to existing ones — a forward-looking obligation distinct from the periodic register submission, and one that requires the technology function to flag a new critical vendor relationship to compliance early enough for the notification to happen before, not after, the arrangement goes live.
On business continuity specifically, the Central Bank accepts that firms will often rely on testing performed by the outsourcing service provider itself, rather than running fully independent tests — but only where the provider can adequately evidence that testing, conducted at a level the firm’s own risk appetite and impact tolerance actually require, and demonstrably alignable with the firm’s own contingency measures. A firm that accepts a provider’s generic “we test our DR annually” assurance, without obtaining evidence the testing was conducted to a standard matching the firm’s own risk tolerance, hasn’t actually satisfied this expectation — it’s accepted a lower bar than the Guidance sets.
How we engage with this
We read outsourcing registers and third-party risk frameworks against what the Central Bank’s guidance actually expects, as a Supplier and Dependency Review — including an honest concentration risk assessment that goes beyond the firm’s own direct visibility. The output is a written assessment the board can act on before the next register submission, not after a supervisory finding.
We don’t broker outsourcing arrangements. We don’t complete register submissions on a client’s behalf. We don’t represent firms to the Central Bank. We read what’s there, identify what’s missing, and write it down for the people who have to decide what to do about it.
Pricing is published at /pricing/. If your outsourcing register has never been reviewed with concentration risk specifically in mind, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming