Exact requirement
Each detail page names the article, section, scope and current status.
SOFTWARE ESCROW & RECOVERABILITY REGULATIONS
Financial regulators are converging on the same expectation: critical third-party software must remain recoverable when the provider fails. Castler maps software escrow, current custody and signed recovery evidence to the exact framework that governs your institution.
GLOBAL COVERAGE
Select a jurisdiction to open the regulation, deadline and evidence mapping behind it.

REGULATORY EVIDENCE NETWORK
Live jurisdiction index
09
COVERED
THE GLOBAL REGULATORY MANDATE
Across financial regulation, cyber-resilience rules and global assurance standards, the direction is converging: critical third-party software must remain current, testable and recoverable when its provider fails.
17
MANDATES
9
JURISDICTIONS
17
Regulation and standard mappings
9
Regions and framework groups
Per release
Current recoverability evidence
Signed
Board-examinable artefact
THE STRUCTURAL SHIFT
Software escrow regulation began with a custody problem: a regulated institution depended on software it did not own and needed continuing access if the vendor failed. The contract and source-code deposit created a legal path to those materials. Modern frameworks now examine whether the institution can actually maintain the critical function through disruption.
That change is visible across RBI IT Directions §12(f), RBI PSO §17(c), SEBI CSCRF and IRDAI’s Information and Cyber Security Guidelines in India; DORA Articles 9, 28 and 30 in Europe; PRA SS2/21 and the UK operational-resilience regime; MAS technology-risk expectations; and APRA CPS 230. The language differs, but the operational question is consistent: is the third-party dependency understood, current, testable and recoverable?
Castler separates the two layers. Cloud Custody establishes software escrow, current deposit capture, agreement management and an audit trail from vendor onboarding. Software Recoverability independently rebuilds, deploys and replicates the application, then seals the evidence as a signed Proof of Recovery.
Each detail page names the article, section, scope and current status.
Every regulatory expectation is paired with a specific custody or Proof of Recovery artefact.
The control begins when the vendor contract starts, not when an audit finding appears.
THE DIRECTORY
Each page explains the issuing body, requirement reference, entity scope, compliance timeline, consequences, Castler mapping, frequently asked questions, and related regulations. The summaries support orientation and should be read alongside official texts and professional advice.
Source-code escrow, current deposits, third-party cyber resilience, and recovery evidence across banking, payments, capital markets, and insurance.
PRA and FCA expectations require credible stressed exit, material-provider continuity, impact tolerances and demonstrable operational resilience.
Third-party technology, continuity and recoverability requirements for the jurisdiction or standard.
APRA CPS 230 requires operational-risk management, material-service-provider controls and continuity of critical operations within tolerance.
MAS technology-risk guidance covers outsourced software, third-party governance, secure delivery and tested IT continuity.
Third-party technology, continuity and recoverability requirements for the jurisdiction or standard.
Third-party technology, continuity and recoverability requirements for the jurisdiction or standard.
REGULATORY MAPPING
Bring your perimeter. We’ll map the current custody, critical applications, article language and signed recovery evidence your institution needs.
Book a 15-min briefing