Authors
Executive summary
Sovereignty has moved from a niche policy concept to one of the defining technology and economic policy issues of the moment. Increasing geopolitical tensions, concerns regarding strategic dependence on foreign technology providers, and initiatives such as the EU's proposed Cloud and AI Development Act (CADA)[1] have brought renewed scrutiny to the resilience and control of critical digital infrastructure. While much of this debate has emerged outside financial services, it is increasingly influencing discussions around technology risk, digital resilience and economic security.
For financial institutions, sovereignty is not yet a standalone regulatory requirement. However, many of the themes underpinning the debate are already visible in regulatory initiatives focused on operational resilience, concentration risk and critical third-party dependencies, including the Digital Operational Resilience Act (DORA)[2] and the UK's Critical Third Party regime[3]. As regulators, policymakers and financial institutions consider the implications of geopolitical disruption, supply-chain dependencies and reliance on global technology providers, sovereignty considerations are beginning to enter the regulatory conversation.
Sovereignty should not be assessed primarily through the nationality, ownership or geographic location of technology providers, a theme also explored in our recent paper Balancing Sovereignty and Innovation: A Proportionate Path for the Proposed EU Cloud and AI Development Act. Instead, it should be approached as an operational resilience issue. The key question is whether a financial institution can maintain effective control, continuity and resilience in the face of legal, geopolitical, operational or supply-chain disruptions. In practice, this requires distinguishing between control, operational autonomy and substitutability.
Financial institutions should begin developing sovereignty strategies now, not necessarily to meet a specific regulatory obligation, but to strengthen resilience, better understand critical dependencies, and prepare for the potential evolution of regulatory expectations. Sovereignty is ultimately best understood not as a question of provider nationality, but of preparedness, operational autonomy and risk management.
Sovereignty risk: the next evolution of operational resilience
Financial institutions have spent years strengthening their approach to cyber risk, outsourcing, operational resilience and third-party risk management. Sovereignty risk builds on these disciplines.
Sovereignty risk in the financial services setting, is the risk that geopolitical, legal, regulatory or jurisdictional developments affecting an organisation, service provider and their supply chains which may impact the continuity, integrity or controllability of technology services and/or data stored within them.
Examples might include:
- Cross-border legal conflicts;
- Extraterritorial government actions, especially related to data access requests;
- Trade restrictions or export controls;
- Technology supply chain disruptions;
- Geopolitical fragmentation; or
- Dependencies that reduce an institution's ability to respond to disruption.
Avoiding a false choice
One of the problems with the current sovereignty debate is the emergence of a false choice between:
- Global technology providers; and
- Local alternatives.
For financial institutions (and their regulators), this is not a realistic or desirable choice.
Modern banking depends upon access to the most advanced technologies, global innovation ecosystems and highly resilient infrastructure operating at significant scale. A siloed approach to technology procurement risks creating inefficiencies, reducing innovation and limiting access to best-in-class capabilities – leading to the sovereignty paradox, whereby resilience may actually be compromised. The objective should therefore not be to eliminate global dependencies. Nor should it be to pursue a theoretical zero-risk sovereignty model.
Instead, institutions should seek to:
- Understand sovereign dependencies, especially in relation to their data estate and the systems in which their data is stored;
- Assess their materiality and determine risk appetite;
- Identify appropriate mitigations steps;
- Ensure resilience frameworks address plausible disruption scenarios; and
- Ensure the financial services community, including regulators and technology service providers are working collaboratively to achieve a resilient outcome.
From risk elimination to risk management – Four practical steps
No financial institution can eliminate all risk, including sovereignty-related risk. Just as firms cannot eliminate cyber risk, operational risk or concentration risk, they cannot eliminate every geopolitical or jurisdictional dependency within complex technology ecosystems. The goal should therefore be effective assessment and the putting in place of ongoing governance measures, essentially revisiting established playbooks of risk management and updating them to account for sovereignty risk. We see this coming to life via the following four steps:
1. Assess critical dependencies
Institutions should identify critical business services, right across their entire organisation, which depend on external technology ecosystems. This mapping (including its depth) should extend beyond the direct provider to the wider service chain, including subcontractors, identity and security services and other common dependencies that may create hidden concentration risk.
This mapping should assess:
- Cloud platforms;
- Identity services;
- Security services;
- Data platforms and associated institution-wide data governance;
- AI systems; and
- Key supply chain dependencies.
Importantly, this stage should identify any technical updates and improvements that may be required to critical business services, and ensure teams are architecting or configuring services to achieve maximum and ongoing resilience.
2. Review contractual protections – Sovereignty as a procurement discipline
An important and often overlooked step is to undertake a detailed review of material supplier contracts. Many financial institutions entered into cloud arrangements several years ago. Since then, cloud providers have significantly enhanced their contractual commitments, operational controls and sovereign-by-design offerings.
Institutions should therefore assess:
- Existing resilience commitments;
- Audit and transparency provisions;
- Data control arrangements;
- Jurisdictional protections;
- Exit provisions;
- Service continuity commitments; and
- Sovereign cloud capabilities now available from providers.
To be most effective, this review must be undertaken by teams that have a clear view across the entire institution of all accountabilities, stakeholders and dependencies. The review may identify opportunities to update contractual arrangements to reflect the latest sovereign-by-design capabilities and resilience features offered by providers. In other cases, consideration will need to be given to the fact that for many cloud-based offerings, updates, especially in relation to security, are constantly evolving. For many institutions, contractual remediation may represent one of the most practical and cost-effective sovereignty mitigation steps available.
3. Integrate sovereignty into design and resilience testing
Leveraging insights and learnings from the assessment of critical dependencies, sovereignty scenarios should be incorporated into operational and other existing risk and resilience frameworks, and teams should explore what existing (and/or new) mitigation steps may be required.
Example scenarios may include:
- Loss of cross-border support functions;
- Geopolitical restrictions affecting service delivery;
- Third-party legal intervention scenarios;
- Supply chain disruptions; and
- Regional technology fragmentation.
The purpose is not necessarily to test whether a firm could theoretically exit a provider overnight, but whether it could (for example) continue operating in a degraded but tolerable state, with clear decision rights, access to critical data, manual workarounds and communications plans.
4. Establish on-going Governance and risk ownership
Sovereignty themes often sit across multiple functions including:
- Technology;
- Risk;
- Procurement;
- Legal;
- Compliance;
- Operational resilience; and
- Public policy.
As a result, organisations frequently assess elements of sovereignty without maintaining a consolidated view. Establishing clear governance and ownership protocols can help ensure that sovereignty risks are assessed and managed consistently and proportionately. Further, given the growing regulatory, operational resilience and geopolitical dimensions of sovereignty, this is increasingly a board-level issue. Boards should receive regular briefings on the institution's sovereignty posture, key dependencies, emerging regulatory developments and associated business risks, enabling effective oversight and informed strategic decision-making.
Governance should also make clear who can accept sovereignty-related risk, who funds remediation, and what events, such as material provider changes, new subcontracting arrangements, regulatory developments or geopolitical escalation, should trigger reassessment.
Call to action: Developing a sovereignty strategy
The emergence of the UK's Critical Third-Party regime and the EU's evolving oversight frameworks should not be viewed as a signal to retreat from global technology ecosystems. Rather, they reflect growing recognition that these providers form part of the critical globally connected infrastructure of modern financial services.
The challenge for financial institutions is therefore not to eliminate sovereign risk. The challenge is to understand it and to put in place arrangements (that are not cumbersome or overly resource-heavy) to mitigate such risks from becoming a reality.
Organisations should ask:
- Have we identified our critical sovereign dependencies?
- Have we tested whether we can continue operating in a degraded but tolerable state during disruption?
- Have we assessed whether those dependencies align with our risk appetite?
- Have we reviewed whether current contractual arrangements adequately address sovereignty-related concerns?
- Have we evaluated relevant sovereign-by-design capabilities now offered by providers and updated our contracts?
- Have we incorporated sovereignty scenarios into our resilience testing programme?
- Can we explain our approach to regulators, Boards and stakeholders?
Institutions that can answer these questions confidently will be better positioned to navigate an increasingly complex geopolitical, regulatory and technology landscape.
How CMS can help
CMS' Technology Policy Advisory Practice supports financial institutions through:
- Sovereignty risk assessments;
- Contractual and outsourcing reviews;
- Sovereign cloud and AI readiness assessments and playbooks;
- Board and executive briefings and best practices;
- Operational resilience enhancement;
- Scenario design and tabletop exercises;
- Regulatory horizon scanning; and
- Engagement with regulators and policymakers.
Our objective is to help institutions develop a structured, evidence-based understanding of sovereign dependencies and establish proportionate governance and mitigation strategies that support resilience while preserving access to the world's leading technology platforms.
[1] Cloud and AI Development Act | Shaping Europe’s digital future
[2] Digital Operational Resilience Act (DORA)
[3] UK financial system strengthened with new safeguards for major technology providers - GOV.UK