Across the Middle East, regulators such as the Communications, Space & Technology Commission (CST), central banks, and financial authorities are introducing operational resilience and third-party technology risk frameworks that closely align with global standards like the EU’s Digital Operational Resilience Act (DORA). These frameworks focus on:
This regulatory evolution reflects a broader trend: resilience expectations are rising globally as firms bring risk management practices up to date and in-line with best practice.
Even though the most severe financial penalties in some frameworks may still be years away, regulatory engagement has already begun.
Early findings are prompting businesses to remediate gaps now, creating operational and reputational pressure before fines are ever issued.
Contractual clarity
Many contractual addendums that have been common practice previously have lacked in detail, leading to prolonged negotiations and delayed outcomes. The CST framework looks to remedy this with more specific regulation.
Supplier classification issues and capability gaps
Some software vendors resist being classified as “critical”. When it comes to capability, some suppliers simply cannot meet resilience expectations, requiring identification, remediation planning, and often transition support, slowing resolution and creating ambiguity in regulatory expectations.
Cost and proportionality
Discussions around proportional mitigation costs can stretch out through rounds of negotiation, distracting teams and diminishing momentum.
.
Intragroup outsourcing oversight
A surprising number of firms assume that internal group providers are compliant without ever validating it. While you can outsource operations, you cannot outsource risk. At Escode, we recommend verification of preparedness by intragroup suppliers; especially in stressed exit planning.
DORA requires financial institutions to maintain critical services during disruptions. Software escrow supports this by providing secure access to source code and technical documentation if a vendor is unable to meet their obligations, helping institutions continue operations with minimal disruption.
DORA places a strong emphasis on assessing and managing third-party risk, particularly where critical services are involved. Software escrow reduces this dependency by ensuring institutions can maintain and support applications even if a vendor fails or experiences operational challenges.
To meet DORA’s requirements for ICT resilience, institutions must be prepared to recover from disruptions. Software escrow helps by securing essential software assets, allowing internal teams or alternative providers to restore and maintain service if a vendor is unavailable.
DORA requires institutions to have clear and tested exit plans for critical third-party services. Software escrow agreements ensure access to the materials needed to transition services to a new provider. Software escrow verification enables firms to test exit plans by verifying that the material deposited into escrow is correct, complete, and can be rebuilt into the working application either in-house or with an alternative vendor.
DORA expects financial institutions to maintain records that demonstrate effective ICT risk management. Software escrow agreements define clear terms for software access and compliance while software escrow verification provides evidence that deposits are complete and deployable, offering a transparent audit trail that meets regulatory expectations.
Omer Ahmed Khan
Avanza Solutions
Build a stronger software resilience strategy today. Book a demo to see our platform in action, or talk to our sales team for pricing details and solutions guidance.