Featured Product

    MFSA Clarifies Whether SaaS Cloud Model is an Outsourcing Arrangement

    March 08, 2021

    MFSA published a circular clarifying whether the Software-as-a-Service (SaaS) cloud model is an outsourcing arrangement. The circular also provides brief guidance on how license holders shall manage the relevant outsourcing risks associated with SaaS arrangements, including but not limited to risks associated with the data being processed by the SaaS third-party providers. MFSA states that license holders need to, for instance, give due consideration to business continuity in case of disruptions on the part of the SaaS third-party providers, including migration and exit strategies. The circular also states that SaaS third-party providers should be subject to adequate due diligence both at the initial stage and on an ongoing basis.

    The MFSA circular presents the definition of (verbatim) SaaS as stated in the EC cloud strategy from May 2019 and the differing definition of ICT third-party provider as stated under the proposed Regulation on Digital Operational Resilience. Within the context of the vendor-user relationship, the SaaS model allows the vendor to manage the business application(s) that would otherwise have to be managed in-house. With respect to establishing whether SaaS is an outsourcing arrangement, the circular states that, under normal circumstances, the management element of the service rendered by SaaS third-party providers to license holders qualifies as an outsourcing arrangement. SaaS qualifies as an outsourcing arrangement if the service is performed on a recurrent or an ongoing basis and if the service would normally fall within the scope of functions that would or could realistically be performed by the license holder, even if the license holder has not performed this function in the past. License holders are to assess and determine whether SaaS currently being consumed or planned to be acquired, qualifies as an outsourcing arrangement. License holders are to further assess and determine whether the outsourcing arrangement entails the outsourcing of a critical or important function.  

    Additional guidance on outsourcing risk and on whether certain arrangements quality as outsourcing can be found within the MFSA Guidance on Technology Arrangements ICT and Security Risk Management and Outsourcing Arrangements and on the guidelines of ESAs on outsourcing arrangements and/or outsourcing to cloud service providers. License holders are reminded of their obligation to comply with any applicable Acts, Regulations, rules, and sector-specific guidelines pertaining to outsourcing arrangements.

     

    Related Links

    Keywords: Europe, Malta, Banking, SAAS, Cloud Computing, Outsourcing Risk, Operational Resilience, Third-Party Arrangements, MFSA

    Related Articles
    News

    EBA Clarifies Use of COVID-19-Impacted Data for IRB Credit Risk Models

    The European Banking Authority (EBA) published four draft principles to support supervisory efforts in assessing the representativeness of COVID-19-impacted data for banks using the internal ratings based (IRB) credit risk models.

    June 21, 2022 WebPage Regulatory News
    News

    EP Reaches Agreement on Corporate Sustainability Reporting Directive

    The European Council and the European Parliament (EP) reached a provisional political agreement on the Corporate Sustainability Reporting Directive (CSRD).

    June 21, 2022 WebPage Regulatory News
    News

    PRA Consults on Model Risk Management Principles for Banks

    The Prudential Regulation Authority (PRA) launched a consultation (CP6/22) that sets out proposal for a new Supervisory Statement on expectations for management of model risk by banks.

    June 21, 2022 WebPage Regulatory News
    News

    EC Regulation Amends Standards for Calculating Credit Risk Adjustments

    The European Commission (EC) published the Delegated Regulation 2022/954, which amends regulatory technical standards on specification of the calculation of specific and general credit risk adjustments.

    June 21, 2022 WebPage Regulatory News
    News

    BIS Hub Updates Work Program for 2022, Announces New Projects

    The Bank for International Settlements (BIS) Innovation Hub updated its work program, announcing a set of projects across various centers.

    June 17, 2022 WebPage Regulatory News
    News

    EIOPA Issues Cyber Underwriting Proposal, Statement on Open Insurance

    The European Insurance and Occupational Pensions Authority (EIOPA) published two consultation papers—one on the supervisory statement on exclusions related to systemic events and the other on the supervisory statement on the management of non-affirmative cyber exposures.

    June 17, 2022 WebPage Regulatory News
    News

    US Senate Members Seek Details on SEC Proposed Climate Disclosure Rule

    Certain members of the U.S. Senate Committee on Banking, Housing, and Urban Affairs issued a letter to the Securities and Exchange Commission (SEC)

    June 16, 2022 WebPage Regulatory News
    News

    EIOPA Consults on Review of Securitization Framework in Solvency II

    The European Insurance and Occupational Pensions Authority (EIOPA) published a consultation paper on the advice on the review of the securitization prudential framework in Solvency II.

    June 16, 2022 WebPage Regulatory News
    News

    BIS Bulletins Discuss DeFi Lending and Aspects of Crypto-Assets

    The Bank for International Settlements (BIS) published bulletins on lending in decentralized finance (DeFi) system, on blockchain scalability and fragmentation of crypto, and on extractable value and market manipulation in crypto and decentralized finance.

    June 16, 2022 WebPage Regulatory News
    News

    UK Authorities Issue Regulatory and Reporting Updates for Banks

    The Prudential Regulation Authority (PRA) issued a statement on PRA buffer adjustment while the Bank of England (BoE) published a notice on the statistical reporting requirements for banks.

    June 15, 2022 WebPage Regulatory News
    RESULTS 1 - 10 OF 8292