A focused course, tailored for you
IT Sourcing Legal Practice for CIB Banking
Build the contract skills that hold up when regulators, vendors, and internal risk teams all read the same clause differently.
The resilience clause that your vendor's legal team redlines is not a negotiation problem. It is a drafting problem. Policy-level language does not translate into enforceable contract terms without a practitioner who knows exactly which clause carries the regulatory obligation, which schedule carries the technical requirement, and which side-letter carries the risk the master agreement cannot hold.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
IT & Sourcing Legal Analysts at major CIB banks are sitting at the intersection of four simultaneous pressures. DORA has moved from policy adoption to contract enforcement, and vendors who accepted boilerplate resilience clauses last year are now disputing scope, RTO thresholds, and audit rights. EBA guidelines on third-party risk require documented concentration-risk assessments that most legacy vendor files do not have. GDPR data processor schedules negotiated before the current supervisory interpretation of 'appropriate technical and organisational measures' are being reopened. And internal risk committees want exit-plan clauses that can actually be exercised, not clauses that read well in a policy review. The analyst in the middle drafts all of it, defends all of it, and negotiates all of it with vendors who have dedicated contract management teams. The skill gap is not legal knowledge, it is the translation of regulatory obligations into specific, vendor-signable contract language.
What you walk away with
- Draft a DORA-compliant operational resilience annex that defines RTO, RPO, and recovery scope in terms a vendor legal team will sign without material redline.
- Build an exit-plan clause that satisfies EBA third-party risk guidelines and your internal concentration-risk governance without requiring a separate side agreement.
- Structure a data processor schedule that survives a GDPR supervisory review without reopening the master services agreement.
- Write a cloud-services addendum that maps SLA breach to contractual remedy in a way your internal risk committee will approve on first review.
- Produce a third-party risk file that demonstrates regulatory compliance without requiring the vendor to disclose sub-processor chains beyond what the agreement already covers.
- Negotiate audit-rights clauses that satisfy your internal information security team while remaining acceptable to a vendor's standard commercial terms.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- Twelve written modules covering DORA, EBA third-party risk, GDPR processor terms, cloud SLA-to-remedy conversion, and multi-jurisdictional CIB sourcing.
- Downloadable clause library organised by regulatory obligation (DORA, EBA GL/2019/02, GDPR Article 28, PRA SS2/21).
- Vendor-redline response templates for the four most common positions in regulated-bank IT sourcing negotiations.
- Amendment checklist for bringing legacy agreements into current compliance without full renegotiation.
- Third-party risk file template formatted for supervisory and risk-committee presentation.
- Hand-built implementation playbook, delivered alongside course access, covering your specific contract portfolio and vendor mix.
What you will have in hand by Day 1, Week 1, Month 1
Course access and the hand-built implementation playbook are both provisioned within 24 hours of purchase.
The implementation playbook is built for your specific contract portfolio and vendor mix, not a generic template.
Modules are self-paced, written format. Most analysts complete the full course across two to three working weeks.
Before and after
The resilience clause gets redlined by every vendor. The exit plan looks complete on paper but cannot be executed. The legacy vendor file has gaps the risk committee keeps flagging. Each contract cycle takes longer than the last because the same four positions come up and there is no established counterproposal.
A clause library that translates regulatory obligations into vendor-signable language. An exit-plan template that passes risk-committee review on first submission. A legacy-amendment checklist that closes the compliance gap without triggering full renegotiation. A documented counterproposal position for the four most common vendor redlines.
What happens if you do not address this
The current regulatory cycle is compressing the window between policy adoption and contract enforcement. Banks that do not have vendor agreements updated for DORA resilience, EBA concentration risk, and current GDPR processor standards before the next supervisory review will be remediating under time pressure rather than on their own schedule. The analyst who cannot draft these clauses will be dependent on external counsel for work that should be handled internally.
Who it is for
You are an IT or Sourcing Legal Analyst at a major bank or financial institution, operating in the CIB, wholesale, or corporate banking division. You draft and negotiate IT vendor agreements, outsourcing contracts, and data processing agreements. You work across internal risk, compliance, procurement, and technology teams. You understand the regulatory landscape in principle but need the practitioner-level contract drafting skills to operationalise it.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Each module is written for a 30-45 minute focused read. Full course: approximately 8-10 hours across twelve modules. The implementation playbook adds a further 4-6 hours of applied work against your own vendor file.
Why $199 is the right number
External counsel charges by the hour for the same contract drafting this course teaches internally. A single vendor negotiation handled externally costs more than this course. Internal legal training programmes at major banks cover regulatory frameworks but rarely reach practitioner-level contract drafting for IT sourcing specifically. This course fills that gap at a fixed cost.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.