Skip to content
Contract Review

What Banks Look for in SaaS Vendor Contracts

5 min readUpdated 5 August 2026

Selling SaaS into financial services requires navigating one of the most demanding vendor qualification processes in any industry. Banks and regulated financial entities are required under DORA, EBA outsourcing guidelines, and their own internal policies to conduct detailed contract reviews before onboarding technology vendors. Understanding what banks check — and why — helps SaaS vendors accelerate their sales cycles significantly.


Why Banks Have Stringent Vendor Review Processes

Banks are subject to multiple regulatory frameworks that impose direct obligations on their technology supply chain:

DORA (Digital Operational Resilience Act): In force from January 2025, requires financial entities to maintain a Register of Information of all ICT third-party service providers, conduct risk assessments of critical vendors, and include specific contractual provisions in ICT vendor agreements (Article 30).

EBA ICT and Security Risk Management Guidelines: The European Banking Authority guidelines require banks to assess ICT vendor risk, conduct due diligence, and ensure contracts contain specific provisions before onboarding.

ECB Supervisory Expectations: The ECB publishes expectations for significant institutions on cloud and technology outsourcing that inform procurement standards.

Internal Policy: Most banks have internal third-party risk management (TPRM) programmes layered on top of regulatory requirements, often more demanding than the minimum regulatory floor.

The result: a SaaS vendor selling to a bank can expect a contract review process that takes weeks and covers 50–100 specific requirements. Preparation reduces this dramatically.


What Banks Check in SaaS Vendor Contracts

DORA Article 30 Mandatory Clauses

Every ICT vendor contract with a regulated financial entity must include (Article 30(2)):

  • Clear and complete description of all services: Not just the headline service, but all components, including any processing that occurs in sub-contractors' infrastructure
  • Location of data processing: Where data is stored, processed, and backed up — at country and data centre level
  • Provisions on availability, authenticity, integrity, and confidentiality: Specific security commitments, not general statements
  • Guaranteed access, inspection, and audit rights: Banks must be able to audit their critical vendors. The contract must explicitly grant this right
  • Termination rights: Including what happens to data on termination
  • Incident reporting obligations: Timelines for notifying the bank of ICT incidents — typically 4 hours for major incidents affecting financial services customers under DORA

Additional Provisions Banks Expect

Beyond Article 30 mandatory clauses, bank procurement teams typically check for:

Business continuity and disaster recovery:

  • RTO (Recovery Time Objective) and RPO (Recovery Point Objective) commitments in the contract
  • Documented BCP tested at least annually
  • Evidence of BCP testing results available on request

Sub-processor / subcontractor disclosure:

  • Complete list of sub-contractors with access to the bank's data
  • Notification obligation when sub-contractors change
  • Contractual chain: vendor must impose equivalent obligations on sub-contractors

Cloud provider concentration:

  • If the SaaS runs on AWS, Azure, or GCP, banks assess their concentration risk across their own vendor portfolio. They may request alternative cloud options or multi-cloud deployment
  • DORA Article 29 includes requirements for financial entities to address concentration risk from critical ICT providers

Penetration testing:

  • Annual penetration testing as a minimum
  • Results available for review (or evidence of remediation)
  • Some banks will request TLPT (threat-led penetration testing) for critical vendors

Data residency:

  • Many banks require EU data residency, particularly for personal data
  • Contract must specify data location and prohibit transfers outside agreed geographies without bank approval

Intellectual property and insolvency provisions:

  • Escrow arrangements for source code (for critical bespoke software)
  • Step-in rights if the vendor becomes insolvent or is acquired

GDPR / Data Protection

  • Article 28-compliant DPA
  • International transfer mechanism if vendor uses non-EEA sub-processors
  • Breach notification timeline aligned with GDPR (72 hours) and DORA (4 hours for operational incidents)
  • Data retention and deletion provisions
  • Data subject rights assistance

The Procurement Questionnaire Process

Before contract review, most banks issue a vendor due diligence questionnaire (DDQ) — sometimes called a security questionnaire or third-party risk assessment. Standard questionnaire frameworks include:

  • SIG (Standardised Information Gathering): 800+ questions across 18 domain areas
  • CAIQ (Consensus Assessments Initiative Questionnaire): Cloud Security Alliance framework
  • Bank-specific questionnaires: Each major bank has its own version, often longer than the standard frameworks

Completing these accurately takes significant time. SaaS vendors in enterprise sales cycles should maintain a master response document covering all major frameworks.


Accelerating Bank Sales with Compliance Preparation

SaaS vendors who close financial services deals fastest typically:

  1. Have a published DPA — publicly available, Article 28-compliant, with DORA Article 30 provisions included
  2. Maintain a current sub-processor list — publicly accessible, updated with change notifications
  3. Hold a relevant certification — ISO 27001 or SOC 2 Type II, with current certificate available
  4. Complete standard questionnaires in advance — maintain master SIG/CAIQ responses that can be quickly adapted
  5. Have documented BCP/DR policies — with test evidence available on request
  6. Know their data locations — can answer "where is data stored?" at a country and data centre level without delay

ComplyOne identifies every EU regulation that applies to your business in 5 minutes — free, no credit card.

See which regulations apply to you →