The Bank of Mauritius (BoM) is consulting on revisions to the guideline for banks licensed to carry on private banking business, with the consultation period ending on September 15, 2021. The guideline sets out the regulatory and supervisory framework applicable to banks conducting private banking business. Private banking business is defined in the Banking Act 2004 as “the business of offering banking and financial services and products to high-net-worth customers including, but not limited to, an all-inclusive money-management relationship.” BoM also published a draft guideline on the use of cloud services by financial institutions, with the consultation period ending on September 08, 2021.
The guideline on the use of cloud services lays down the minimum requirements that shall be applicable to the use of cloud services provided by third parties for material services. Where specified in the guideline, these minimum requirements shall also apply to services that involve customer information. Financial institutions are expected to follow a risk-based approach in respect of cloud services. The level of governance to be applied, the information security requirements, the types of controls to be deployed, and the level of the initial and ongoing due diligence and assurance to be performed shall be commensurate with the criticality of the services. The guideline stipulates that financial institutions that use or intend to use cloud services shall have a board-approved
cloud strategy. Post finalization, a transitional period of six months shall be granted to all financial institutions to ensure compliance with the requirements of the guideline. In addition to this guideline, the financial institutions should also comply with the Guideline on Outsourcing by Financial Institutions in the event an outsourced activity avails of the use of cloud services.
Comment Due Date: September 15, 2021(Private Banking)/September 08, 2021 (Cloud Services)
Keywords: Middle East and Africa, Mauritius, Banking, Cloud Services, Private Banking, Regtech, Cloud Computing Arrangement, Outsourcing Arrangements, SAAS, PAAS, BOM
Previous ArticleSBV Proposes to Develop Law on Bad Debt Resolution
The Prudential Regulation Authority (PRA) published the final policy statement PS21/21 on the leverage ratio framework in the UK. PS21/21, which sets out the final policy of both the Financial Policy Committee (FPC) and PRA
The Consumer Financial Protection Bureau (CFPB) proposed to amend Regulation B to implement changes to the Equal Credit Opportunity Act (ECOA) under Section 1071 of the Dodd-Frank Act.
The Prudential Regulation Authority (PRA) decided to maintain, at the 2019 levels, the buffer rates for the Other Systemically Important Institutions (O-SII) for another year, with no new rates to be set until December 2023.
The Financial Stability Board (FSB) published a progress report on implementation of its high-level recommendations for the regulation, supervision, and oversight of global stablecoin arrangements.
In a letter to the authorized deposit taking institutions, the Australian Prudential Regulation Authority (APRA) announced an increase in the minimum interest rate buffer it expects banks to use when assessing the serviceability of home loan applications.
The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) are consulting on the preliminary guidance that clarifies that stablecoin arrangements should observe international standards for payment, clearing, and settlement systems.
The European Banking Authority (EBA) and the European Insurance and Occupational Pensions Authority (EIOPA) have set out their respective work priorities for 2022.
The Malta Financial Services Authority (MFSA) updated the guidelines on supervisory reporting requirements under the reporting framework 3.0, in addition to the reporting module on leverage under the common reporting (COREP) framework.
The European Commission (EC) published the Implementing Decision 2021/1753 on the equivalence of supervisory and regulatory requirements of certain third countries and territories for the purposes of the treatment of exposures, in accordance with the Capital Requirements Regulation or CRR (575/2013).
EC published the Implementing Regulation 2021/1751, which lays down implementing technical standards on uniform formats and templates for notification of determination of the impracticability of including contractual recognition of write-down and conversion powers.