Financial entities shall have in place exit strategies for ICT services provided by ICT third-party service providers, taking into account risks that may emerge at the level of the ICT third-party service provider, in particular a possible failure, a deterioration of the quality of the ICT services provided, any business disruption due to inappropriate or failed provision of ICT services or any material risk arising in relation to the appropriate and continuous deployment of the respective ICT service.
Document defining exit strategies for ICT third-party service providers, including transition plans, data migration procedures, alternative provider arrangements, and timeline estimates as required by DORA Article 44.
exit-strategy-documentationGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
ICT PROVIDER EXIT STRATEGY
Meridian Cloud Services GmbH — Core Banking Infrastructure Hosting
Nordvik Bank AG
Strategy Reference: EXIT-PRV001-2025-001
Version 1.2 | Created: 15 March 2024 | Last Updated: 20 January 2025
Strategy Owner: Vendor Management Officer
Classification: Confidential
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
EXIT STRATEGY OVERVIEW
This document defines the exit strategy for the Bank's contractual arrangement
with Meridian Cloud Services GmbH ("Meridian") for core banking infrastructure
hosting services, as required by DORA Article 44. The strategy addresses planned
and unplanned exit scenarios, transition procedures, data migration, and
alternative provider arrangements.
Provider: Meridian Cloud Services GmbH
Service: Core banking infrastructure hosting (IaaS)
Contract Reference: CTR-PRV001-2021-003
Contract End Date: 28 February 2026
Criticality: Critical
Annual Contract Value: EUR 2,450,000
Transition Assistance: 12 months (per MSA Clause 15.3)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
TRIGGER EVENTS
The following events would trigger activation of this exit strategy:
Planned Exit Triggers:
— Contract expiry without renewal (28 February 2026)
— Strategic decision to change hosting provider (e.g., cloud migration)
— Merger or acquisition requiring infrastructure consolidation
Unplanned Exit Triggers:
— Material breach of contract by Meridian (MSA Clause 15.2)
— Meridian insolvency or financial distress
— Regulatory direction to terminate the arrangement (FINMA, ECB)
— Chronic underperformance (availability below 99.9% for 3 consecutive months)
— Security breach at Meridian affecting Bank data confidentiality or integrity
— Meridian acquisition by entity creating unacceptable concentration risk
— Loss of critical certifications (ISO 27001, PCI-DSS)
Escalation for Unplanned Triggers:
— CIO and CRO notified immediately
— Board Risk Committee notified within 24 hours
— FINMA notified if trigger relates to critical function disruption
— Exit strategy activation decision within 5 business days
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
TRANSITION PLAN
Phase 1: Preparation (Months 1-3)
Activities:
— Activate transition governance (Transition Steering Committee)
— Finalise alternative provider selection (see Alternative Provider section)
— Negotiate and execute contract with alternative provider
— Establish project team (Bank: 8 FTE; Provider: 4 FTE estimated)
— Conduct detailed technical assessment of target environment
— Develop detailed migration plan with workload prioritisation
Deliverables:
— Signed contract with alternative provider
— Detailed migration plan with timeline and resource allocation
— Risk assessment for transition period
— Communication plan for internal stakeholders and regulators
Phase 2: Environment Setup (Months 3-6)
Activities:
— Provision target environment at alternative provider
— Configure network connectivity (VPN, dedicated links)
— Establish database replication to target environment
— Deploy application infrastructure (Temenos T24, middleware)
— Configure monitoring and alerting
— Implement security controls and access management
Deliverables:
— Target environment operational and security-hardened
— Database replication active and validated
— Application stack deployed and configured
— Security assessment of target environment completed
Phase 3: Migration and Testing (Months 6-12)
Activities:
— Migrate non-production environments first (dev, UAT)
— Conduct functional testing in target environment
— Conduct performance testing and capacity validation
— Migrate pre-production environment
— Conduct user acceptance testing
— Conduct parallel-run period (minimum 3 months)
— Validate disaster recovery capability at new provider
Deliverables:
— All non-production environments migrated and validated
— Performance benchmarks met or exceeded
— UAT sign-off from business stakeholders
— DR capability validated at new provider
Phase 4: Cutover (Months 12-15)
Activities:
— Final data synchronisation and cutover
— DNS and routing changes
— Production validation and smoke testing
— Hypercare period (4 weeks with enhanced monitoring)
— Decommission Meridian environment
— Data return and destruction verification
Deliverables:
— Production environment operational at new provider
— Hypercare period completed without critical issues
— Meridian data return confirmed (within 30 days per MSA)
— Meridian data destruction certified (within 60 days per MSA)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
DATA MIGRATION PROCEDURES
Data Category Volume (est.) Migration Method
─────────────────────────────────────────────────────────────────────────────
Oracle Database 4.2 TB Oracle Data Pump export/import with
continuous replication during
parallel-run period
Application Config 12 GB Ansible playbook export and
re-deployment
File Storage 850 GB Rsync with integrity verification
Backup History 18 TB Not migrated — fresh baseline at
new provider
Log Archives 2.1 TB Exported to Bank's long-term
storage (regulatory retention)
Encryption Keys N/A Re-generated at new provider;
data re-encrypted during migration
Data Integrity Verification:
— Checksums computed before and after migration for all data categories
— Row-count and hash verification for database tables
— Application-level validation tests post-migration
— Independent verification by Internal Audit
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ALTERNATIVE PROVIDER ARRANGEMENTS
Pre-qualified alternative providers (from Substitutability Analysis SA-2025-001):
Provider Readiness Notes
─────────────────────────────────────────────────────────────────────────────
AWS Financial Services High Temenos offers AWS-native
(eu-central-1) deployment. Proof-of-concept
completed Q4 2024.
Swisscom Enterprise Cloud Medium Swiss-domiciled. Capacity
validation required.
T-Systems Sovereign Cloud Medium German sovereign cloud.
Limited Temenos experience.
Preferred alternative: AWS Financial Services (eu-central-1), based on:
— Temenos T24 cloud-native deployment available
— Proof-of-concept successfully completed in Q4 2024
— Financial-grade compliance certifications (ISO 27001, SOC 2, C5, PCI-DSS)
— Geographic diversification (Frankfurt primary, Dublin secondary)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
TIMELINE AND MILESTONES
Milestone Target (from trigger)
─────────────────────────────────────────────────────────────────────────────
Exit strategy activation decision Week 1
Transition Steering Committee formed Week 2
Alternative provider contract signed Month 3
Target environment provisioned Month 6
Non-production migration complete Month 8
Parallel-run period begins Month 9
Production cutover Month 12-15
Hypercare complete Month 13-16
Meridian decommissioning complete Month 15-18
Total estimated transition duration: 15-18 months
For unplanned exit (emergency):
— Interim service continuity via Meridian transition assistance (12 months)
— Accelerated timeline targeting 12-month cutover
— Acceptance of higher risk during compressed transition
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
RESOURCE REQUIREMENTS
Resource Estimated Cost
─────────────────────────────────────────────────────────────────────────────
Alternative provider setup EUR 800,000
Migration tooling and licensing EUR 200,000
Internal project team (8 FTE) EUR 1,200,000
External migration consultants EUR 600,000
Parallel-run costs (dual hosting) EUR 400,000
Testing and validation EUR 150,000
Contingency (15%) EUR 500,000
─────────────────────────────────────────────────────────────────────────────
Total estimated transition cost: EUR 3,850,000
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
RISK ASSESSMENT
Risk Likelihood Impact Mitigation
─────────────────────────────────────────────────────────────────────────────
Extended migration timeline Medium High Parallel-run period
provides buffer
Data loss during migration Low Critical Checksums and
continuous replication
Performance degradation at Medium High Extensive performance
new provider testing before cutover
Service disruption during Low Critical Cutover during
cutover maintenance window
Meridian non-cooperation Low High Contractual transition
during transition assistance obligation
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Strategy Owner: Vendor Management Officer
Reviewed by: CIO, CRO
Approved by: Board Risk Committee
Date: 20 January 2025
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
exit_strategy_status — fs-exit-strategy-status
{
"factId": "e0f1a2b3-c4d5-6789-efab-901234567890",
"evidenceId": "d9e0f1a2-b3c4-5678-9012-345678abcdef",
"evidenceClassId": "exit-strategy-documentation",
"factType": "exit_strategy_status",
"data": {
"provider_id": "PRV-001",
"strategy_date": "2025-01-20",
"has_exit_strategy": true,
"has_transition_plan": true,
"has_data_migration_plan": true,
"alternative_provider_identified": true,
"transition_timeline_months": 18,
"data_migration_tested": false,
"estimated_transition_cost_eur": 3850000
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-01-21T14:00:00Z",
"supersededBy": null
}
fs-exit-strategy-statusDORA-Art44-P1strategy_datetransition_timeline_months{
"properties": {
"alternative_provider_identified": {
"type": "boolean"
},
"data_migration_tested": {
"type": "boolean"
},
"estimated_transition_cost_eur": {
"minimum": 0,
"type": "number"
},
"has_data_migration_plan": {
"type": "boolean"
},
"has_exit_strategy": {
"type": "boolean"
},
"has_transition_plan": {
"type": "boolean"
},
"provider_id": {
"minLength": 1,
"type": "string"
},
"strategy_date": {
"format": "date",
"type": "string"
},
"transition_timeline_months": {
"minimum": 0,
"type": "integer"
}
},
"required": [
"provider_id",
"strategy_date",
"has_exit_strategy",
"has_transition_plan",
"has_data_migration_plan"
],
"type": "object"
}