Write down every external service your firm depends on. Platform, CRM, hosting, market data, KYC provider, payment processors, email, the bridge, the analytics tool, the support desk, the outsourced compliance consultant, the accountant. Now ask which of those are performing a function you are licensed to carry out. That subset is your outsourcing register, and in most trading firms it is a dozen entries or more.
What counts as outsourcing
The common definition across European supervisory guidance is an arrangement under which a third party performs a process, service or activity that the firm would otherwise perform itself. Buying a commodity service usually does not count. Office cleaning is not outsourcing. Market information subscriptions and standard utilities generally sit outside as well.
The line moves once the vendor does something inside your regulated perimeter. A KYC provider running your identity checks is performing your customer due diligence. A platform vendor executing and recording client orders is inside your investment business. A CRM holding client records and payment history is holding your regulatory records. Those are arrangements a supervisor expects to see documented.
The second classification is whether the arrangement is critical or important, meaning a defect in it would materially damage your ability to meet regulatory obligations, continue in business or serve clients. For a broker, execution, pricing, client money records and KYC almost always land in that bucket. The heavier obligations apply to that group.
The fields the register carries
Regulators that publish a template converge on a similar set of fields, and building the register with all of them from the start avoids a painful retrofit:
- Reference number, start date, contract renewal or expiry date and notice periods.
- Provider legal name, registration number, group parent and the country where the service is performed.
- Description of the function, and whether it is classified as critical or important, with the reasoning.
- Country where data is stored and processed, which links to the questions in data residency rules.
- Sub-outsourcing: who the provider relies on in turn, since your dependency runs down the whole chain.
- Date of the last risk assessment and the internal owner accountable for the relationship.
- Substitutability: whether an alternative provider exists and how long a transfer would take.
- Exit plan reference, including whether the firm can retrieve its data in a usable format.
The substitutability field is the one that generates useful arguments internally. A vendor with no realistic alternative and a long migration is a concentration risk whatever the contract says, and writing it down forces the board to decide whether it accepts that.
Sub-outsourcing is where surprises live
Your KYC provider uses a document verification vendor, which uses a cloud region in another country. Your platform vendor uses a hosting provider and a data centre operator. You contracted with one company and depend on four. Guidance expects firms to know the chain for critical arrangements, to require notice of changes in it, and to have the right to object when a provider proposes a sub-outsourcing change that alters the risk.
That right only exists if it is in the contract, which is why the register and contract review run together. Firms that sign standard vendor terms without an audit and access clause discover at examination time that they cannot give a supervisor what it asks for.
Outsourcing requirements vary by regime, and some regulators expect notification or prior approval for certain arrangements. This describes the general mechanism rather than your obligations. Confirm the applicable rules with advisers in your licensing jurisdiction.
Due diligence before, monitoring after
The register records the outcome of two separate exercises. Before signing: financial soundness of the provider, security posture, subcontracting, jurisdiction and sanctions exposure, insurance, and whether they have served regulated firms before. After signing: service levels actually delivered, incidents, changes in ownership or location, and a periodic reassessment on a cycle set by criticality.
A register that has not been updated in a year is evidence of the absence of monitoring, not evidence of stability. Supervisors read the dates.
Why this matters commercially, not only for the file
Three practical benefits fall out of a maintained register. Your continuity planning gets accurate, because the dependency map is the same map, which is why the register and the continuity plan are usually reviewed together. Your banking and payments applications get easier, because underwriters ask who runs your KYC and where client data sits, and a firm that answers instantly reads as organised. And notification duties become manageable, because you know which arrangements need to be told to a regulator, a topic covered in notifying a regulator about cloud use.
One position worth stating plainly. Outsourcing moves the work, never the responsibility. A firm that says its vendor handles compliance has not outsourced anything a supervisor recognises, and the same reasoning applies to the shortcuts described in white label licence myths. The register exists to make that ownership visible, with a named person against every line.
"The register is the fastest audit of a firm I know. Show me who you depend on, whether you could replace them, and how long it would take. Three columns tell me more about the business than the pitch deck does."
— Alex Onta, Executive Director, SINGUARD
Key Takeaways
- Outsourcing is a third party performing a function you would otherwise perform yourself, not every supplier you pay.
- Classify each arrangement as critical or important and record the reasoning, because the heavier duties attach to that group.
- Track the sub-outsourcing chain and secure notice, audit and access rights in the contract before you sign.
- Outsourcing transfers the work and never the regulatory responsibility, so every line needs a named internal owner.
Frequently Asked Questions
Which suppliers belong in an outsourcing register?
Any third party performing a process, service or activity the firm would otherwise perform itself, particularly where it touches regulated activity such as execution, client records, customer due diligence or client money. Commodity purchases like office services generally sit outside the definition.
What makes an outsourcing arrangement critical or important?
Whether a failure or defect in it would materially damage the firm's ability to meet its regulatory obligations, continue operating or serve clients. Execution, pricing, client money records and KYC usually qualify for a retail trading firm, and the classification decides which additional duties apply.
Does using a vendor reduce our regulatory responsibility?
No. Outsourcing moves the work while the licensed firm keeps the obligation, which is why supervisors expect due diligence before signing, monitoring afterwards and a documented exit route for every critical arrangement.
About the Author
Alex Onta is an Executive Director at SINGUARD. He built eTrader, the terminal, the mobile apps, eTrader Broker, Copytrading, Business and Community, along with the worldwide clustered-server infrastructure it all runs on, with his brother Roman Onta helping on the design, and he leads that division today. Together with Roman he builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals, and the two of them carry worldwide compliance, payment processing and international business structuring side by side. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.