PRA Finalizes Policy on Outsourcing and Third-Party Risk Management
PRA published the policy statement PS7/21 that sets out the final supervisory statement SS2/21 on outsourcing and third-party risk management. Firms will be expected to comply with the expectations in SS2/21 by March 31, 2022. PS7/21 also contains feedback to responses to the consultation paper CP30/19, which was published in December 2019 and had set out proposals to modernize the regulatory framework on outsourcing and third-party risk management. PRA revised the policy in SS2/21 based on responses received to CP30/19; the revisions relate to the text on definition of outsourcing, proportionality, governance and record-keeping, pre-outsourcing phase, outsourcing agreements, data security, and business continuity and exit plans.
SS2/21 elaborates on the definition of outsourcing in the PRA Rulebook. It notes that there are arrangements between firms and third parties that fall outside this definition and are, consequently, outside the scope of the existing requirements on outsourcing and some of the detailed expectations in SS2/21. However, these third-party arrangements are still subject to the PRA Fundamental Rules and other PRA requirements and expectations on business continuity, governance, operational resilience, and risk management. SS2/21 clarifies the application of the principle of proportionality to intragroup outsourcing and to "non-significant firms." SS2/21 further sets out the expectations on governance, including under the Senior Managers and Certification Regime (SM&CR), and record keeping. SS2/21 also sets out expectations for firms during the pre-outsourcing phase and aims to:
- Complement the requirements and expectations on operational resilience, as set out in the PRA Rulebook, SS1/21, and statement of policy on operational resilience
- Facilitate greater resilience and adoption of the cloud and other new technologies, as set out in the response of BoE to the "Future of Finance" report
- Implement the EBA guidelines on outsourcing arrangements and clarify how PRA expects banks to approach the EBA Outsourcing Guidelines in the context of its requirements and expectations
- Implement the relevant sections of the EBA guidelines on information and communication technology and security risk management
Outsourcing arrangements entered into on or after March 31, 2021 should meet the expectations in SS2/21 by March 31, 2022. Firms should seek to review and update legacy outsourcing agreements entered into before March 31, 2021 at the first appropriate contractual renewal or revision point to meet the expectations in SS2/21 as soon as possible on or after March 31, 2022. SS7/21 is relevant to banks, building societies, and PRA-designated investment firms, insurance and reinsurance firms, groups in scope of Solvency II, including the Society of Lloyd’s and managing agents, and branches of overseas banks and insurers. Some content in SS2/21 is also relevant to credit unions and non-directive firms. The policy set out in PS7/21 has been designed in the context of the UK having left EU and the transition period having come to an end. Unless otherwise stated, any references to EU or EU-derived legislation refer to the version of the legislation that forms part of the retained EU law. PRA will keep the policy under review to assess whether any changes would be required due to changes in the UK regulatory framework.
Related Links
Effective Date: March 31, 2022
Keywords: Europe, UK, Banking, Insurance, Proportionality, Operational Resilience, Third-Party Arrangements, Operational Risk, Outsourcing Risk, PRA
Related Articles
EBA Clarifies Use of COVID-19-Impacted Data for IRB Credit Risk Models
The European Banking Authority (EBA) published four draft principles to support supervisory efforts in assessing the representativeness of COVID-19-impacted data for banks using the internal ratings based (IRB) credit risk models.
EP Reaches Agreement on Corporate Sustainability Reporting Directive
The European Council and the European Parliament (EP) reached a provisional political agreement on the Corporate Sustainability Reporting Directive (CSRD).
PRA Consults on Model Risk Management Principles for Banks
The Prudential Regulation Authority (PRA) launched a consultation (CP6/22) that sets out proposal for a new Supervisory Statement on expectations for management of model risk by banks.
EC Regulation Amends Standards for Calculating Credit Risk Adjustments
The European Commission (EC) published the Delegated Regulation 2022/954, which amends regulatory technical standards on specification of the calculation of specific and general credit risk adjustments.
BIS Hub Updates Work Program for 2022, Announces New Projects
The Bank for International Settlements (BIS) Innovation Hub updated its work program, announcing a set of projects across various centers.
EIOPA Issues Cyber Underwriting Proposal, Statement on Open Insurance
The European Insurance and Occupational Pensions Authority (EIOPA) published two consultation papers—one on the supervisory statement on exclusions related to systemic events and the other on the supervisory statement on the management of non-affirmative cyber exposures.
US Senate Members Seek Details on SEC Proposed Climate Disclosure Rule
Certain members of the U.S. Senate Committee on Banking, Housing, and Urban Affairs issued a letter to the Securities and Exchange Commission (SEC)
EIOPA Consults on Review of Securitization Framework in Solvency II
The European Insurance and Occupational Pensions Authority (EIOPA) published a consultation paper on the advice on the review of the securitization prudential framework in Solvency II.
BIS Bulletins Discuss DeFi Lending and Aspects of Crypto-Assets
The Bank for International Settlements (BIS) published bulletins on lending in decentralized finance (DeFi) system, on blockchain scalability and fragmentation of crypto, and on extractable value and market manipulation in crypto and decentralized finance.
UK Authorities Issue Regulatory and Reporting Updates for Banks
The Prudential Regulation Authority (PRA) issued a statement on PRA buffer adjustment while the Bank of England (BoE) published a notice on the statistical reporting requirements for banks.