Skip to main content
Image coming soon

IT Sourcing Legal Practice for CIB Banking

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

IT Sourcing Legal Practice for CIB Banking

Build the contract skills that hold up when regulators, vendors, and internal risk teams all read the same clause differently.

The resilience clause that your vendor's legal team redlines is not a negotiation problem. It is a drafting problem. Policy-level language does not translate into enforceable contract terms without a practitioner who knows exactly which clause carries the regulatory obligation, which schedule carries the technical requirement, and which side-letter carries the risk the master agreement cannot hold.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

IT & Sourcing Legal Analysts at major CIB banks are sitting at the intersection of four simultaneous pressures. DORA has moved from policy adoption to contract enforcement, and vendors who accepted boilerplate resilience clauses last year are now disputing scope, RTO thresholds, and audit rights. EBA guidelines on third-party risk require documented concentration-risk assessments that most legacy vendor files do not have. GDPR data processor schedules negotiated before the current supervisory interpretation of 'appropriate technical and organisational measures' are being reopened. And internal risk committees want exit-plan clauses that can actually be exercised, not clauses that read well in a policy review. The analyst in the middle drafts all of it, defends all of it, and negotiates all of it with vendors who have dedicated contract management teams. The skill gap is not legal knowledge, it is the translation of regulatory obligations into specific, vendor-signable contract language.

What you walk away with

  • Draft a DORA-compliant operational resilience annex that defines RTO, RPO, and recovery scope in terms a vendor legal team will sign without material redline.
  • Build an exit-plan clause that satisfies EBA third-party risk guidelines and your internal concentration-risk governance without requiring a separate side agreement.
  • Structure a data processor schedule that survives a GDPR supervisory review without reopening the master services agreement.
  • Write a cloud-services addendum that maps SLA breach to contractual remedy in a way your internal risk committee will approve on first review.
  • Produce a third-party risk file that demonstrates regulatory compliance without requiring the vendor to disclose sub-processor chains beyond what the agreement already covers.
  • Negotiate audit-rights clauses that satisfy your internal information security team while remaining acceptable to a vendor's standard commercial terms.

The 12 modules

Module 1. Regulatory Obligations as Contract Language
DORA, EBA GL/2019/02, and GDPR each impose obligations that appear in policy documents before they appear in contracts. This module maps each obligation to the specific clause type that carries it: which obligations belong in the master agreement, which belong in the service schedule, which require a separate annex. You leave with a clause-mapping worksheet that works across your existing vendor file structure.
Module 2. Drafting the DORA Operational Resilience Annex
The resilience annex is where most vendor negotiations stall. This module covers the four elements that determine whether a vendor will sign: RTO and RPO definitions scoped to the specific service, recovery testing obligations tied to your BCP calendar, incident notification windows that comply with DORA Article 19 without requiring real-time reporting, and audit-right language scoped to resilience rather than general operations. Each element is drafted with the common vendor objection alongside it.
Module 3. EBA Third-Party Risk: The Documentation File
The EBA third-party risk guidelines require a documentation file that most banks are building retrospectively from legacy vendor agreements. This module covers what the file must contain, what can be sourced from existing agreements versus what requires new contract language, and how to structure the concentration-risk narrative for the governance committee. You produce a file template that works for both your supervisory team and your internal third-party risk function.
Module 4. Exit Plans That Can Actually Be Executed
Exit-plan clauses are easy to write at the policy level and nearly impossible to execute. This module covers the four elements that make one enforceable: the transition-assistance obligation specifying what the vendor must provide and for how long, the data-return schedule naming formats and timelines, the knowledge-transfer clause creating a measurable deliverable rather than a best-efforts obligation, and the handover period aligned to your internal programme timeline. Each is tested against common vendor redlines.
Module 5. GDPR Data Processor Schedules: Current Supervisory Standard
The supervisory interpretation of 'appropriate technical and organisational measures' has moved since most processor schedules were drafted. This module covers the current standard for financial-services data processors, the sub-processor disclosure obligation vendors most frequently dispute, the audit-rights clause that satisfies your DPO without giving the vendor grounds to refuse, and the breach notification timeline aligned to both GDPR Article 33 and your internal incident-response procedure. Output: a schedule template ready for your next renewals.
Module 6. Cloud Services Addendum: SLA to Contractual Remedy
Cloud vendor SLAs are written for their benefit, not yours. This module covers the gap between an SLA and a contractual remedy: converting uptime commitments into credit mechanisms your finance team will accept, defining 'material breach' in terms that trigger termination rather than credit accrual, and negotiating a cloud-security schedule that maps to your ISMS controls without requiring the vendor to rewrite their standard exhibit. Worked through clause by clause against a CIB cloud migration pattern.
Module 7. Concentration Risk: The Contract Disclosure
Concentration risk governance requires a disclosure to your supervisory team about vendor dependencies. Most IT sourcing files lack the contractual language to enable that disclosure. This module covers drafting a vendor-dependency clause naming the specific services creating concentration risk, building a contract-level narrative your second-line risk function can present to the committee, and structuring a multi-vendor clause where a single service depends on two or more providers mapped to your concentration-risk threshold.
Module 8. Audit Rights: Scope, Frequency, and Vendor Acceptance
Audit-rights clauses fail in two directions: too broad and the vendor refuses to sign; too narrow and your information security team cannot work. This module covers scope language that satisfies your CISO while remaining acceptable to a vendor's standard terms, frequency and notice-period provisions your supervisory team will accept, the right to appoint a third-party auditor without vendor consent, and an audit-findings clause that creates a remediation obligation. Pattern-tested against EBA, DORA, and PRA expectations.
Module 9. Vendor Redlines: The Four Most Common and How to Resolve Them
The four redline positions that appear most frequently in IT sourcing negotiations at regulated banks are: limiting audit rights to 'information security' rather than 'operational resilience', replacing exit-transition obligations with 'commercially reasonable efforts', capping liability below the annual contract value for data breaches, and removing sub-processor disclosure entirely. This module covers the counterproposal language for each position, the internal approval path for each concession, and the escalation point where the negotiation requires risk-committee visibility rather than analyst-level resolution.
Module 10. Multi-Jurisdictional Contracts: CIB Cross-Border Sourcing
CIB sourcing agreements frequently span multiple jurisdictions, with services delivered from locations outside the EEA, governed by law outside the EU, and processed by sub-processors in jurisdictions without an adequacy decision. This module covers the governing-law election that protects your regulatory position, the data-transfer mechanism that survives a Schrems II challenge, the sub-processor addendum that works for a vendor with delivery centres in multiple jurisdictions, and the dispute-resolution clause that your internal legal team can actually enforce.
Module 11. Contract Renewal: Bringing Legacy Agreements into Current Compliance
Most banks hold IT vendor agreements signed before current regulatory standards that are now non-compliant on DORA resilience, EBA third-party risk, or GDPR processor terms. This module covers the triage method for a legacy vendor file, the amendment strategy that achieves compliance without triggering full renegotiation, the addendum structure that layers new obligations onto existing commercial terms, and the communication approach for presenting the amendment to a vendor who believes their existing contract already complies.
Module 12. Building Your Practitioner File
The final module assembles a practitioner file you will use across your next contract cycle: a clause library organised by regulatory obligation and clause type, a vendor-redline response template for the four most common positions, an amendment checklist for legacy agreements, and a governance narrative template for presenting third-party risk files to the risk committee. Each element is built from the materials in the preceding modules, customised to the CIB sourcing context, and formatted for immediate use.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Vendor pushes back on the DORA resilience clause: Module 2 (Operational Resilience Annex) plus Module 9 (Vendor Redlines).
Risk committee flags a concentration-risk gap in the vendor file: Module 3 (EBA Documentation File) plus Module 7 (Concentration Risk Disclosure).
DPO flags a data processor schedule that does not meet current GDPR supervisory standard: Module 5 (GDPR Data Processor Schedules).
Legacy vendor agreement needs to be brought into DORA and EBA compliance before the next regulatory review: Module 11 (Contract Renewal: Legacy Agreements).

What you get with this course

  • Twelve written modules covering DORA, EBA third-party risk, GDPR processor terms, cloud SLA-to-remedy conversion, and multi-jurisdictional CIB sourcing.
  • Downloadable clause library organised by regulatory obligation (DORA, EBA GL/2019/02, GDPR Article 28, PRA SS2/21).
  • Vendor-redline response templates for the four most common positions in regulated-bank IT sourcing negotiations.
  • Amendment checklist for bringing legacy agreements into current compliance without full renegotiation.
  • Third-party risk file template formatted for supervisory and risk-committee presentation.
  • Hand-built implementation playbook, delivered alongside course access, covering your specific contract portfolio and vendor mix.

What you will have in hand by Day 1, Week 1, Month 1

Course access and the hand-built implementation playbook are both provisioned within 24 hours of purchase.

The implementation playbook is built for your specific contract portfolio and vendor mix, not a generic template.

Modules are self-paced, written format. Most analysts complete the full course across two to three working weeks.

Before and after

Before

The resilience clause gets redlined by every vendor. The exit plan looks complete on paper but cannot be executed. The legacy vendor file has gaps the risk committee keeps flagging. Each contract cycle takes longer than the last because the same four positions come up and there is no established counterproposal.

After

A clause library that translates regulatory obligations into vendor-signable language. An exit-plan template that passes risk-committee review on first submission. A legacy-amendment checklist that closes the compliance gap without triggering full renegotiation. A documented counterproposal position for the four most common vendor redlines.

What happens if you do not address this

The current regulatory cycle is compressing the window between policy adoption and contract enforcement. Banks that do not have vendor agreements updated for DORA resilience, EBA concentration risk, and current GDPR processor standards before the next supervisory review will be remediating under time pressure rather than on their own schedule. The analyst who cannot draft these clauses will be dependent on external counsel for work that should be handled internally.

Who it is for

You are an IT or Sourcing Legal Analyst at a major bank or financial institution, operating in the CIB, wholesale, or corporate banking division. You draft and negotiate IT vendor agreements, outsourcing contracts, and data processing agreements. You work across internal risk, compliance, procurement, and technology teams. You understand the regulatory landscape in principle but need the practitioner-level contract drafting skills to operationalise it.

Who this is NOT for. General-practice lawyers with no financial-services client base. Procurement managers who do not own contract drafting. Compliance officers building policy frameworks rather than enforceable agreements. Anyone whose work does not involve vendor-facing contract language in a regulated banking context.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Each module is written for a 30-45 minute focused read. Full course: approximately 8-10 hours across twelve modules. The implementation playbook adds a further 4-6 hours of applied work against your own vendor file.

Why $199 is the right number

External counsel charges by the hour for the same contract drafting this course teaches internally. A single vendor negotiation handled externally costs more than this course. Internal legal training programmes at major banks cover regulatory frameworks but rarely reach practitioner-level contract drafting for IT sourcing specifically. This course fills that gap at a fixed cost.

FAQ

Is this course specific to EU-regulated banks?
The regulatory framework covered (DORA, EBA third-party risk guidelines, GDPR) applies to EU-regulated institutions. Much of the contract-drafting methodology applies more broadly to any IT sourcing legal function in a regulated financial-services context.
Does the course cover PRA-supervised entities in the UK?
Yes. Module 8 covers audit-rights expectations against EBA, DORA, and PRA supervisory standards. Module 11 includes PRA SS2/21 in the legacy-amendment checklist.
What is the implementation playbook and how is it tailored?
The implementation playbook is a hand-built document that applies the course methodology to your specific context: the regulatory obligations you are working against, the vendor categories in your portfolio, and the internal governance path your contracts follow. It is not a generic template. It is built after purchase based on the information you provide.
How is this different from a standard legal skills course?
This course is written for an IT sourcing legal analyst working in a regulated banking environment. Every module references the specific regulatory obligations, vendor redline patterns, and internal governance structures that this role encounters. It is not a general contract-drafting course applied to financial services.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.