September 24, 2018

APRA released updated guidance, in the form of an Information Paper, on the use of shared computing services, such as cloud, by APRA-regulated entities. The new paper acknowledges that advancements in cloud computing service offerings over the past three years have improved the ability of APRA-regulated entities to manage the risks involved. However, it also emphasizes the need for entities to be mindful of the differing levels of responsibility for operating and managing these arrangements.

This Information Paper is relevant for a broad audience including boards, senior management, risk management, technical specialists, and internal audit. APRA has a number of existing prudential standards and practice guides that are pertinent to cloud computing services. These Prudential Standards and Prudential Practice Guides include CPS 231 Outsourcing; SPS 231 Outsourcing; HPS231 Outsourcing; PPG 231 Outsourcing; SPG 231 Outsourcing; CPS 232 Business Continuity Management; SPS 232 Business Continuity Management; CPG 233 Pandemic Planning; (draft) CPS 234 Information Security, CPG 234 Management of Security Risk in Information and Information Technology; and CPG 235 Managing Data Risk. This Information Paper applies the concepts included in these standards and guides and APRA intends to reflect the principles in this paper in future guidance updates. For the purpose of this paper, APRA has classified these risks into three broad categories: low, heightened, and extreme.

  • For arrangements with low inherent risk not involving offshoring, APRA would not expect an APRA-regulated entity to consult with APRA prior to entering into the arrangement.
  • For arrangements with heightened risk, APRA would expect to be consulted after the APRA-regulated entity’s internal governance process is completed.
  • For arrangements involving extreme inherent risk, APRA encourages earlier engagement as these arrangements will be subjected to a higher level of scrutiny.

The new Information Paper updates information on prudential considerations and key principles issued to APRA-regulated entities in July 2015. It has been developed in response to the growing use of the cloud by APRA-regulated entities for higher inherent risk activities and in response to the observed areas of weakness in how entities approach and manage these risks. APRA-regulated entities should note that while this information paper does not constitute formal regulation, APRA intends to incorporate the better practices described in the paper into prudential standards and practice guides in the future. Any such changes will be subject to APRA’s normal processes of consultation. 

 

Related Links

Keywords: Asia Pacific, Australia, Banking, Fintech, Cloud Computing, Guidance, APRA

Related Articles
News

PRA Finalizes Reporting Amendments to Pillar 2 Liquidity Framework

PRA published the final Policy Statement PS13/19 on regulatory reporting amendments and clarifications to the Pillar 2 liquidity framework for banks in UK.

June 17, 2019 WebPage Regulatory News
News

IAIS Consults on Revisions to IAIS Supervisory Material

IAIS has launched a public consultation on revisions to the IAIS supervisory material.

June 14, 2019 WebPage Regulatory News
News

IMF Paper on Implementing Prudential Standards in Developing Economies

IMF published a working paper that provides practical guidance on how developing economies, including non-Basel Committee member countries, could incorporate international standards into their prudential framework.

June 14, 2019 WebPage Regulatory News
News

EBA Single Rulebook Q&A: Second Update for June 2019

EBA published answers to five questions under the Single Rulebook question and answer (Q&A) updates for this week.

June 14, 2019 WebPage Regulatory News
News

FSB Releases Update on Meeting of Regional Consultative Group for Asia

FSB published an update on the meeting of its Regional Consultative Group (RCG) for Asia.

June 14, 2019 WebPage Regulatory News
News

BoE, FCA, and MAS Announce Collaboration on Cyber Security

MAS and UK financial authorities (BoE and FCA) announced that they will work together to strengthen cyber security in their financial sectors.

June 13, 2019 WebPage Regulatory News
News

CBIRC Advisory Committee Holds Meeting, Discusses Regulatory Issues

The first meeting of the International Advisory Committee (IAC) of CBIRC was held in Shanghai from June 11 to 12, 2019.

June 13, 2019 WebPage Regulatory News
News

ECB and EIOPA Publish Common Minimum Standards for Data Revision in EU

ECB and EIOPA published the common minimum standards for supervisory and statistical reporting data by the undertakings in EU.

June 13, 2019 WebPage Regulatory News
News

IMF Reports on 2019 Article IV Consultation with Czech Republic

IMF published its staff report and selected issues report under the 2019 Article IV consultation with Czech Republic.

June 13, 2019 WebPage Regulatory News
News

APRA Response to Proposal on Revisions to Capital Framework for Banks

APRA published a paper in response to the first round of consultation on proposed changes to the capital framework for authorized deposit-taking institutions.

June 12, 2019 WebPage Regulatory News
RESULTS 1 - 10 OF 3252