← All insights

IT Risks Cannot Be Delegated

Published: 9 December 2025

IT Risks Cannot Be Delegated

IT Governance: Why Responsibility Cannot Be Delegated

IT outsourcing promises cost advantages, access to expertise and faster innovation. What is often overlooked is that operational risk rises at the same time, and it cannot simply be delegated away. FINMA therefore explicitly classifies the outsourcing of critical functions as a major risk to the stability of the financial centre and its institutions, particularly given the concentration on a small number of cloud and SaaS providers.

Crucially: Responsibility for proper service delivery remains with the outsourcing company. It cannot be delegated by contract.

Governance: Board, Executive Team, Business Units

Good outsourcing governance is not an IT matter. It is a leadership task.

  • Board of Directors: Holds overall management (Art. 716a para. 1 no. 1 OR), organisational responsibility and supervision; these tasks can neither be outsourced nor transferred to providers. The board sets risk tolerance, defines critical functions and decides which dependencies are acceptable and which are not.
  • Executive team: Responsible for operational implementation, from outsourcing strategy and provider selection through to integrating outsourced services into the internal control system.
  • Business units: Remain accountable for the outsourced processes and data. They must define requirements, controls and contingency processes, and review them continuously.

This division of roles applies equally to banks and insurers, industrial companies, hospitals and public administration. The regulatory framework may vary, but the chain of liability does not.

Third-Party Risk from a European Perspective

Regulation such as DORA (the EU Digital Operational Resilience Act) and the planned EBA guidelines on third-party risk go far beyond traditional outsourcing. They cover almost all critical third-party services. For unregulated companies in the EU, they act as a de facto standard: these companies too must actively manage key dependencies, supply chain risks and the resilience of cloud and software services.

Incidents such as the CrowdStrike update or major cloud outages show that a failure at a single technology provider can trigger global chain reactions. These guidelines are not yet binding for Switzerland, or only in certain areas. The direction of travel is clear, though, and FINMA has already picked it up, for example in FINMA Circular 2018/3 on Outsourcing.

Five Core Principles of IT Outsourcing

  • “Own the risk” instead of “park the risk”: Every outsourced function remains an integral part of the business model, including all legal, cyber and reputational risk. Risk must be identified, assessed, managed and monitored as if the service were delivered in-house.
  • A holistic view of third parties, not a focus on individual providers: Critical outsourcing arrangements are not the only concern. Smaller specialist providers or subcontractors can also represent critical weaknesses, for example at the company, fiduciary and banking interface. Supply chain risk, sub-outsourcing and concentration on a small number of cloud or payment providers belong on the radar of risk management and audit, including vendor lock-in.
  • Contractual safeguards combined with active governance: Contracts must set minimum standards for information security, audit rights, exit scenarios, data location and subcontractors. Without active management, control and monitoring, though, these remain paper compliance. Clear KPIs, regular service reviews, independent controls and tested contingency and exit plans are required. In practice, particularly at smaller organisations, outsourcing providers are often trusted blindly, and reviews and tests happen too rarely. Recommendation: Define, already within the outsourcing project, the conditions and effort required to switch providers or bring a service back in-house.
  • Align business and IT strategy: IT outsourcing must not be driven by cost alone. It must fit the business strategy, the degree of digitalisation and the organisation’s risk tolerance. Transferring critical core processes almost entirely to one or a few global providers creates new strategic dependencies, and requires clear governance decisions at the highest level.
  • Resilience before efficiency: Regulators increasingly demand operational resilience: the ability to keep critical functions running even when a service provider fails. This requires redundancy, tested fallback processes, clear communication channels and a precise record of all critical outsourcing relationships. In cloud and SaaS in particular, organisations often rely on a single platform, which creates significant vendor lock-in and a corresponding dependency (compare the recent Microsoft price increases).

What Boards and Executives Should Do

  • Keep an inventory of all material outsourcing and third-party relationships, including sub-outsourcing and cloud use, and update it regularly.
  • Define clear responsibilities: who is accountable, per service, for risk analysis, ongoing monitoring, incident management and exit?
  • Design risk and performance reporting so that the board or supervisory body can see outsourcing risk as clearly as credit, market or production risk.
  • Use industry standards and regulatory requirements (FINMA, EBA, DORA and others) as a benchmark, even where the organisation is not formally subject to them in full.
  • Control and monitor outsourcing partners’ services, including testing contingency arrangements. When new functions or applications are added, stay aware of the new dependencies they bring.

Responsible IT outsourcing means capturing the benefits of specialisation and scale without giving up control. Risk cannot be delegated. Boards and executives in particular need to keep this in mind. Those who recognise it, and act accordingly, strengthen compliance and build a genuine competitive advantage.