GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

VND-015 Subcontractor Disclosure and Change Approval

Tier 2+ProviderManaged Service Providerdeployment model

Description

A disclosure record available to customers names every subcontractor that underpins a customer-facing service, the part of the service it performs, the ICT products, services and processes it provides, a contact point for it, the country it operates from and its legal entity identifier. An intended material change to that set is notified to the affected customers before it is made, with a stated notice period during which a customer may object, and the change is not implemented while an objection is open or before the period ends. Where a subcontractor is engaged into a service the organisation has committed as critical for a customer, the subcontract carries the monitoring, reporting, continuity, security and audit access terms that customer's contract requires, together with requirements on the subcontractor's personnel for awareness, skills, training and where appropriate certification, verification of their background, an obligation to handle vulnerabilities that present a risk to the organisation's systems and an obligation to supply security updates through the life of the product or service or to replace it after support ends. The disclosure record links each of those terms to the subcontract that carries it, and it is kept current rather than reviewed on a cycle.

Rationale

Subcontracting stops being a disclosure and becomes a permission the moment a customer can object: the change waits, whether or not anything is wrong with it, and adding a party the customer did not approve is a termination ground on its own. That constraint reaches the organisation's own infrastructure roadmap, which is why it sits in a control rather than in a contract schedule. The contact point and the product list are the two fields that make the record usable during an incident, when the question is who to call about which component rather than who signed what. Flow-down is the expensive half: satisfying it means renegotiating upstream contracts, not only the customer-facing one, so the record links the term to the subcontract rather than asserting that equivalent terms exist somewhere. Boundaries. VND-003 is the sub-processor register: personal data, notice, a right to object and equivalent processing obligations. This control is the ICT supply chain underpinning service delivery whether or not personal data is involved, with the hold on the change and the flow-down. Where a party is both, both apply and the artefact is one register with two columns. VND-001 assesses a supplier before engagement and holds the register of all direct suppliers; this one discloses the subset underpinning a customer-facing service and governs changing it. VND-002 holds the terms the organisation requires of any supplier it buys from; this one holds the subset a customer's contract makes it flow down. VND-014 grants the audit access this control pushes into the subcontract. VND-013 states the termination ground an unapproved change creates.

Applicability (9 profiles)

SaaS AI Providerstablerequireddeployment duty

The chain behind a multi-tenant service is invisible to the customer unless it is disclosed, and a change to it lands on the customer's workload without the customer touching anything.

Enterprise AI Deployerstablenot-applicableout of scope

The deployer reads the provider's subcontractor disclosure and objects through it under VND-002 and VND-003 rather than publishing one. Where it supplies a service to external customers, the disclosure and the hold on a change are its own and it reads the row on saas-ai-provider.

GPAI Model Providerstableconditionaldeployment duty

Condition: deployment_model in cloud-saas, cloud-single-tenant

The chain behind a multi-tenant service is invisible to the customer unless it is disclosed, and a change to it lands on the customer's workload without the customer touching anything. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).

High-Risk Provider (EU)stablerequireddeployment duty

The chain behind a multi-tenant service is invisible to the customer unless it is disclosed, and a change to it lands on the customer's workload without the customer touching anything.

Public Body Deployer (EU)stablenot-applicableout of scope

The deployer reads the provider's subcontractor disclosure and objects through it under VND-002 and VND-003 rather than publishing one. Where it supplies a service to external customers, the disclosure and the hold on a change are its own and it reads the row on saas-ai-provider.

Data Act Cloud Provider (EU)stablerequireddeployment duty

The chain behind a multi-tenant service is invisible to the customer unless it is disclosed, and a change to it lands on the customer's workload without the customer touching anything.

DORA ICT Provider (EU)stablerequiredrole duty

RTS 2025/532 turns subcontracting from a disclosure into a permission: Art. 5 holds the change until the customer approves or the notice period lapses, Art. 4(1) pushes the customer's monitoring, reporting, security and audit access terms into the subcontract and Art. 3(1)(b) to (d) makes the provider evidence that it can identify every subcontractor of a critical or important service and grant the same access rights through the chain. ITS 2024/2956 Art. 3(6) is where the legal entity identifier per party comes from. VND-003's note shrinks to the personal data arm.

HIPAA Business Associate (US)stablerequireddeployment duty

The chain behind a multi-tenant service is invisible to the customer unless it is disclosed, and a change to it lands on the customer's workload without the customer touching anything.

NIS2 Cloud Provider (EU)stablerequiredrole duty

Annex point 5.2 adds two fields to every register entry, a contact point for the party and the list of ICT products, ICT services and ICT processes it provides, kept up to date rather than reviewed on a cycle. Point 5.1.4 adds four contract terms to the subcontract for a customer-facing service: competence, skills, training and where appropriate certification of the party's employees at point (b), verification of their background at point (c), an obligation to handle vulnerabilities presenting a risk to the entity's systems at point (f) and the requirements applying where that party subcontracts further at point (g). Point 6.1.2(b) adds security updates through the life of the product or replacement after support ends. VND-001 keeps the register of direct suppliers as a whole and VND-002 the general contract terms.

Framework Mappings (10)

DORA-Art.29Preliminary assessment of ICT concentration risk at entity levelinformative
DORA-Art.30.2.aDescription of functions and ICT services, and subcontracting permissionpartial
DORA-RTS-2025/532-Art.3.1Conditions assessed before subcontracting is permittedpartial
DORA-RTS-2025/532-Art.4.1Contract conditions for subcontracting critical or important functionspartial
DORA-RTS-2025/532-Art.5Material changes to subcontracting arrangementsfull
DORA-RTS-2025/532-Art.6Termination for unauthorised subcontracting changesinformative
NIS2-CIR-10.2Verification of Backgroundpartial
NIS2-CIR-5.1Supply Chain Security Policypartial
NIS2-CIR-5.2Directory of Suppliers and Service Providersinformative
NIS2-CIR-6.1Security in Acquisition of ICT Services or ICT Productspartial

Evidence (2)

recorddocumentmanual

Subcontractor disclosure record as available to customers, with the change notices issued in the period and the implementation dates of the changes they announced.

Example: Subcontractor disclosure page captured 30 June 2026, listing 23 parties, with change notices SC-2026-03 and SC-2026-07 and their implementation records.

Test: Verify: (1) every subcontractor in the record carries the part of the service it performs, the ICT products, services and processes it provides, a contact point, the operating country and a legal entity identifier, (2) the record reconciles to the subcontracts in force for the services it covers, with no party supplying a customer-facing service and missing from it, (3) each change notice in the period states the notice period and the route for objecting, (4) for each notified change, the implementation date falls after the notice period closed or after the recorded customer approval, and no change was implemented while an objection was open, (5) no subcontractor in the record for a service committed as critical was added without a notice, (6) the contact point for one entry is reachable and resolves to a party able to answer about that component.

contractdocumentmanual

Executed subcontract for a subcontractor engaged into a service committed as critical for a customer, with the clause map linking each flowed-down term to the customer contract that requires it.

Example: Executed managed database services agreement with Corvus Data Ltd, signed 19 May 2026, with clause map CM-CORVUS-01 of 22 May 2026.

Test: Take a subcontractor in the disclosure record for a service committed as critical and request its subcontract. Verify: (1) the subcontract carries the monitoring, reporting, continuity, security and audit access terms the customer contract requires, (2) the audit access term names the customer and the authorities supervising it rather than the organisation alone, (3) requirements on the subcontractor's personnel for awareness, skills, training and where appropriate certification are present and background verification is required for the roles that reach the service, (4) the subcontract obliges the subcontractor to handle vulnerabilities presenting a risk to the organisation's systems and to supply security updates through the life of the product or service or replace it after support ends, (5) the clause map links each term to the customer contract requiring it and the disclosure record points at this subcontract, (6) the terms are in the executed instrument rather than in a supplier policy the subcontractor can revise on its own.

Questions (3)

boolean

Is a record of the subcontractors underpinning each customer-facing service made available to customers?

This is the ICT supply chain behind the service, whether or not personal data is involved. A sub-processor list covering only parties that process personal data is a no unless it also reaches the rest of the chain.

multi

Which of the following does the subcontractor change process provide?

Advance notice of a material change to the affected customersA stated notice period during which a customer may objectImplementation held until the period closes or the customer approvesImplementation held while an objection is openFlow-down of the customer's audit access rights into the subcontractFlow-down of the monitoring, reporting, continuity and security terms the customer contract requiresRequirements on the subcontractor's personnel for training, certification and background verificationNone of the above

Answer on what the process does rather than on what a contract template offers. The third and fourth options differ: a change can be held until the notice period closes and still go ahead over an objection raised inside it.

select

What identifies each subcontractor in the record?

A legal entity identifier, the operating country, a contact point and the products and services it providesA legal entity identifier and the operating countryA legal entity name and the operating countryA legal entity name onlyA service category without naming the party

Options run from the most complete entry to the least. Answer on the record as published, not on what the internal supplier register holds.