Almost no licensed trading firm builds everything itself. The trading platform comes from a vendor, the CRM from another, identity checks from a third, hosting from a cloud provider, and the overnight support shift from a company in a different time zone. That is normal, expected and permitted. It is also regulated, and the rules are more specific than most firms realise until an inspection.
The principle that runs through every regime
Outsourcing transfers the work, never the accountability. Whatever a firm delegates, it remains answerable to its regulator for the outcome, must be able to supervise the provider, and must not become so dependent that it cannot continue if the arrangement ends. Those three ideas appear in European financial rules, in the guidance of the major offshore regimes, and in operational resilience rulebooks under different wording.
The practical consequence: a firm cannot answer a supervisor's question by saying the vendor handles that. It must be able to explain how the vendor handles it, how the firm checks, and what happens if the vendor stops.
Critical or important, and why the label matters
Rules apply in proportion to what the function does. A function is generally treated as critical or important if a defect in it would materially damage the firm's ability to comply with its licence, or its financial soundness, or the continuity of its services to clients.
By that test, the trading platform is critical. So are order execution and routing, client money reconciliation, the AML and KYC process, risk management, and core hosting. The marketing agency, the office cleaning and the design studio are not. Between them sits a grey zone, and the client support desk is the most commonly misclassified: a desk that only answers questions is ordinary, while one that resets passwords, approves withdrawals or handles complaints is doing regulated work.
Critical arrangements attract the fuller obligations: a written agreement with defined service levels, due diligence before signing, ongoing monitoring, audit and access rights, notification to the regulator in some regimes, and a documented exit plan.
What belongs in the agreement
A compliant outsourcing agreement is not a standard software contract with a compliance clause bolted on. The elements supervisors look for are consistent.
- A precise description of the function, with measurable service levels and what happens when they are missed.
- Data protection terms, including storage location and the transfer mechanism, which ties directly to data residency.
- Audit and access rights for the firm, its auditors and its regulator, covering premises, systems and records, rather than a report the vendor chooses to send.
- Rules on subcontracting: whether the vendor may subcontract, notice before it does, and the vendor's responsibility for anyone it appoints.
- Business continuity and incident notification, with a defined window for telling the firm about an outage or a breach.
- Termination rights and a transition period long enough to move, with the vendor obliged to cooperate and to hand back data in a usable format.
The exit plan is the part firms skip
Every framework asks for it and almost nobody writes it until asked. The question is simple: if this vendor terminated the contract, failed, or lost its own licence, how would the firm continue serving clients, and how long would it take.
The answer needs to be specific. Which alternative provider, or which in-house fallback. Where the data would come from and in what format. Who executes the migration and how long clients would be affected. Firms that lost access to a major platform at short notice discovered the value of this document the hard way, and the ones who had thought about platform concentration risk in advance moved in weeks rather than months.
An exit plan that depends on data you cannot extract is not a plan. Confirm the export format and test an actual export during the contract, not at the point of leaving.
Cloud, and the illusion of negotiation
Hosting with a large cloud provider is outsourcing, and it is treated as such. The awkward part is that a small broker will not negotiate bespoke audit rights with a hyperscale provider. The accepted route is to rely on the provider's published financial services addendum, its certifications and audit reports, and to document that reliance as a considered decision with the residual risk named.
Where a firm does have leverage is with its software vendors. A platform or CRM supplier selling to regulated firms should already offer the audit rights, incident notification and exit assistance clauses, because every one of its clients needs them. If a vendor treats these as unusual requests, that tells you which market it normally sells to.
Intragroup does not mean exempt
Firms often assume that using a sister company inside the same group falls outside the rules. It does not. Intragroup outsourcing is still outsourcing, and while some regimes allow a lighter touch on due diligence where the group exercises real control, the written agreement, the oversight and the exit plan are still expected. A support entity in another country staffed by the same owners is exactly the arrangement supervisors ask about, because the informality that makes it convenient is what makes it hard to evidence.
Oversight after signing
Due diligence before the contract is the visible half. The half that gets firms criticised is what happens afterwards: nobody named as the owner of the relationship, no periodic review, no record of service level performance, no check that the vendor's own certifications are still current.
A workable minimum is a register listing every outsourced function, its criticality, the provider, the contract dates, the named internal owner and the last review date. Then an annual review for critical arrangements, written down. This sits naturally with the compliance officer's responsibilities, and it is one of the first documents requested in an inspection, alongside the audit trail from the systems themselves.
"The regulator does not care that your vendor made the mistake. Your licence, your client, your problem. The outsourcing file exists to show you knew that before it happened."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- Outsourcing moves the work and never the accountability. The firm must still be able to explain, supervise and continue without the provider.
- Critical or important functions attract the full obligations, and a support desk that approves withdrawals or handles complaints is usually one of them.
- The agreement needs audit and access rights, subcontracting rules, incident notification windows and a workable termination and transition period.
- Write the exit plan and test a real data export during the contract, because a plan that depends on data you cannot extract is not a plan.
Frequently Asked Questions
Does using a cloud provider count as outsourcing?
Yes, in every major regime cloud hosting of a regulated function is treated as outsourcing. Small firms rarely negotiate bespoke terms with large providers, so the accepted approach is to rely on the published financial services addendum and audit reports, and to document that reliance as a considered decision.
Which functions can never be outsourced?
Senior management responsibility and the governance of the firm cannot be delegated. Most regimes also expect the compliance oversight function and ultimate control of client money arrangements to sit with the firm, even where operational tasks around them are performed by a provider.
Does the regulator need to be notified about an outsourcing arrangement?
It depends on the regime and the criticality. Several jurisdictions require prior notification or approval for critical or important functions, and many expect a register of arrangements to be maintained and produced on request. Check the licence conditions rather than assuming.
About the Author
Roman Onta is an Executive Director at SINGUARD. He builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals side by side with his brother Alex Onta, and he helped on the design of eTrader, the division Alex built and leads. His ground is worldwide payment processing, AML compliance and the corporate structures brokers are built on, work the two of them carry together, shaped by executive roles in the UAE and international corporates. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.