BoM revised the guideline setting out a broad framework for financial institutions that have entered into outsourcing or are planning to outsource their business activities to service providers. The guideline covers risk management framework in outsourcing, evaluation of risks involved in outsourcing, classification of outsourcing activities, and the use of cloud-based services by financial institutions. This guideline is applicable to all financial institutions falling under the regulatory purview of BoM.
The guideline is based on a three-tier classification of activities: material activities that require authorization, non-material activities that do not require authorization, and core activities that cannot be outsourced. BoM considers cloud-based services operated by service providers as a form of outsourcing and recognizes that financial institutions may have recourse to such services to enhance their operations and service efficiency. The usage of cloud-based services by financial institutions shall be restricted to non-core activities only. Financial institutions are required to take appropriate measures with respect to data access, confidentiality, integrity, sovereignty, recoverability, regulatory compliance, and auditing. They should ensure that the service providers have the capacity to identify and segregate customer data using strong physical or logical controls. As per the guideline, financial institutions are ultimately responsible and accountable for maintaining oversight of cloud-based services and managing the attendant risks of adopting cloud-based services, as in any other form of outsourcing arrangement.
Financial institutions should conduct an assessment of all their existing outsourcing arrangements against this guideline. Where the outsourcing is considered material, financial institutions should inform BoM in writing about the level of compliance with the guideline and report weaknesses, if any. Institutions should also submit a plan and timeframe on how such weaknesses would be rectified. This should be done within four months from when the guideline becomes effective. Financial institutions should annually submit to BoM a Return on Outsourced Activities, containing a list of all material and non-material activities that have been outsourced, in such form and manner prescribed by BoM. This return should be submitted within the next twenty working days of the previous calendar year. The guideline follows the high-level principles on outsourcing in financial services, developed by the Joint Forum comprising BCBS, IOSCO, and IAIS.
Keywords: Middle East and Africa, Mauritius, Banking, Outsourcing, Cloud Computing, Regtech, BoM
The Central Bank of the Philippines (BSP) issued communications covering developments related to online lending platforms, open finance framework and roadmap, and on the expected regulations in the area sustainable finance.
The Board of Governors of the Federal Reserve System (FED) published the final rule that amends Regulation I to reduce the quarterly reporting burden for member banks by automating the application process for adjusting their subscriptions to the Federal Reserve Bank capital stock, except in the context of mergers.
The European Banking Authority (EBA) published its assessment of risks through the quarterly Risk Dashboard and the results of the Autumn edition of the Risk Assessment Questionnaire (RAQ).
The Malta Financial Services Authority (MFSA) updated the guidelines on supervisory reporting requirements under the reporting framework 3.0.
The Hong Kong Monetary Authority (HKMA) published a circular, along with the reporting form and instructions, for self-assessment, by authorized institutions, of compliance with the Code of Banking Practice 2021.
The Financial Conduct Authority (FCA) decided to register European DataWarehouse Ltd and SecRep Limited as securitization repositories under the UK Securitization Regulation, with effect from January 17, 2022.
The European Commission (EC) published the Delegated Regulation 2022/25, which supplements the Investment Firms Regulation (IFR or Regulation 2019/2033) with respect to the regulatory technical standards specifying the methods for measuring the K-factors referred to in Article 15 of the IFR.
The Bank of International Settlements (BIS) published a paper that assesses the ways in which platform-based business models can affect financial inclusion, competition, financial stability and consumer protection.
The Central Bank of Egypt (CBE) published a circular with instructions on emergency liquidity assistance to banks that are unable to meet their liquidity requirements.
The European Supervisory Authorities (ESAs) published the list of identified financial conglomerates for 2021.