Featured Product

    MFSA Clarifies Whether SaaS Cloud Model is an Outsourcing Arrangement

    March 08, 2021

    MFSA published a circular clarifying whether the Software-as-a-Service (SaaS) cloud model is an outsourcing arrangement. The circular also provides brief guidance on how license holders shall manage the relevant outsourcing risks associated with SaaS arrangements, including but not limited to risks associated with the data being processed by the SaaS third-party providers. MFSA states that license holders need to, for instance, give due consideration to business continuity in case of disruptions on the part of the SaaS third-party providers, including migration and exit strategies. The circular also states that SaaS third-party providers should be subject to adequate due diligence both at the initial stage and on an ongoing basis.

    The MFSA circular presents the definition of (verbatim) SaaS as stated in the EC cloud strategy from May 2019 and the differing definition of ICT third-party provider as stated under the proposed Regulation on Digital Operational Resilience. Within the context of the vendor-user relationship, the SaaS model allows the vendor to manage the business application(s) that would otherwise have to be managed in-house. With respect to establishing whether SaaS is an outsourcing arrangement, the circular states that, under normal circumstances, the management element of the service rendered by SaaS third-party providers to license holders qualifies as an outsourcing arrangement. SaaS qualifies as an outsourcing arrangement if the service is performed on a recurrent or an ongoing basis and if the service would normally fall within the scope of functions that would or could realistically be performed by the license holder, even if the license holder has not performed this function in the past. License holders are to assess and determine whether SaaS currently being consumed or planned to be acquired, qualifies as an outsourcing arrangement. License holders are to further assess and determine whether the outsourcing arrangement entails the outsourcing of a critical or important function.  

    Additional guidance on outsourcing risk and on whether certain arrangements quality as outsourcing can be found within the MFSA Guidance on Technology Arrangements ICT and Security Risk Management and Outsourcing Arrangements and on the guidelines of ESAs on outsourcing arrangements and/or outsourcing to cloud service providers. License holders are reminded of their obligation to comply with any applicable Acts, Regulations, rules, and sector-specific guidelines pertaining to outsourcing arrangements.

     

    Related Links

    Keywords: Europe, Malta, Banking, SAAS, Cloud Computing, Outsourcing Risk, Operational Resilience, Third-Party Arrangements, MFSA

    Related Articles
    News

    EC Issues Regulation on Adjustments to K-Factor Coefficients Under IFR

    The European Commission (EC) published a report summarizing responses to the targeted consultation on the supervisory convergence and the single rulebook in the European Union (EU).

    January 20, 2022 WebPage Regulatory News
    News

    OSFI Issues Results of Pilot on Climate Risk Scenario Analysis

    The Office of the Superintendent of Financial Institutions (OSFI) published an update on the discussion paper that intended to engage federally regulated financial institutions and other interested stakeholders in a dialog with OSFI, to proactively enhance and align assurance expectations over key regulatory returns.

    January 20, 2022 WebPage Regulatory News
    News

    ECB Issues Opinions on Green Bonds Standard and CRR Proposals

    The European Central Bank (ECB) published its opinion on a proposal for a regulation on European green bonds, following a request from the European Parliament.

    January 19, 2022 WebPage Regulatory News
    News

    ESRB Explores Policy Response to Risks Arising from Digitalization

    The Advisory Scientific Committee (ASC) of the European Systemic Risk Board (ESRB) published a report that explores the expected impact of digitalization on provision of financial and banking services, and proposes policy measures to address the risks stemming from digitalization.

    January 18, 2022 WebPage Regulatory News
    News

    EU Authorities Address COVID-19 Reporting, MCD, and PSD2 Issues

    The European Banking Authority (EBA) announced that the guidelines on the reporting and disclosure of exposures subject to measures COVID-relief measures shall continue to apply until further notice.

    January 17, 2022 WebPage Regulatory News
    News

    FI Publishes Multiple Regulatory and Reporting Updates

    The Swedish Financial Supervisory Authority (FI) announced that the capital adequacy reporting as at December 31, 2021 must be done by February 11, 2022.

    January 17, 2022 WebPage Regulatory News
    News

    BSP Tackles Aspects of Lending and Islamic, Open & Sustainable Finance

    The Central Bank of the Philippines (BSP) issued communications covering developments related to online lending platforms, open finance framework and roadmap, and on the expected regulations in the area sustainable finance.

    January 16, 2022 WebPage Regulatory News
    News

    US Agencies Issue Regulatory Updates, FDIC Launches Tech Sprint

    The Board of Governors of the Federal Reserve System (FED) published the final rule that amends Regulation I to reduce the quarterly reporting burden for member banks by automating the application process for adjusting their subscriptions to the Federal Reserve Bank capital stock, except in the context of mergers.

    January 13, 2022 WebPage Regulatory News
    News

    EBA Issues Guide on Bank Resolvability, Consults on Transferability

    The European Banking Authority (EBA) published its assessment of risks through the quarterly Risk Dashboard and the results of the Autumn edition of the Risk Assessment Questionnaire (RAQ).

    January 13, 2022 WebPage Regulatory News
    News

    MFSA Publishes CRD5 Updates and Supervisory Priorities for 2022

    The Malta Financial Services Authority (MFSA) updated the guidelines on supervisory reporting requirements under the reporting framework 3.0.

    January 13, 2022 WebPage Regulatory News
    RESULTS 1 - 10 OF 7875