Banking Platform Exit Plans: A Dependency and Switching-Cost Framework
Most banks can explain why they chose a core banking, cloud or BaaS provider. Fewer can show they could actually leave one. A four-part framework for testing exit readiness.
In this research
Procurement teams are usually well prepared to answer "why this provider." They are far less often able to answer "how would we leave it." That gap does not show up until a provider's service quality drops, its ownership changes, or a regulator asks for evidence that was never produced. For a bank, a neobank or a BaaS platform, the underlying core banking, cloud or middleware relationship is rarely single-purpose: it touches ledgers, customer data, payment rails and downstream reporting at once, which is exactly why an untested exit plan is expensive to discover late.
This article sets out a framework for testing exit readiness before it is needed, built from the exit-plan expectations that UK and EU regulators already place on material outsourcing and third-party ICT arrangements. It is not legal advice and it does not describe any named firm's arrangements. Applicability depends on a firm's regulatory status, the materiality of the specific arrangement, and jurisdiction: the UK and EU regimes referenced below are aligned in substance but are separate legal frameworks with different scope and enforcement.
"Can we switch providers" is four separate questions
Treated as a single yes/no question, exit readiness collapses distinct risks into one reassuring answer. In practice it splits into four:
- Data. Can the firm actually extract its data and configuration, in a usable format, on a bounded timeline?
- Operations. Does the firm know which internal processes, staff and downstream systems depend on this provider precisely enough to hand them over?
- Contingency. If the provider fails without warning, is there a bridge (escrow, a dual-run capability, a manual fallback) that buys time without harming customers?
- Contract. Do the termination rights, notice periods and sub-outsourcing controls in the actual agreement support the exit the firm would need to make?
A firm can be strong on one of these and dangerously exposed on another. A contract with clean termination clauses is not evidence that a data export has ever been attempted; a provider that promises full data portability in a sales deck is not the same as a firm that has run the extract. The framework below scores each dimension separately rather than producing one aggregate figure, because the underlying regulatory material does not support collapsing them.
What UK and EU regulators actually expect
The Prudential Regulation Authority's supervisory statement on outsourcing sets out its expectations in a dedicated chapter on business continuity and exit plans. The PRA's March 2026 update to that statement, which takes effect from 18 March 2027 alongside a wider third-party reporting policy statement, expects firms to develop, maintain and test a documented exit strategy for each material outsourcing arrangement that separately covers a stressed exit, following the failure or insolvency of the provider, and a non-stressed exit for commercial, performance or strategic reasons. The PRA does not prescribe a specific exit method; its focus is whether the firm can keep delivering the affected business service within its stated impact tolerance, however the exit is achieved. PRA SS2/21, Chapter 10 (March 2026 update, effective 18 March 2027)[1]
The same chapter expects exit preparation to start during the pre-outsourcing due-diligence phase, not once an exit is already underway. That includes estimating the cost, resourcing and timing of a future exit, and identifying which data would need to be recovered first. It also treats temporary bridging arrangements, such as an escrow deal that keeps a service usable for a transitional period after termination, as an accepted way to sustain operations through a stressed exit even when they are not a viable long-term solution. PRA SS2/21, Chapter 10[1]
The European Banking Authority's outsourcing guidelines, which apply to EU credit institutions, investment firms and payment or e-money institutions, set out closely aligned expectations for critical or important functions: a documented exit strategy covering termination, provider failure, quality deterioration and material continuity risk, developed through a business impact analysis that identifies the resources and time an exit would take, with defined success criteria and monitoring indicators that should trigger an exit. EBA Guidelines on outsourcing arrangements, paragraphs 106–108[2]
For ICT services specifically, the EU's Digital Operational Resilience Act adds its own exit-strategy requirement in Article 28 for services supporting critical or important functions, covering possible provider failure, service-quality deterioration and business disruption, with transition plans to remove data and services and move them to an alternative provider or back in-house. DORA, Article 28[3]
On the UK side, the FCA's operational resilience framework requires in-scope firms to have identified their important business services and set impact tolerances for the maximum disruption those services can tolerate: the outcome an exit plan is meant to protect, rather than a substitute for one. The compliance deadline for operating within impact tolerances was 31 March 2025; a further reporting requirement for material third-party arrangements takes effect 18 March 2027, a date independently confirmed by the PRA's own supervisory-statement update. FCA operational resilience[4]
Methodology: CloudFintech created this original worksheet from the exit-plan expectations in PRA SS2/21 Chapter 10, EBA outsourcing guidelines paragraphs 106-108 and DORA Article 28. Every readiness rating is a reader-supplied assessment of their own arrangement; the worksheet is not a compliance checklist, a legal opinion or a prediction of any provider's reliability.
Primary sources: PRA SS2/21, Chapter 10 (March 2026 update); EBA Guidelines on outsourcing arrangements; DORA, Article 28; FCA operational resilience
Download underlying datasetFor a single material arrangement, score data portability, operational handover, the contingency bridge and contract rights separately, using the tested/documented/absent scale in the worksheet above. A firm that scores "tested" on contract rights and "documented only" on data portability has not extracted its data since the agreement was signed, and should treat that as an open risk rather than average it against the stronger score.
Re-run the scoring after any material change to the arrangement, such as a new sub-outsourcer, a new hosting region, or an expanded scope of services, rather than on a fixed annual date alone. The PRA's chapter on business continuity and exit plans expects firms to update their plans with lessons learned from testing, which implies the plan is a living record rather than a document produced once for a due-diligence file. PRA SS2/21, Chapter 10[1]
Where firms most often overestimate readiness
Two patterns recur. The first is treating a provider's stated data-export capability as equivalent to a tested one. A platform's documentation describing an export API is not the same as a firm having run a full extract-and-reload exercise within a defined time window and confirmed the output is usable. The EBA's guidelines are explicit that exit plans should be "sufficiently tested," for example by analysing the actual costs, impacts, resources and timing of transferring a service to an alternative provider: a test, not a description. EBA Guidelines on outsourcing arrangements, paragraph 107[2]
The second is assuming contract terms agreed at signing still hold. Termination rights, notice periods and sub-outsourcing change-control clauses are set once, during negotiation, and then rarely revisited until an exit is being considered, by which point renegotiating from a position of dependency is harder. The PRA's supervisory statement flags a sub-outsourced provider changing its list of material sub-outsourcers without notifying the firm, or failing to grant the firm and its regulators equivalent access and audit rights, as situations that may justify exercising a contractual termination right. Both are findings a periodic clause-by-clause review would catch, and neither is visible from the original signed agreement alone. PRA SS2/21, Chapter 10[1]
A short implementation sequence
Start mapping dependencies during due diligence, before a material outsourcing arrangement is signed, so alternative providers and rough exit costs are identified while there is still negotiating leverage. Define the contingency bridge, whether escrow, a dual-run capability or a manual fallback, as part of the same pre-outsourcing work, not as a reaction to a live disruption. Test the data-portability and operational-handover dimensions on a defined schedule and after any material change to the arrangement, and assign an accountable owner for reviewing the contract's termination and sub-outsourcing clauses against the current relationship, not just the clauses as originally negotiated. Record the results of each test, including gaps found, so the exit plan reflects what has actually been verified rather than what was assumed at signing.
None of this removes the underlying dependency a bank takes on when it outsources a core function: regulators do not expect it to. It replaces an untested assumption about exitability with a checkable one. For a related view of the technology-pattern risks in moving core banking workloads, see CloudFintech's cloud-native core banking migration guide; that article covers execution risk once a migration is under way, while the framework here covers whether an exit is achievable before one is needed.
Sources
Numbered references are anchored to the specific claims they support. Primary documents are preferred wherever available.
- PRA SS2/21, Chapter 10 (March 2026 update, effective 18 March 2027) bankofengland.co.uk ↩
- EBA Guidelines on outsourcing arrangements, paragraphs 106–108 eba.europa.eu ↩
- DORA, Article 28 eur-lex.europa.eu ↩
- FCA operational resilience fca.org.uk ↩
Frequently asked questions
What is the difference between a stressed and non-stressed exit?
A stressed exit follows an event such as the failure or insolvency of a service provider, and acts as a last-resort measure when other business-continuity steps cannot manage the disruption. A non-stressed exit is planned and managed for commercial, performance or strategic reasons. UK supervisory guidance expects firms to document and test plans for both, though the greater regulatory focus is on stressed exits because the consequences of being unprepared are more severe.
Do PRA, EBA and DORA all require the same exit-plan checklist?
No. They are aligned in substance but are separate legal regimes with different scope: PRA SS2/21 applies to UK banks, building societies, PRA-designated investment firms and insurers; the EBA guidelines apply to EU credit institutions, investment firms and payment or e-money institutions; DORA Article 28 applies specifically to EU financial entities' ICT third-party arrangements supporting critical or important functions. A firm should confirm which regime, if any, applies to its specific status and arrangement rather than assume one checklist satisfies all three.
What counts as a 'tested' exit plan rather than a documented one?
Regulatory guidance distinguishes the two. A documented plan describes an intended approach; a tested plan has been exercised, for example through an analysis of the actual costs, resources and timing of transferring a service to an alternative provider, or a completed data-extract exercise. EBA guidelines specifically call for exit plans to be sufficiently tested, not only documented.
What is an example of a contingency bridge for a stressed exit?
UK supervisory guidance cites software escrow arrangements as an example: a contractual mechanism allowing continued use of a service or technology for a transitional period after termination. It is described as a temporary measure that is not necessarily a long-term solution, intended to sustain important business services while a firm executes a fuller exit.
Why does contract review matter after an agreement is already signed?
Termination rights, notice periods and sub-outsourcing controls are typically negotiated once, at signing, and can become misaligned with how the relationship actually operates, for example if a provider changes its sub-outsourcers or restricts audit access over time. Supervisory guidance treats those situations as grounds a firm may need to rely on its termination rights for, which only works if those rights are checked against current practice rather than assumed from the original agreement.
Update history
- Published as an original exit-readiness framework for banking-platform outsourcing dependencies, mapped to PRA SS2/21, EBA outsourcing guidelines and DORA Article 28.