77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
All officer roles
OUT

Outsourcing Officer

Central oversight of all material outsourcing arrangements: risk analysis, exit strategies, provider monitoring, and the outsourcing register. Keeps the institution audit-ready under MaRisk AT 9 and DORA's ICT third-party regime.

Focus areas
Outsourcing registerMaRisk AT 9Exit strategyDORA
Legal basis

§ 25b KWG · MaRisk AT 9 · DORA (EU) 2022/2554

Quick contact

Talk to us about Outsourcing Officer

Three lines and you are in our inbox. We reply within one business day.

By sending you agree to our privacy notice. We use the data only to reply to you.

What is an Outsourcing Officer?

The Outsourcing Officer provides central oversight of a financial institution's outsourcing arrangements. The role exists because supervised institutions remain fully responsible for functions they hand to third parties, so they need a controlled view of every material outsourcing, its risks, its monitoring and its exit path.

The legal anchor is Section 25b of the German Banking Act (Kreditwesengesetz, KWG), which requires institutions to ensure that outsourcing does not impair the proper conduct of business, internal controls or the supervisor's ability to audit. Section 25b paragraph 1 sentence 4 KWG also obliges every institution to keep an outsourcing register covering material and non-material arrangements alike. The supervisory detail comes from the Minimum Requirements for Risk Management (MaRisk), in particular module AT 9 on outsourcing. AT 9 paragraph 12 is explicit: every institution that outsources must set up a central outsourcing officer inside the institution itself, with a central outsourcing management function added in support according to the nature, scale and complexity of the arrangements. An examination rarely asks whether those building blocks exist; it asks whether they fit together, whether the risk analysis matches the classification in the register, whether the contract carries the rights the analysis assumes, and whether monitoring has been documented without gaps.

For information and communication technology, the EU Digital Operational Resilience Act (Regulation (EU) 2022/2554, DORA) adds a directly applicable regime for ICT third-party risk: a register of information on all ICT service arrangements, mandatory contractual content, risk assessment of concentration and substitutability, and stricter rules for services supporting critical or important functions. DORA and MaRisk AT 9 overlap, so the officer manages one coherent framework rather than two parallel ones.

In practice the officer maintains the register, coordinates risk analyses, monitors provider performance and sub-outsourcing, keeps the exit arrangements workable, and reports on material outsourcing to the management board at least annually under AT 9 paragraph 13. The recurring weaknesses are familiar: a register that does not reflect the full contract population, a risk analysis written at signature and never revisited, an exit strategy with no named fallback, and sub-outsourcing the institution hears about only after the event. The role steers the provider relationship rather than auditing it independently, which keeps it distinct from internal audit. Insurance undertakings run a comparable function under a separate supervisory framework, where the German term is Ausgliederung.

Core duties of the Outsourcing Officer

  • Maintain the outsourcing register required by Section 25b paragraph 1 sentence 4 KWG and MaRisk AT 9, and the DORA register of information.
  • Coordinate the risk analysis that decides whether an arrangement is a material outsourcing.
  • Review outsourcing agreements for the content required by Section 25b KWG, MaRisk AT 9 and DORA.
  • Monitor provider performance, service levels and material sub-outsourcing.
  • Define exit processes and fallback options for material outsourcing and review them regularly.
  • Assess concentration risk and substitutability across ICT third-party providers under DORA.
  • Report on material outsourcing to the management board at least annually and on an ad hoc basis.
  • Safeguard the supervisor's and internal audit's audit and information rights.
  • Track contractual obligations, renewals and remediation of provider findings.
  • Coordinate with risk, compliance, information security and the ICT function.

When is appointment required?

The driver is supervised status combined with outsourcing. MaRisk AT 9 paragraph 12 states it without a threshold: every institution that outsources must set up a central outsourcing officer inside the institution itself. Only in addition, depending on the nature, scale and complexity of the outsourcing activity, does a central outsourcing management function follow in support. The explanatory notes to AT 9 paragraph 12 require the officer to sit in an organisational unit reporting directly to the management board, or at least to have a direct reporting line to it. Smaller, less complex institutions may assign the function to a member of the management board, and the head of the central outsourcing management function may also be named as the officer.

The trigger for the underlying obligations is any outsourcing of activities and processes, with the strongest requirements attaching to material outsourcing as identified by the risk analysis. For information and communication technology, DORA applies directly to a broad range of financial entities and requires the register of information and ICT third-party risk management regardless of the KWG and MaRisk overlay, which widens the population that needs structured outsourcing oversight.

The institution should document the function and its authority, ensure the officer has access to all relevant arrangements and the standing to challenge them, and avoid conflicts of interest with the business units that own the relationships. Responsibility for the outsourced functions stays with the institution and its management under Section 25b paragraph 2 KWG; the officer provides the central control, the register and the monitoring that make that responsibility demonstrable to the supervisor.

  • Any outsourcing by an institution subject to Section 25b KWG (MaRisk AT 9 paragraph 12)
  • Any material outsourcing identified by the risk analysis under MaRisk AT 9
  • Use of ICT third-party providers within the scope of DORA
  • Outsourcing supporting critical or important functions under DORA
  • Growth in outsourcing volume or concentration with a single provider
  • Supervisory finding on outsourcing governance or the register

Sectors that need this role

  • Banks and credit institutions under the KWG
  • Financial services and securities firms
  • Payment and e-money institutions
  • Insurance undertakings within DORA scope
  • Asset and fund management companies
  • Leasing and factoring institutions
  • Crypto-asset service providers in scope of financial regulation
  • Group ICT and shared-service entities serving financial firms
  • Central counterparties and market infrastructure
CIVAC

How CIVAC supports the Outsourcing Officer role

CIVAC gives the Outsourcing Officer one place to run the central outsourcing management function. The role file holds the appointment, the written job description and the deputy arrangement, so that a change of person is not also a change of evidence. The outsourcing register, the risk analyses, the reviewed contracts and the exit strategies sit as documents in the documentation pillar and stay retrievable when the supervisor or internal audit asks for them.

Recurring obligations run as scheduled tasks with a named owner and a reminder: provider monitoring, contract renewals, tests of the exit strategy and checks on sub-outsourcing. Material arrangements are then looked at on a date, not only once something goes wrong. Findings from monitoring or review become tracked remediation tasks whose course the append-only audit trail keeps. Training on outsourcing governance is recorded per person with proof, and role templates give the repeating steps a fixed shape. An institution that cannot staff the role in house can have an external officer appointed and keep working in the same records. The role costs 49 euros per month.

Frequently asked questions

Need this officer role for your organisation?

Appoint our experts as your external officer or license CIVAC for your in-house team. Get in touch and we walk you through the right setup.