EIOPA finalized the guidelines on information and communication technology (ICT) security and governance for the insurance sector. The guidelines address how rules on operational risks set forth in the Solvency II Directive and in the Delegated Regulation 2015/35 are applied to the ICT security and governance. EIOPA consulted on the draft guidelines between December 2019 and March 2020 and has also published its response to the key issues raised in the feedback. The guidelines are intended for both market participants and the national supervisory authorities, which are expected to apply these guidelines from July 01, 2021.
The objective of the guidelines is to promote the increase of the operational resilience of the digital operations of insurance and reinsurance undertakings against the risks they face. Operational resilience is key to protecting the digital assets (including their systems and data) of insurance and reinsurance undertakings. The guidelines provide clarification and transparency to market participants on the minimum expected information and cyber-security capabilities and help to avoid potential regulatory arbitrage. These guidelines are also intended to foster supervisory convergence regarding the expectations and processes applicable in relation to ICT security and governance as a key to proper ICT and security risk management.
Competent authorities should, when complying or supervising compliance with these guidelines, take into account the principle of proportionality. This principle should should ensure that governance arrangements, including those related to ICT security and governance are proportionate to the nature, scale, and complexity of the corresponding risks undertakings face or may face. The guidelines should be read in conjunction with the Solvency II Directive, the Delegated Regulation 2015/35, the EIOPA guidelines on system of governance, and the EIOPA guidelines on outsourcing to cloud service providers.
Effective Date: July 01, 2021 (expected)
Keywords: Europe, EU, Insurance, Governance, Operational Risk, Solvency II, Cloud Service Providers, ICT Risk, EIOPA
Previous ArticleEC Amends Regulation on IFRS 16 in Response to COVID-19 Crisis
EBA published a report analyzing the impact of the unwind mechanism of the liquidity coverage ratio (LCR) for a sample of European banks over a three-year period, from the end of 2016 to the first quarter of 2020.
In response to questions from a member of the European Parliament, the ECB President Christine Lagarde issued a letter clarifying the possibility of amending the AnaCredit Regulation and making targeted longer-term refinancing operations (TLTROs) dependent on the climate-related impact of bank loans.
IASB started the post-implementation review of the classification and measurement requirements in IFRS 9 on financial instruments and added the review as a project to its work plan.
FSB published a report that examines progress in implementing policy measures to enhance the resolvability of systemically important financial institutions.
EBA published a report on the benchmarking of national loan enforcement frameworks across 27 EU member states, in response to the call for advice from EC.
FSB published a letter from its Chair Randal K. Quarles, along with two reports exploring various aspects of the market turmoil resulting from the COVID-19 event.
RBNZ launched a consultation on the details for implementing the final Capital Review decisions announced in December 2019.
The Trustees of the IFRS Foundation, which are responsible for the governance and oversight of IASB, have announced the appointment of Dr. Andreas Barckow as the IASB Chair, effective July 2021.
HKMA issued a letter to consult the banking industry on a full set of proposed draft amendments to the Banking (Capital) Rules for implementing the Basel standard on capital requirements for banks’ equity investments in funds in Hong Kong.
ESRB published an opinion assessing the decision of Swedish Financial Supervisory Authority (FSA) to extend the application period of a stricter measure for residential mortgage lending, in accordance with Article 458 of the Capital Requirements Regulation (CRR).