As the Deputy is aware, I met with the CEOs of both Bank of Ireland and AIB in January of this year. While the topic of outsourcing and off-shoring roles did not arise in these meetings and was therefore not discussed, the topic of cyber security investment did come up in both meetings. Bank of Ireland and AIB emphasised that they are prioritising investment in cyber security.
I note that all Banks licensed in the EU including Bank of Ireland and Allied Irish Banks are required to comply with the Digital Operational Resilience Act (DORA), which entered into force on 16 January 2023 and applied as of 17 January 2025. This sets out the framework that those entities need to adhere to in order to ensure they maintain a secure cyber environment. The Central Bank, as the relevant competent authority, oversees the compliance to DORA for entities under their remit in Ireland.
The purpose of DORA is to strengthen the IT security of financial entities ensuring that Europe’s financial sector is sufficiently resilient against operational disruptions. This is achieved by harmonising financial sector operational rules that apply to financial entities and third party ICT service providers contracted by financial entities.
Section II of the DORA Regulation creates an oversight framework of critical ICT third-party service providers; this framework addresses cyber security risk that can arise as a result of financial entities outsourcing ICT operations to third-party ICT service providers. As part of this framework the European Supervisory Authorities (ESA) are required to designate ICT third-party service providers as significant if they are deemed systemically important due to a higher number of financial entities relying on their services.
Every significant third-party ICT service provider is assigned a lead overseer by the ESA who has specified powers granted to them for the purpose of ensuring the critical ICT third-party provider complies with DORA and has in place comprehensive, sound and effective rules, procedures, mechanisms and arrangements to manage the ICT risk which it may pose to financial entities. The ESAs on the 18th of November 2025 published their initial list of designated critical ICT third-party providers under DORA:
• Accenture plc;
• Amazon web Services EMEA Sarl;
• Bloomberg L.P.;
• Capgemini SE;
• Colt Technology Services;
• Deutsche Telekom AG;
• Equinix (EMEA) B.V.;
• Fidelity National Information Services, Inc.;
• Google Cloud EMEA Limited;
• International Business Machine Corporation;
• InterXion HeadQuarters B.V.;
• Kyndryl Inc.;
• LSEG Data and Risk Limited;
• Microsoft Ireland Operations Limited;
• NTT DATA Inc.;
• Oracle Nederland B.V.;
• Orange SA;
• SAP SE;
• Tata Consultancy Services Limited.