Featured Product

    APRA Updates Guidance on Cloud Computing Services

    September 24, 2018

    APRA released updated guidance, in the form of an Information Paper, on the use of shared computing services, such as cloud, by APRA-regulated entities. The new paper acknowledges that advancements in cloud computing service offerings over the past three years have improved the ability of APRA-regulated entities to manage the risks involved. However, it also emphasizes the need for entities to be mindful of the differing levels of responsibility for operating and managing these arrangements.

    This Information Paper is relevant for a broad audience including boards, senior management, risk management, technical specialists, and internal audit. APRA has a number of existing prudential standards and practice guides that are pertinent to cloud computing services. These Prudential Standards and Prudential Practice Guides include CPS 231 Outsourcing; SPS 231 Outsourcing; HPS231 Outsourcing; PPG 231 Outsourcing; SPG 231 Outsourcing; CPS 232 Business Continuity Management; SPS 232 Business Continuity Management; CPG 233 Pandemic Planning; (draft) CPS 234 Information Security, CPG 234 Management of Security Risk in Information and Information Technology; and CPG 235 Managing Data Risk. This Information Paper applies the concepts included in these standards and guides and APRA intends to reflect the principles in this paper in future guidance updates. For the purpose of this paper, APRA has classified these risks into three broad categories: low, heightened, and extreme.

    • For arrangements with low inherent risk not involving offshoring, APRA would not expect an APRA-regulated entity to consult with APRA prior to entering into the arrangement.
    • For arrangements with heightened risk, APRA would expect to be consulted after the APRA-regulated entity’s internal governance process is completed.
    • For arrangements involving extreme inherent risk, APRA encourages earlier engagement as these arrangements will be subjected to a higher level of scrutiny.

    The new Information Paper updates information on prudential considerations and key principles issued to APRA-regulated entities in July 2015. It has been developed in response to the growing use of the cloud by APRA-regulated entities for higher inherent risk activities and in response to the observed areas of weakness in how entities approach and manage these risks. APRA-regulated entities should note that while this information paper does not constitute formal regulation, APRA intends to incorporate the better practices described in the paper into prudential standards and practice guides in the future. Any such changes will be subject to APRA’s normal processes of consultation. 

     

    Related Links

    Keywords: Asia Pacific, Australia, Banking, Fintech, Cloud Computing, Guidance, APRA

    Related Articles
    News

    HKMA Enhances Loan Guarantee Scheme to Alleviate Pressure on SMEs

    HKMA announced that enhancements will be made to the Special 100% Loan Guarantee of the SME Financing Guarantee Scheme (SFGS) and the application period will be extended to December 31, 2021.

    February 24, 2021 WebPage Regulatory News
    News

    BoE Sets Out Plan to Transform Data Collection from Financial Sector

    BoE has set out a three-phased plan to transform data collection from the UK financial sector over the next decade.

    February 23, 2021 WebPage Regulatory News
    News

    BIS Issues Updates on Technology Initiatives on Cross-Border Payments

    BIS recently made a couple of announcements with respect to the planned and ongoing work in the area of financial technology.

    February 23, 2021 WebPage Regulatory News
    News

    ESRB Updates List of Macro-Prudential Measures in February 2021

    ESRB updated the list of national macro-prudential measures applied by each member state in the European Economic Area.

    February 22, 2021 WebPage Regulatory News
    News

    BoE Survey Shows Positive COVID Impact on Outsourced Banking Services

    BoE has set out results of a survey on the impact of COVID-19 events on the use of machine learning and data science.

    February 22, 2021 WebPage Regulatory News
    News

    ECB Issues Opinion on Proposal to Regulate Crypto-Asset Markets in EU

    In response to a request from the European Council and Parliament, ECB published an opinion on the proposed regulation on markets in crypto-assets.

    February 22, 2021 WebPage Regulatory News
    News

    APRA Announces Aggregate Committed Liquidity Facility for Banks

    APRA announced the updated aggregate amounts for the 2021 Committed Liquidity Facility (CLF) established between the Reserve Bank of Australia (RBA) and certain locally incorporated authorized deposit-taking institutions that are subject to the Liquidity Coverage Ratio (LCR).

    February 19, 2021 WebPage Regulatory News
    News

    ECB and UK Authorities Agree on Post-Brexit Supervisory Cooperation

    ECB published supervisory Memorandums of Understanding (MoUs) with UK as well as other European and non-European authorities.

    February 19, 2021 WebPage Regulatory News
    News

    EIOPA Outlines Strategic Supervisory Priorities for Insurance Sector

    EIOPA identified business model sustainability and adequate product design as the two EU-wide strategic supervisory priorities.

    February 19, 2021 WebPage Regulatory News
    News

    US Agencies to Revise FFIEC 031, FFIEC 041, and FFIEC 051 Reports

    After considering comments received on the November 2020 proposal, US Agencies (FDIC, FED and OCC) are proceeding with the proposed revisions to the reporting forms and instructions for Call Reports FFIEC 031, FFIEC 041, and FFIEC 051.

    February 19, 2021 WebPage Regulatory News
    RESULTS 1 - 10 OF 6618