concept

Sector Cloud Rules

Sector-specific rules governing cloud use — outsourcing notification, audit rights, concentration risk and exit — which shape provider and service choices.

regulationcloudoutsourcingconcentrationaudit-rights

Definition

Regulated sectors treat cloud adoption as outsourcing a material function, and impose obligations that constrain how it is done.

The obligations that recur

Notification and approval. Regulators may need to be told before a material workload moves, sometimes with a waiting period. This is a lead time in the delivery plan, not a formality.

Audit and access rights. Contracts must permit the organisation and its regulator to audit the provider. Major providers offer standard clauses; smaller vendors frequently cannot, which constrains the supplier set.

Concentration risk. Both the organisation's dependence on one provider and the sector's collective dependence. This is an increasing focus and is the main driver behind multi-cloud requirements in regulated sectors — a resilience argument rather than a commercial one.

Exit plans. A credible, tested plan for moving off a provider within a defined period. "We could rewrite it" is not credible.

Sub-outsourcing transparency. Knowing who the provider depends on, since their concentration is yours.

Data location and access, including which personnel in which jurisdictions can reach the data.

The architectural consequences

Exit obligations favour portable choices. A workload on managed Kubernetes with a standard database engine is far easier to move than one built on provider-specific serverless and proprietary managed services. That does not forbid the latter — it means the choice must be justified against the exit requirement for anything material.

Concentration requirements may mandate multi-provider capability for critical services. This is expensive and complex, and the pragmatic response is usually to make the critical path portable rather than the whole estate.

Audit rights favour large providers with established compliance programmes, which narrows supplier choice and is worth knowing before an evaluation.

Failure scenarios

  • Provider-specific services in a critical path with an exit obligation, discovered at review.
  • Exit plan written and never tested, so its feasibility is unknown.
  • Sub-outsourcing unmapped, so concentration is understated.
  • Notification lead time missed, delaying a launch.
  • A small vendor selected who cannot meet audit-rights requirements.

Interview question

"An exit plan must be credible and tested. What does that mean for how you build?"