Featured Product

    EIOPA Consults on Guidelines on Outsourcing to Cloud Service Providers

    July 01, 2019

    EIOPA launched a consultation on the guidelines for outsourcing to cloud service providers. The guidelines are addressed to insurance and reinsurance undertakings as well as national supervisory authorities in EU. The guidelines specify how the outsourcing provisions set forth in the Solvency II Directive (2009/138/EC), in the Delegated Regulation 2015/35, and in the EIOPA guidelines on system of governance need to be applied in case of outsourcing to cloud service providers. The consultation is open until September 30, 2019. These guidelines apply from July 01, 2020 to all cloud outsourcing arrangements entered into, or amended on or after this date.

    EIOPA developed these guidelines in line with its contribution to Fintech Action Plan of EC and taking into account the outcome of its Fourth Insurtech Roundtable on the use of cloud computing by (re)insurance undertakings. The guidelines aim to provide clarification and transparency to market participants and to help avoid potential regulatory arbitrages. They also intend to foster supervisory convergence regarding the expectations and processes applicable in relation to cloud outsourcing. Annex 1 to the consultation contains the impact assessment to the guidelines whereas Annex II provides an overview of questions for consultation. The key areas covered in the guidelines include the following:

    • Criteria to distinguish whether cloud services should be considered within the scope of outsourcing
    • Principles and elements of governance of cloud outsourcing, including documentation requirements and list of information part of the notification to supervisory authorities
    • Pre-outsourcing analysis, including materiality assessment, risk assessment, and due diligence on the service providers
    • Contractual requirements
    • Management of access and audit rights; security of data and systems; sub-outsourcing, monitoring, and oversight of cloud outsourcing; and exit strategies
    • Principle-based instructions for national supervisory authorities on the supervision of cloud outsourcing arrangements including, where applicable, at group level

    The use of cloud outsourcing is a common practice among all types of financial undertakings, not only for insurance and reinsurance undertakings. Moreover, the key associated risks are similar across sectors. Acknowledging these facts and recognizing the potential risks of regulatory fragmentation in developing these guidelines—in addition to the (re)insurance provisions on outsourcing—EIOPA also considered the most recent guidance published by EBA.

     

    Related Links

    Comment Due Date: September 30, 2019

    Effective Date: July 01, 2020

    Keywords: Europe, EU, Insurance, Reinsurance, Guidelines, Outsourcing, Cloud Service Providers, Governance, Fintech, Insurtech, Regulatory Arbitrage, Supervisory Convergence, Cloud Outsourcing, Solvency II, EBA, EC, EIOPA

    Featured Experts
    Related Articles
    News

    EC Delegated Regulation on Specialized Lending Exposures Under CRR

    EC finalized the Delegated Regulation 2021/598 that supplements the Capital Requirements Regulation (CRR or 575/2013) and lays out the regulatory technical standards for assigning risk-weights to specialized lending exposures.

    April 14, 2021 WebPage Regulatory News
    News

    OSFI Consults on Minimum Qualifying Rate for Uninsured Mortgages

    OSFI is proposing new minimum qualifying rate for uninsured mortgages under the Guideline B-20.

    April 13, 2021 WebPage Regulatory News
    News

    OSFI Issues Letter on ICAAP Submission and Internal Audit of BCAR

    OSFI issued a letter to confirm that a formal Internal Capital Adequacy Assessment Process (ICAAP) submission is not required in 2021.

    April 12, 2021 WebPage Regulatory News
    News

    ECB Updates List of Supervised Entities in EU in April 2021

    ECB updated the list of supervised entities in EU, with the number of significant supervised entities amounting to 115 as of the March 01, 2021 cut-off date.

    April 12, 2021 WebPage Regulatory News
    News

    ESMA Issues Notification Templates for STS Synthetic Securitizations

    ESMA published the interim simple, transparent, and standardized (STS) notification templates for synthetic securitizations, post the recent amendments to the Securitization Regulation.

    April 09, 2021 WebPage Regulatory News
    News

    EC Agrees to Prolong Scheme to Support NPL Reduction at Greek Banks

    EC has approved the prolongation of an existing Greek scheme aiming to support the reduction of nonperforming loans, or NPLs, of Greek banks on the basis that it remains free of any State aid.

    April 09, 2021 WebPage Regulatory News
    News

    EIOPA Study Examines Internal Model Market and Credit Risks Under SII

    EIOPA published a report presenting the results of its yearly study on the internal modeling of market and credit risks under the Solvency II Directive, also known as SII.

    April 09, 2021 WebPage Regulatory News
    News

    EBA Issues Erratum for Phase 2 Package of Reporting Framework 3.0

    EBA published an erratum for the technical package on phase 2 of the reporting framework 3.0.

    April 08, 2021 WebPage Regulatory News
    News

    EBA Updates Lists of Entities for Use in Capital Calculations under SA

    EBA published an erratum for the technical package on phase 2 of the reporting framework 3.0.

    April 08, 2021 WebPage Regulatory News
    News

    FED Proposes to Automate Bank Stock Adjustment Using Call Report Data

    FED published a proposal to automate non-merger-related adjustments to member banks' subscriptions to Federal Reserve Bank capital stock.

    April 08, 2021 WebPage Regulatory News
    RESULTS 1 - 10 OF 6835