Compose OUTSOURICING LEGAL CONTRACT between a UK Firm and India Based I.T. Firm
Budget: $10 – $30 USD
**Needing a Qualified Lawyer – 24-Hour Turnaround**
This task must be completed within 24 hours.
It’s a straightforward project for any qualified UK lawyer familiar with FCA-regulated outsourcing. About 75% of the content can be taken from standard templates you already have. The remaining 25% just needs careful regulatory alignment and quality drafting.
You will not be paid if the deliverable is not of professional, FCA-ready quality.
**Project:** FCA-Compliant IT Outsourcing Agreement for UK Authorised Payment Institution (API)
**About Us:**
We are a UK payments firm applying for FCA authorisation as an Authorised Payment Institution under the Payment Services Regulations 2017.
We will outsource some critical and important functions to Asia-based suppliers, so the contracts must meet UK FCA and EBA outsourcing standards.
**Goal:**
Produce a plain-English, FCA-acceptable Master IT Outsourcing Agreement under English law that can be submitted in our FCA authorisation pack.
Preferably one master agreement with two schedules. If you believe separate agreements are safer, explain why and provide both.
**Deliverables:**
1. Master IT Outsourcing Agreement (UK law) covering FCA SYSC 8, EBA Outsourcing Guidelines (2019), PSRs 2017, and Operational Resilience (PS21/3).
2. Schedule A – Supplier 1 (Technology & Platform): IT infrastructure, cybersecurity, and transaction platform management.
3. Schedule B – Supplier 2 (Customer Support / BPO): multichannel support, SLAs, complaints, QA, staffing, reporting.
4. Data Processing Agreement (UK GDPR compliant) including IDTA or SCCs + UK Addendum, plus short DTIA template.
5. Outsourcing Register Entry template for each supplier (per FCA expectations).
6. Compliance Mapping Note (1–2 pages) showing where the contract meets SYSC 8, EBA, PSRs, and PS21/3.
7. Files to be provided in Word format (tracked-changes and clean signature versions).
---
**Schedule A – Supplier 1 (Technology & Platform)**
Include hosting and infrastructure, network and security controls, backups, monitoring, OS/database management, CI/CD, change management, transaction routing and reconciliation, fraud/AML integration, dispute handling, logging and data retention, ISO 27001/SOC 2 alignment, encryption, access controls, vulnerability management, incident response (24/7 with SLAs), business continuity and DR testing, service levels and reporting, data location and transfers, governance and review processes.
---
**Schedule B – Supplier 2 (Customer Support / BPO)**
Include support channels (phone, email, chat, in-app), hours, escalation, SLAs for response and resolution, QA scoring, CSAT/NPS, FCA DISP-compliant complaints handling, record-keeping, training and data-protection controls, call recording, secure agent setup, breach notification, data deletion, weekly MI, monthly reporting, staffing and vetting requirements.
---
**Mandatory Clauses in the Master Agreement:**
* Regulatory accountability remains with us.
* Full audit and access rights for FCA, PRA, and Bank of England, including sub-contractors and overseas sites.
* Sub-outsourcing only with prior written consent and full flow-down of obligations.
* Operational resilience mapping, testing, and sharing of results.
* Change control requiring approval for material changes.
* Data protection roles and responsibilities, lawful basis, retention and deletion, SCCs/IDTA + DTIA, rapid breach notification.
* Information security aligned with ISO 27001 or equivalent; evidence on request.
* Transparent pricing, SLA service credits, and chronic failure remedies.
* Adequate cyber and professional indemnity insurance.
* Liability capped overall but uncapped for data breach, IP infringement, fraud, wilful misconduct, or fines caused by supplier breach.
* Termination and exit rights for cause, regulatory direction, or chronic KPI failure; cooperation, data return, and step-in rights.
* Governing law: England & Wales.
* Standard notices and confidentiality clauses.
* Supplier must provide data for the FCA outsourcing register.
This task must be completed within 24 hours.
It’s a straightforward project for any qualified UK lawyer familiar with FCA-regulated outsourcing. About 75% of the content can be taken from standard templates you already have. The remaining 25% just needs careful regulatory alignment and quality drafting.
You will not be paid if the deliverable is not of professional, FCA-ready quality.
**Project:** FCA-Compliant IT Outsourcing Agreement for UK Authorised Payment Institution (API)
**About Us:**
We are a UK payments firm applying for FCA authorisation as an Authorised Payment Institution under the Payment Services Regulations 2017.
We will outsource some critical and important functions to Asia-based suppliers, so the contracts must meet UK FCA and EBA outsourcing standards.
**Goal:**
Produce a plain-English, FCA-acceptable Master IT Outsourcing Agreement under English law that can be submitted in our FCA authorisation pack.
Preferably one master agreement with two schedules. If you believe separate agreements are safer, explain why and provide both.
**Deliverables:**
1. Master IT Outsourcing Agreement (UK law) covering FCA SYSC 8, EBA Outsourcing Guidelines (2019), PSRs 2017, and Operational Resilience (PS21/3).
2. Schedule A – Supplier 1 (Technology & Platform): IT infrastructure, cybersecurity, and transaction platform management.
3. Schedule B – Supplier 2 (Customer Support / BPO): multichannel support, SLAs, complaints, QA, staffing, reporting.
4. Data Processing Agreement (UK GDPR compliant) including IDTA or SCCs + UK Addendum, plus short DTIA template.
5. Outsourcing Register Entry template for each supplier (per FCA expectations).
6. Compliance Mapping Note (1–2 pages) showing where the contract meets SYSC 8, EBA, PSRs, and PS21/3.
7. Files to be provided in Word format (tracked-changes and clean signature versions).
---
**Schedule A – Supplier 1 (Technology & Platform)**
Include hosting and infrastructure, network and security controls, backups, monitoring, OS/database management, CI/CD, change management, transaction routing and reconciliation, fraud/AML integration, dispute handling, logging and data retention, ISO 27001/SOC 2 alignment, encryption, access controls, vulnerability management, incident response (24/7 with SLAs), business continuity and DR testing, service levels and reporting, data location and transfers, governance and review processes.
---
**Schedule B – Supplier 2 (Customer Support / BPO)**
Include support channels (phone, email, chat, in-app), hours, escalation, SLAs for response and resolution, QA scoring, CSAT/NPS, FCA DISP-compliant complaints handling, record-keeping, training and data-protection controls, call recording, secure agent setup, breach notification, data deletion, weekly MI, monthly reporting, staffing and vetting requirements.
---
**Mandatory Clauses in the Master Agreement:**
* Regulatory accountability remains with us.
* Full audit and access rights for FCA, PRA, and Bank of England, including sub-contractors and overseas sites.
* Sub-outsourcing only with prior written consent and full flow-down of obligations.
* Operational resilience mapping, testing, and sharing of results.
* Change control requiring approval for material changes.
* Data protection roles and responsibilities, lawful basis, retention and deletion, SCCs/IDTA + DTIA, rapid breach notification.
* Information security aligned with ISO 27001 or equivalent; evidence on request.
* Transparent pricing, SLA service credits, and chronic failure remedies.
* Adequate cyber and professional indemnity insurance.
* Liability capped overall but uncapped for data breach, IP infringement, fraud, wilful misconduct, or fines caused by supplier breach.
* Termination and exit rights for cause, regulatory direction, or chronic KPI failure; cooperation, data return, and step-in rights.
* Governing law: England & Wales.
* Standard notices and confidentiality clauses.
* Supplier must provide data for the FCA outsourcing register.