VND-015 Subcontractor Disclosure and Change Approval
Description
A disclosure record available to customers names every subcontractor that underpins a customer-facing service, the part of the service it performs, the ICT products, services and processes it provides, a contact point for it, the country it operates from and its legal entity identifier. An intended material change to that set is notified to the affected customers before it is made, with a stated notice period during which a customer may object, and the change is not implemented while an objection is open or before the period ends. Where a subcontractor is engaged into a service the organisation has committed as critical for a customer, the subcontract carries the monitoring, reporting, continuity, security and audit access terms that customer's contract requires, together with requirements on the subcontractor's personnel for awareness, skills, training and where appropriate certification, verification of their background, an obligation to handle vulnerabilities that present a risk to the organisation's systems and an obligation to supply security updates through the life of the product or service or to replace it after support ends. The disclosure record links each of those terms to the subcontract that carries it, and it is kept current rather than reviewed on a cycle.
Rationale
Subcontracting stops being a disclosure and becomes a permission the moment a customer can object: the change waits, whether or not anything is wrong with it, and adding a party the customer did not approve is a termination ground on its own. That constraint reaches the organisation's own infrastructure roadmap, which is why it sits in a control rather than in a contract schedule. The contact point and the product list are the two fields that make the record usable during an incident, when the question is who to call about which component rather than who signed what. Flow-down is the expensive half: satisfying it means renegotiating upstream contracts, not only the customer-facing one, so the record links the term to the subcontract rather than asserting that equivalent terms exist somewhere. Boundaries. VND-003 is the sub-processor register: personal data, notice, a right to object and equivalent processing obligations. This control is the ICT supply chain underpinning service delivery whether or not personal data is involved, with the hold on the change and the flow-down. Where a party is both, both apply and the artefact is one register with two columns. VND-001 assesses a supplier before engagement and holds the register of all direct suppliers; this one discloses the subset underpinning a customer-facing service and governs changing it. VND-002 holds the terms the organisation requires of any supplier it buys from; this one holds the subset a customer's contract makes it flow down. VND-014 grants the audit access this control pushes into the subcontract. VND-013 states the termination ground an unapproved change creates.
Applicability (9 profiles)
The chain behind a multi-tenant service is invisible to the customer unless it is disclosed, and a change to it lands on the customer's workload without the customer touching anything.
The deployer reads the provider's subcontractor disclosure and objects through it under VND-002 and VND-003 rather than publishing one. Where it supplies a service to external customers, the disclosure and the hold on a change are its own and it reads the row on saas-ai-provider.
Condition: deployment_model in cloud-saas, cloud-single-tenant
The chain behind a multi-tenant service is invisible to the customer unless it is disclosed, and a change to it lands on the customer's workload without the customer touching anything. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).
The chain behind a multi-tenant service is invisible to the customer unless it is disclosed, and a change to it lands on the customer's workload without the customer touching anything.
The deployer reads the provider's subcontractor disclosure and objects through it under VND-002 and VND-003 rather than publishing one. Where it supplies a service to external customers, the disclosure and the hold on a change are its own and it reads the row on saas-ai-provider.
The chain behind a multi-tenant service is invisible to the customer unless it is disclosed, and a change to it lands on the customer's workload without the customer touching anything.
RTS 2025/532 turns subcontracting from a disclosure into a permission: Art. 5 holds the change until the customer approves or the notice period lapses, Art. 4(1) pushes the customer's monitoring, reporting, security and audit access terms into the subcontract and Art. 3(1)(b) to (d) makes the provider evidence that it can identify every subcontractor of a critical or important service and grant the same access rights through the chain. ITS 2024/2956 Art. 3(6) is where the legal entity identifier per party comes from. VND-003's note shrinks to the personal data arm.
The chain behind a multi-tenant service is invisible to the customer unless it is disclosed, and a change to it lands on the customer's workload without the customer touching anything.
Annex point 5.2 adds two fields to every register entry, a contact point for the party and the list of ICT products, ICT services and ICT processes it provides, kept up to date rather than reviewed on a cycle. Point 5.1.4 adds four contract terms to the subcontract for a customer-facing service: competence, skills, training and where appropriate certification of the party's employees at point (b), verification of their background at point (c), an obligation to handle vulnerabilities presenting a risk to the entity's systems at point (f) and the requirements applying where that party subcontracts further at point (g). Point 6.1.2(b) adds security updates through the life of the product or replacement after support ends. VND-001 keeps the register of direct suppliers as a whole and VND-002 the general contract terms.
Framework Mappings (10)
| DORA-Art.29 | Preliminary assessment of ICT concentration risk at entity level | informative |
| DORA-Art.30.2.a | Description of functions and ICT services, and subcontracting permission | partial |
| DORA-RTS-2025/532-Art.3.1 | Conditions assessed before subcontracting is permitted | partial |
| DORA-RTS-2025/532-Art.4.1 | Contract conditions for subcontracting critical or important functions | partial |
| DORA-RTS-2025/532-Art.5 | Material changes to subcontracting arrangements | full |
| DORA-RTS-2025/532-Art.6 | Termination for unauthorised subcontracting changes | informative |
| NIS2-CIR-10.2 | Verification of Background | partial |
| NIS2-CIR-5.1 | Supply Chain Security Policy | partial |
| NIS2-CIR-5.2 | Directory of Suppliers and Service Providers | informative |
| NIS2-CIR-6.1 | Security in Acquisition of ICT Services or ICT Products | partial |
Evidence (2)
Subcontractor disclosure record as available to customers, with the change notices issued in the period and the implementation dates of the changes they announced.
Example: Subcontractor disclosure page captured 30 June 2026, listing 23 parties, with change notices SC-2026-03 and SC-2026-07 and their implementation records.
Test: Verify: (1) every subcontractor in the record carries the part of the service it performs, the ICT products, services and processes it provides, a contact point, the operating country and a legal entity identifier, (2) the record reconciles to the subcontracts in force for the services it covers, with no party supplying a customer-facing service and missing from it, (3) each change notice in the period states the notice period and the route for objecting, (4) for each notified change, the implementation date falls after the notice period closed or after the recorded customer approval, and no change was implemented while an objection was open, (5) no subcontractor in the record for a service committed as critical was added without a notice, (6) the contact point for one entry is reachable and resolves to a party able to answer about that component.
Executed subcontract for a subcontractor engaged into a service committed as critical for a customer, with the clause map linking each flowed-down term to the customer contract that requires it.
Example: Executed managed database services agreement with Corvus Data Ltd, signed 19 May 2026, with clause map CM-CORVUS-01 of 22 May 2026.
Test: Take a subcontractor in the disclosure record for a service committed as critical and request its subcontract. Verify: (1) the subcontract carries the monitoring, reporting, continuity, security and audit access terms the customer contract requires, (2) the audit access term names the customer and the authorities supervising it rather than the organisation alone, (3) requirements on the subcontractor's personnel for awareness, skills, training and where appropriate certification are present and background verification is required for the roles that reach the service, (4) the subcontract obliges the subcontractor to handle vulnerabilities presenting a risk to the organisation's systems and to supply security updates through the life of the product or service or replace it after support ends, (5) the clause map links each term to the customer contract requiring it and the disclosure record points at this subcontract, (6) the terms are in the executed instrument rather than in a supplier policy the subcontractor can revise on its own.
Questions (3)
Is a record of the subcontractors underpinning each customer-facing service made available to customers?
This is the ICT supply chain behind the service, whether or not personal data is involved. A sub-processor list covering only parties that process personal data is a no unless it also reaches the rest of the chain.
Which of the following does the subcontractor change process provide?
Answer on what the process does rather than on what a contract template offers. The third and fourth options differ: a change can be held until the notice period closes and still go ahead over an objection raised inside it.
What identifies each subcontractor in the record?
Options run from the most complete entry to the least. Answer on the record as published, not on what the internal supplier register holds.