The FSRA’s outsourcing review and the three clauses your IT contract needs

The FSRA reviewed outsourcing practices across ADGM during 2025, and the DFSA’s own report points the same way. Service agreements signed before 2025 predate both frameworks.


The Financial Services Regulatory Authority (FSRA) of Abu Dhabi Global Market (ADGM) used its 2025 annual report to record a thematic review of outsourcing practices, run during the year and prompted by growing reliance on third-party providers. It examined governance, risk management and oversight of outsourced arrangements, including accountability, data protection and operational resilience, and the findings fed targeted supervisory follow-up.

The sharpest consequence falls on incident reporting. The obligation to report runs on the licence holder. In an outsourced estate the first sign of an incident reaches the provider, and it reaches the client when the provider passes it on. Where a contract obliges the provider to give notice in reasonable time, a reporting window measured in hours has little chance of being met.

Closing that distance takes three things in writing:

  • A stated notification period tied to the client’s own regulatory clock.
  • A named escalation route that works outside business hours.
  • An undertaking to hand over logs and a timeline in a form the client can submit.
  • Who holds the data, and in which country it physically sits.
  • What the provider is contractually obliged to do when something breaks.
  • When the arrangement was last reviewed, and against what measures.
  • What the company did about the answer.

Service agreements drafted before 2025 rarely carry any of the three, because the frameworks they would have had to anticipate did not exist.

Service agreements drafted before 2025 rarely carry any of the three.

What the FSRA did in 2025

The FSRA introduced Cyber Risk Management Rules into its GEN Rulebook through a Notice of Publication dated 29 July 2025, setting clearer minimum requirements for Relevant Persons, the regulator’s term for the entities it authorises and recognises. In the same year it implemented a formal IT and cyber incident reporting framework and launched a Cyber Threat Intelligence platform with weekly newsletters. Outsourcing has sat among its stated supervisory priorities since 2024.

The DFSA is working the same ground

The Dubai Financial Services Authority (DFSA) published its 2025 annual report on 25 June 2026, recording a 91 percent increase in notifications of cyber-related incidents and a 153 percent increase in cyber risk breaches identified through targeted risk assessments. It does not publish the counts behind those percentages, so they indicate a direction of travel and no more; for scale, it ran 79 risk assessments across a DIFC population that reached 1,050 regulated entities. The report also describes work on third-party providers of critical technology, and an operational resilience policy in development.

What accountability means in practice

Accountability carries the same meaning for both regulators. Performance of a technology function can be transferred to a provider, while regulatory responsibility for it stays with the licence holder throughout. The test a supervisor applies is whether someone inside the company can answer four questions without calling the provider first:

  • Who holds the data, and in which country it physically sits. 

     

  • What the provider is contractually obliged to do when something breaks. 

     

  • When the arrangement was last reviewed, and against what measures. 

     

  • What the company did about the answer. 

     

A well-run arrangement produces these answers in minutes.

Read the scope before the certificate

The scope of an assurance report is where the difference shows between a provider describing its own controls and one whose controls an independent auditor has examined. Penta commissions an annual ISAE 3402 Type 2 report on its IT infrastructure and processes, audited by EY, alongside ISO/IEC 27001:2022 certification. A Type 2 report tests whether controls operated effectively across the period under review. The compliance position stays with the licence holder in every case.

Companies that can produce the agreement, the current assurance report, the name of the internal owner and a record of the last review find these conversations short. Put the outsourcing and incident-reporting review on the agenda this year, and Penta can help you get there.

References

  1. FSRA of Abu Dhabi Global Market, Notice of Publication dated 29 July 2025, amendments to the FSRA regulatory framework for Authorised Persons and Recognised Bodies in relation to cyber risk management (Cyber Risk Management Rules, GEN Rulebook).
  2. FSRA Annual Report 2025, Abu Dhabi Global Market - Strengthening Oversight & Modernising the Regulatory Framework .
  3. DFSA Annual Report 2025: Shaping the Financial Markets of the Future.
  4. DFSA media release, 25 June 2026, DFSA Annual Report 2025.
  5. Penta, ADGM’s cyber risk management framework after the deadline (24 June 2026).
Peter-Philp

Peter Philp

Senior Consultant, IT Governance and Operational Resilience

Peter Philp is a senior consultant with Penta IT Services, specialising in IT governance, service management, and operational resilience for regulated institutions. A former head of Penta’s service delivery operations, he brings over two decades of leadership experience connecting technology, governance, and human factors in the delivery of secure, compliant digital infrastructure. 

Connect with Peter