Featured Product

    FCA Reviews Technology Change Management in Financial Services Sector

    February 05, 2021

    FCA published the findings from a review that looked at how financial firms manage technology change, the impact of change failures, and the practices utilized in the industry to help reduce the impact of incidents resulting from change management. While there is no single approach, process, or control that improves change success rates, the analysis found that stronger governance, day-to-day risk management, increased automation, and more robust testing and planning can contribute to successful change activity and less disruption.

    Based on the review, FCA found that firms with higher change success rates had the following common characteristics:

    • Firms with well-established governance arrangements have a higher change success rate. There was a positive correlation between the longevity of governance arrangements and higher change success rates in the sampled firms. The data showed that robust governance can help reduce the number and impact of operational incidents resulting from change.
    • Relying on high levels of legacy technology is linked to more failed and emergency changes. FCA found that firms with a lower proportion of legacy infrastructure and applications had a higher change success rate. Firms with a lower proportion of legacy technology also had a lower proportion of changes being deployed as emergencies and had a higher chance of those emergency changes being successfully deployed.
    • Firms that allocated a higher proportion of their technology budget to change activities experienced fewer change related incidents. Firms that had the lowest proportion of changes resulting in an incident dedicated between 50% and 75% of their information technology budget to these change activities.
    • Frequent releases and agile delivery can help firms to reduce the likelihood and impact of change related incidents. FCA found that firms that deployed smaller, more frequent releases had higher change success rates than those with longer release cycles. Firms that made effective use of agile delivery methodologies were also less likely to experience a change incident.
    • Effective risk management is an important component of effective change management capabilities. Firms that experienced less incidents due to failed changes mitigated the risk of technology change by leveraging a wide range of technical and business knowledge to ensure that potential impacts were well understood. 

    In addition, FCA identified the following areas that could lead to increased operational disruption when carrying out change activity:

    • Most firms do not have complete visibility of third-party changes. According to firms’ incident reporting, in 2019, over 20% of incidents at third-parties were caused by change. Workshop attendees suggested that third-party contracts could be better utilized to provide greater clarity on how changes are communicated and on the potential impact to the information technology estate of a client firm.
    • Firms’ change management processes are heavily reliant on manual review and actions. Repeatability and consistency throughout the lifecycle of a change and its deployment could help reduce the burden of assurance activity and could also allow for a higher degree of confidence when implementing technology change.
    • Legacy technology impacts firms’ ability to implement new technologies and innovative approaches. Firms that classified a higher proportion of their technology estate as legacy had lower adoption rates for DevOps, micro-architecture, and public cloud, which could affect the ability of these to benefit from innovative approaches.

     

    Related Links

    Keywords: Europe, UK, Banking, Securities, Technology Risk, Governance, Fintech, Change Management, Operational Risk, Third-Party Arrangements, Cloud Computing, Outsourcing Arrangements, FCA

    Related Articles
    News

    PRA and FPC Finalize Changes to Leverage Ratio Framework in UK

    The Prudential Regulation Authority (PRA) published the final policy statement PS21/21 on the leverage ratio framework in the UK. PS21/21, which sets out the final policy of both the Financial Policy Committee (FPC) and PRA

    October 08, 2021 WebPage Regulatory News
    News

    CFPB Proposes Rule on Small Business Lending Data Collection

    The Consumer Financial Protection Bureau (CFPB) proposed to amend Regulation B to implement changes to the Equal Credit Opportunity Act (ECOA) under Section 1071 of the Dodd-Frank Act.

    October 08, 2021 WebPage Regulatory News
    News

    PRA Decides to Maintain O-SII Buffers for Another Year

    The Prudential Regulation Authority (PRA) decided to maintain, at the 2019 levels, the buffer rates for the Other Systemically Important Institutions (O-SII) for another year, with no new rates to be set until December 2023.

    October 08, 2021 WebPage Regulatory News
    News

    FSB Report Assesses Implementation of Recommendations on Stablecoins

    The Financial Stability Board (FSB) published a progress report on implementation of its high-level recommendations for the regulation, supervision, and oversight of global stablecoin arrangements.

    October 07, 2021 WebPage Regulatory News
    News

    APRA Updates Loan Serviceability Expectations for Home Lending

    In a letter to the authorized deposit taking institutions, the Australian Prudential Regulation Authority (APRA) announced an increase in the minimum interest rate buffer it expects banks to use when assessing the serviceability of home loan applications.

    October 06, 2021 WebPage Regulatory News
    News

    CPMI and IOSCO Consult on Guidance on Stablecoin Arrangements

    The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) are consulting on the preliminary guidance that clarifies that stablecoin arrangements should observe international standards for payment, clearing, and settlement systems.

    October 06, 2021 WebPage Regulatory News
    News

    EBA and EIOPA Set Out Work Priorities for 2022

    The European Banking Authority (EBA) and the European Insurance and Occupational Pensions Authority (EIOPA) have set out their respective work priorities for 2022.

    October 05, 2021 WebPage Regulatory News
    News

    MFSA Issues Reporting Updates and Guidance for Banks

    The Malta Financial Services Authority (MFSA) updated the guidelines on supervisory reporting requirements under the reporting framework 3.0, in addition to the reporting module on leverage under the common reporting (COREP) framework.

    October 05, 2021 WebPage Regulatory News
    News

    EC Publishes Decision on List of Equivalent Third Countries Under CRR

    The European Commission (EC) published the Implementing Decision 2021/1753 on the equivalence of supervisory and regulatory requirements of certain third countries and territories for the purposes of the treatment of exposures, in accordance with the Capital Requirements Regulation or CRR (575/2013).

    October 04, 2021 WebPage Regulatory News
    News

    EC Rule on Contractual Recognition of Write-Down and Conversion Powers

    EC published the Implementing Regulation 2021/1751, which lays down implementing technical standards on uniform formats and templates for notification of determination of the impracticability of including contractual recognition of write-down and conversion powers.

    October 04, 2021 WebPage Regulatory News
    RESULTS 1 - 10 OF 7552