ESCROWSURE’s Anthony Watson calls attention to vendor dependency risks

post-title

A visit to Nairobi for the CITO EA launch by software escrow provider ESCROWSURE has brought renewed attention to a concern raised by technology leaders across East Africa: how to maintain business continuity when critical software vendors fail.

When Anthony Watson, CEO  of ESCROWSURE, touched down in Nairobi for the CITO East Africa launch in December last year, he was welcomed by the vibrant conversations East African chief information officers were having around artificial intelligence, cloud migration, and automation.

Because ESCROWSURE is a valued partner of CIO South Africa, Anthony gladly accepted the invitation from Executive Communities managing director Joël Roerig. He joined the historic launch of CITO East Africa, a unique executive community platform for technology leaders across Kenya, Rwanda, Tanzania, and Uganda.

As he engaged with senior technology leaders across the region, a recurring concern quickly emerged regarding how organisations can maintain business continuity when critical software vendors fail. According to Anthony, many organisations are accelerating digital transformation without putting in place the governance structures needed to manage vendor dependency.

“Boards are approving mission critical platforms that run core operational processes, yet in many cases there is no structured mechanism to ensure continuity if the vendor becomes insolvent, is acquired by a competitor, withdraws support, or experiences operational disruption,” Anthony said.

He noted that in sectors such as financial services and healthcare, where core systems underpin payments, policy administration, claims processing, and regulatory reporting, the failure of a software provider can have immediate consequences beyond IT operations. 

“Prolonged software failure is not simply an IT issue. It creates immediate operational exposure, potential regulatory scrutiny, reputational damage, and direct accountability at board level," he said.

Anthony observed that the discussion showed that many organisations still rely on contractual safeguards within supplier agreements, such as service level commitments and termination clauses, as their primary form of protection. However, he noted that contractual rights do not automatically provide access to source code, development environments, or the technical documentation needed to rebuild or maintain a system.

“Without access to these components, organisations may find themselves unable to operate critical systems if a vendor is no longer able to provide support,” Anthony noted.

He added that the conversations reflect a broader shift in how organisations are approaching technology risk, as digital systems become central to business operations and regulators increase their focus on operational resilience and third-party risk management.

"Organisations that cannot demonstrate credible continuity arrangements for mission critical systems may face growing audit pressure," Anthony said.

To mitigate this risk, Anthony argues that organisations must ensure they can access the technical assets required to maintain, update or rebuild systems under defined conditions, moving beyond simply relying on source code to establishing legally enforceable and technically validated continuity frameworks.

“As organisations deepen their reliance on third party platforms, vendor continuity is increasingly being treated as a governance issue. Vendor continuity risk is becoming a strategic issue requiring board level attention," he said.

 

Related articles

Tech leaders encourage smart AI adoption in business 

Artificial intelligence is rapidly entering business conversations, but fast adoption does not automatically translate into better decisions or stronger results. At the CIO of the Future Summit in Tanzania, Rohit Thaker, CTO of TEAGTL, Godwin Mbekelu, head of IT at Sportpesa and Amiri Sultani Mziray, head of ICT at I&M Bank Tanzania discussed how organisations can effectively adopt AI as a strategic enabler of business.

Reliance Insurance IT head Imani Mwanri calls for cross border data regulations

In recent years, East African countries have made significant strides in efforts towards data protection. However, Reliance Insurance head of IT, Imani Mwanri, challenges countries within the region to also develop cross-border data regulations with growing need for data exchange between countries.

Yas Tanzania’s IT director Victor Mtefu’s system migration strategy

At the August CIO of the Future Summit in Tanzania, Yas Tanzania IT director Victor Mtefu narrated how he navigated the high-stakes migration from legacy systems during the telco’s rebrand from Tigo. He also shared why revamping core tech relies far more on strategy and governance than on the technology  alone.

AI still needs a human touch, says Reliance Insurance IT head

At the CIO of the Future Summit in Dar es Salaam, tech leaders discussed AI's impact on daily operations. Among the panelists was Imani Mwanri, head of IT at Reliance Insurance, who urged tech leaders to embrace AI while warning against abandoning human oversight. 

Mulwana CTO Robert Jenkins says AI's real risk is missing regulations

Mulwana CIO, Robert Jenkins Sibbechai, believes the biggest gap in how organisations use AI isn't the technology itself but the absence of any rules governing what it's allowed to do with the data it's fed. He explains why this complicates cybersecurity and how a decade of oversharing on social media set the stage for it.

Build AI around local priorities, says IALE institute CEO Dr Allen Mutono

At the CIO of the Future Summit held at the Dar es Salaam Serena on 11 September, Dr Allen Mutono delivered a keynote address that challenged IT leaders to think carefully about how AI is deployed in African organisations. He also urged CIOs to equip their teams for an AI-enabled workplace while keeping human judgement at the centre.

Top