General Information & Client Service
  • Americas: +1.212.553.1653
  • Asia: +852.3551.3077
  • China: +86.10.6319.6580
  • EMEA: +44.20.7772.5454
  • Japan: +81.3.5408.4100
Media Relations
  • New York: +1.212.553.0376
  • London: +44.20.7772.5456
  • Hong Kong: +852.3758.1350
  • Tokyo: +813.5408.4110
  • Sydney: +61.2.9270.8141
  • Mexico City: +001.888.779.5833
  • Buenos Aires: +0800.666.3506
  • São Paulo: +0800.891.2518
September 24, 2018

APRA released updated guidance, in the form of an Information Paper, on the use of shared computing services, such as cloud, by APRA-regulated entities. The new paper acknowledges that advancements in cloud computing service offerings over the past three years have improved the ability of APRA-regulated entities to manage the risks involved. However, it also emphasizes the need for entities to be mindful of the differing levels of responsibility for operating and managing these arrangements.

This Information Paper is relevant for a broad audience including boards, senior management, risk management, technical specialists, and internal audit. APRA has a number of existing prudential standards and practice guides that are pertinent to cloud computing services. These Prudential Standards and Prudential Practice Guides include CPS 231 Outsourcing; SPS 231 Outsourcing; HPS231 Outsourcing; PPG 231 Outsourcing; SPG 231 Outsourcing; CPS 232 Business Continuity Management; SPS 232 Business Continuity Management; CPG 233 Pandemic Planning; (draft) CPS 234 Information Security, CPG 234 Management of Security Risk in Information and Information Technology; and CPG 235 Managing Data Risk. This Information Paper applies the concepts included in these standards and guides and APRA intends to reflect the principles in this paper in future guidance updates. For the purpose of this paper, APRA has classified these risks into three broad categories: low, heightened, and extreme.

  • For arrangements with low inherent risk not involving offshoring, APRA would not expect an APRA-regulated entity to consult with APRA prior to entering into the arrangement.
  • For arrangements with heightened risk, APRA would expect to be consulted after the APRA-regulated entity’s internal governance process is completed.
  • For arrangements involving extreme inherent risk, APRA encourages earlier engagement as these arrangements will be subjected to a higher level of scrutiny.

The new Information Paper updates information on prudential considerations and key principles issued to APRA-regulated entities in July 2015. It has been developed in response to the growing use of the cloud by APRA-regulated entities for higher inherent risk activities and in response to the observed areas of weakness in how entities approach and manage these risks. APRA-regulated entities should note that while this information paper does not constitute formal regulation, APRA intends to incorporate the better practices described in the paper into prudential standards and practice guides in the future. Any such changes will be subject to APRA’s normal processes of consultation. 

 

Related Links

Keywords: Asia Pacific, Australia, Banking, Fintech, Cloud Computing, Guidance, APRA

Related Insights
News

EBA Finalizes Guidelines on the STS Criteria in Securitization

EBA published the final guidelines that provide a harmonized interpretation of the criteria for a securitization to be eligible as simple, transparent, and standardized (STS) on a cross-sectoral basis throughout EU.

December 12, 2018 WebPage Regulatory News
News

OSFI Sets Domestic Stability Buffer for D-SIBs at 1.75%

OSFI set the level for the Domestic Stability Buffer at 1.75% of total risk-weighted assets, as calculated under the Capital Adequacy Requirements (CAR) Guideline.

December 12, 2018 WebPage Regulatory News
News

FSI Publishes Paper on Proportionality in Insurance Solvency Rules

FSI published a paper on proportionality in the application of insurance solvency requirements.

December 11, 2018 WebPage Regulatory News
News

BCBS Updates Framework for Pillar 3 Disclosure Requirements

BCBS published the updated framework for Pillar 3 disclosure requirements.

December 11, 2018 WebPage Regulatory News
News

EBA Issues Revised List of Validation Rules for Reporting

EBA revised the list of validation rules in its implementing technical standards on supervisory reporting.

December 11, 2018 WebPage Regulatory News
News

IMF Reports Assess the Stability of Financial System in Brazil

IMF published a report on the results of the Financial System Stability Assessment (FSSA) on Brazil.

December 11, 2018 WebPage Regulatory News
News

FED Governor Examines Pros of Imposing Capital Buffers on Large Banks

At the Peterson Institute for International Economics in Washington D.C., the FED Governor Lael Brainard summarized the financial stability outlook, highlighted areas where financial imbalances seem to be building, and touched on the related policy implications.

December 07, 2018 WebPage Regulatory News
News

US Agencies Propose Rule on Appraisals for Real Estate Transactions

US Agencies (FDIC, FED, and OCC) proposed a rule to increase the threshold level at or below which appraisals would not be required for the residential real estate transactions from USD 250,000 to USD 400,000. Comments will be accepted for 60 days from publication in the Federal Register.

December 07, 2018 WebPage Regulatory News
News

EBA Single Rulebook Q&A: First Update for December 2018

This week one answer was published as part of the Single Rulebook Questions and Answers (Q&A).

December 07, 2018 WebPage Regulatory News
News

FED Updates Reporting Form and Instructions for FR Y-14Q

FED published the updated reporting form FR Y-14Q for Capital Assessment and Stress Testing, along with the associated instructions.

December 06, 2018 WebPage Regulatory News
RESULTS 1 - 10 OF 2325