Outsourced Execution, Retained Accountability: What Leadership Must Still See When a Vendor Is Already Inside
A vendor can be governed carefully at the moment it is admitted. What happens to that governance once the vendor is no longer a decision to be made, but a dependency the organization already relies on?
The Condition
A vendor admission decision occurs at a defined point. An organization evaluates a prospective vendor, weighs the risks, negotiates terms, and admits or declines the relationship. That decision – made carefully or carelessly – has a clear before and after. An embedded dependency is different. It is a continuing condition.
Once admitted, a vendor does not remain a choice under continuous evaluation; it becomes something the organization relies on – for a system, a workflow, a data process, a customer-facing function. The governance attention that was concentrated at the moment of admission does not automatically travel with the relationship as it deepens. A vendor examined rigorously on day one can become, by year three, an operational dependency no one is examining with the same attention – not because anyone decided to stop looking, but because the organization's attention naturally moves to the next decision while the dependency itself simply continues.
This creates a governance question distinct from vendor selection: for a dependency the organization has already formed, does leadership currently understand what it is relying on, and what sits outside its own direct control? This paper examines what institutional authorities – banking supervisors, EU financial regulators, and, in one instructive instance, the U.S. Congress – have said about accountability for outsourced execution, and what that same evidence reveals about the visibility gap that can open once a vendor is no longer a decision, but a dependency.
Retained Accountability, Established
The clearest and most direct evidence for this paper's central distinction comes from primary regulatory text, not from commentary about it.
In 2023, the Federal Reserve, the FDIC, and the OCC jointly issued interagency guidance governing how U.S. banking organizations manage third-party relationships. The guidance states plainly that a banking organization's use of third parties does not diminish its responsibility to meet applicable requirements to the same extent as if the activities were performed in-house. Within that supervisory domain, moving a function to a vendor does not remove the bank's own responsibility.
The European Union's Digital Operational Resilience Act states a comparable principle in binding statutory form. DORA provides that financial entities using ICT services remain fully responsible for compliance with, and discharge of, obligations under the regulation and applicable financial-services law. It goes further in one specific respect: even where compliance-verification tasks are outsourced, the financial entity remains fully responsible for that verification.
These are two different legal instruments, in two different jurisdictions, governing different but overlapping categories of institution. Neither should be read as establishing a universal cross-industry rule. But within their own domains, both are unambiguous on the same point: the organization's own responsibility does not simply move because execution moves.
What Moves Outward When Execution Does
If accountability stays, something else moves. When an organization hands a function to a vendor, it may gain efficiency, expertise, or scale – while giving up some degree of direct control over how the function is performed, direct supervision of the people and systems executing it, and direct knowledge of operational details that would previously have been visible because the work happened inside the organization's own walls.
This is not, by itself, a governance failure. Outsourcing exists because organizations cannot or should not perform every function internally, and the interagency guidance and DORA both treat vendor relationships as a normal, governable feature of doing business – not an inherently suspect one.
The governance question is narrower: once direct control, supervision, or knowledge has moved outward, and the relationship has moved from a decision under evaluation to a dependency in ongoing operation, is the resulting visibility gap something leadership can still see – or does it become part of the operational background because nothing currently prompts anyone to examine it?
The Distinction
An organization can outsource execution while retaining responsibility for the outcome within the regulatory domains examined here. But retaining accountability is different from retaining visibility into the conditions that produce the outcome. An organization can remain accountable for a dependency it currently has limited direct visibility into – not because it was told it could stop looking, but because visibility requires deliberate, ongoing attention that a one-time admission decision does not by itself provide.
This is the governance condition worth naming precisely: within these frameworks, accountability is retained by design. Visibility into an embedded dependency is not retained automatically. It requires ongoing attention to the dependency as it actually exists.
What Sits Beneath the Contract
The visibility gap described above is not hypothetical. Both the U.S. and EU frameworks explicitly anticipate that a single contracted vendor relationship can represent multiple layers of actual execution – subcontractors, and potentially further parties – that the contracting organization may not directly see.
The interagency guidance lists subcontracting among the factors a bank should consider when negotiating third-party contracts. DORA goes further, requiring contracts for ICT services supporting critical or important functions to address whether subcontracting is permitted and under what conditions, and requiring financial entities to assess how long or complex chains of subcontracting may affect their ability to monitor the function.
It is worth noting that the European Commission rejected the European Supervisory Authorities' first draft technical standard on subcontracting in January 2025, finding that it introduced requirements beyond what DORA itself had authorized. This does not mean subcontracting visibility was abandoned as a concern. It shows that even sophisticated supervisory bodies have had to calibrate how far visibility into a subcontracting chain should extend. That difficulty itself is useful context for organizations trying to understand what sits beneath a single vendor contract.
Contractual Simplicity, Operational Multiplicity
A single signed contract, with a single named counterparty, can represent multiple execution points the contracting organization never directly negotiates with and may never fully see. This is the condition DORA's subcontracting provisions are designed to address.
The practical implication is straightforward to state and harder to operationalize: the number of parties named in a contract is not a reliable measure of the number of parties involved in producing the outcome the contract governs.
Vendor Diversity, Dependency Diversity
A related but distinct condition concerns not depth – how many layers sit beneath one vendor – but breadth: how many nominally separate vendors ultimately rely on the same underlying infrastructure. DORA's concentration-risk provisions require financial entities to assess dependency on a small number of providers and on providers that are difficult or impossible to substitute.
This supports a distinction worth holding separately from subcontracting depth: an organization can have contractual diversity – many vendor names on many contracts – while having limited dependency diversity if those vendors ultimately rely on the same small set of underlying providers.
When One Dependency Fails Everywhere at Once
In February 2024, a ransomware attack against Change Healthcare – a subsidiary of UnitedHealth Group and one of the country's largest healthcare claims-processing clearinghouses – disrupted a system through which an enormous volume of U.S. healthcare claims activity moved. The disruption did not remain confined to Change Healthcare or UnitedHealth Group. It propagated to pharmacies, hospitals, health plans, revenue-cycle vendors, and other intermediaries whose operations depended on Change Healthcare's clearinghouse and pharmacy networks, with effects reaching organizations further downstream.
The evidence supports concentration and dependency propagation. It does not support a precise claim about how many contractual layers separated every affected organization from Change Healthcare, nor does it establish that affected organizations generally lacked a direct relationship with Change Healthcare. The point is narrower: a failure at one highly relied-upon dependency produced consequences across many organizations that relied on that same underlying condition, directly or indirectly.
The subsequent congressional hearings examined UnitedHealth Group's accountability for the outcome and raised concerns about concentration, redundancy, continuity, and the possibility of a single point of failure. These statements are congressional oversight and political accountability, not adjudicated legal findings. They do not establish that UnitedHealth breached a particular legal duty.
What the event illustrates, as a single example rather than proof of a universal rule, is a condition this paper helps make precise: a dependency can exist for years before failure reveals how many organizational consequences are tied to the same underlying point.
This is worth naming as Obraval's interpretive synthesis rather than an institutionally established doctrine: where many organizations route consequential activity through the same underlying dependency, an existing weakness in that dependency does not need to be recreated to be felt repeatedly. It can be expressed once at the point of failure and experienced across many relying organizations. Scale, in this sense, does not necessarily create a new fracture type – it can multiply the number of places an existing fracture is felt.
Where the Evidence Stops
It would overstate what has been examined here to draw several conclusions this evidence does not support.
This is not evidence that outsourcing execution generally increases organizational risk, or that vendor dependencies should be minimized as a matter of course. The regulatory frameworks examined here treat third-party relationships as a normal, governable feature of operating a business – not as something to be avoided.
This is not evidence that any specific vendor-governance practice, dependency-mapping exercise, or documentation standard would have prevented the Change Healthcare disruption or any comparable event. That event is used illustratively, not as proof of a causal mechanism.
This is not evidence that U.S. banking guidance or EU financial regulation creates a general legal standard applicable to organizations outside their respective regulatory scopes. The retained-accountability principle is directly established within U.S. banking supervision and EU financial services; its extension elsewhere here is offered as an observation about a governance condition, not as a claim of legal obligation.
And one hypothesis this research specifically tested was not incorporated as a finding: the idea that governance review of a vendor relationship typically occurs too late, after commercial commitment has already formed. The research gathered for this paper did not provide sufficient institutional evidence to establish that as a demonstrated condition. It remains a plausible question for a different inquiry.
The Obraval Interpretation
Retained accountability, as the regulatory frameworks examined here establish it, is a legal and supervisory condition within their respective domains. Underneath that condition sits a separate visibility question: accountability that remains with an organization is not the same thing as visibility that remains with it.
An organization can remain responsible for an outsourced activity while allowing its understanding of the dependency to erode because nothing in the ordinary course of business prompts leadership to look again at a relationship that was carefully examined once and has since become operational background.
The Executive Implication
The question this paper leaves for leadership is not whether a given vendor should have been admitted, renewed, or continued. That is a decision made at a defined point and evaluated against the conditions known at that point.
The question here is different, and it applies to relationships already in place, already relied upon, already embedded in how the organization operates: for this dependency, right now, does leadership know what the organization is relying on, what sits beneath the visible contract, what remains outside direct control, and who inside the organization still owns the consequence if the dependency fails?
Close
A vendor admission decision occurs at a defined point. A vendor dependency continues, whether or not anyone is still looking at it. Within the regulatory frameworks examined here, accountability continues with it by design.
The open question is not whether responsibility continues inside those frameworks. The question is whether the organization's own understanding of the dependency continues with the same clarity.
That is the visibility question this paper leaves open deliberately: not whether the organization remains accountable, but whether leadership can still see, with useful precision, what the organization is relying on and what it continues to carry.
Sources informing this whitepaper.
Interagency Guidance on Third-Party Relationships (2023).
Used for retained-responsibility principles, subcontracting considerations, and risk-based third-party oversight within U.S. banking supervision.
Digital Operational Resilience Act, including Articles 6, 28, 29, and 30.
Used for retained responsibility, concentration, substitutability, and subcontracting-chain visibility within EU financial services.
2025 technical-standard calibration concerning subcontracting under DORA.
Used as supporting context for the institutional difficulty of defining how far subcontracting-chain visibility should extend.
2024 hearing statements and testimony concerning operational disruption, concentration, continuity, and accountability.
Used illustratively for concentration and dependency propagation only; not as an adjudicated legal finding.