Featured Product

    APRA Updates Guidance on Cloud Computing Services

    September 24, 2018

    APRA released updated guidance, in the form of an Information Paper, on the use of shared computing services, such as cloud, by APRA-regulated entities. The new paper acknowledges that advancements in cloud computing service offerings over the past three years have improved the ability of APRA-regulated entities to manage the risks involved. However, it also emphasizes the need for entities to be mindful of the differing levels of responsibility for operating and managing these arrangements.

    This Information Paper is relevant for a broad audience including boards, senior management, risk management, technical specialists, and internal audit. APRA has a number of existing prudential standards and practice guides that are pertinent to cloud computing services. These Prudential Standards and Prudential Practice Guides include CPS 231 Outsourcing; SPS 231 Outsourcing; HPS231 Outsourcing; PPG 231 Outsourcing; SPG 231 Outsourcing; CPS 232 Business Continuity Management; SPS 232 Business Continuity Management; CPG 233 Pandemic Planning; (draft) CPS 234 Information Security, CPG 234 Management of Security Risk in Information and Information Technology; and CPG 235 Managing Data Risk. This Information Paper applies the concepts included in these standards and guides and APRA intends to reflect the principles in this paper in future guidance updates. For the purpose of this paper, APRA has classified these risks into three broad categories: low, heightened, and extreme.

    • For arrangements with low inherent risk not involving offshoring, APRA would not expect an APRA-regulated entity to consult with APRA prior to entering into the arrangement.
    • For arrangements with heightened risk, APRA would expect to be consulted after the APRA-regulated entity’s internal governance process is completed.
    • For arrangements involving extreme inherent risk, APRA encourages earlier engagement as these arrangements will be subjected to a higher level of scrutiny.

    The new Information Paper updates information on prudential considerations and key principles issued to APRA-regulated entities in July 2015. It has been developed in response to the growing use of the cloud by APRA-regulated entities for higher inherent risk activities and in response to the observed areas of weakness in how entities approach and manage these risks. APRA-regulated entities should note that while this information paper does not constitute formal regulation, APRA intends to incorporate the better practices described in the paper into prudential standards and practice guides in the future. Any such changes will be subject to APRA’s normal processes of consultation. 

     

    Related Links

    Keywords: Asia Pacific, Australia, Banking, Fintech, Cloud Computing, Guidance, APRA

    Related Articles
    News

    APRA Publishes Proposal to Increase Transparency of Banking Data

    APRA proposed to substantially increase the volume and breadth of data it makes publicly available on authorized deposit-taking institutions, including banks, credit unions, and building societies.

    December 05, 2019 WebPage Regulatory News
    News

    ESMA Consults on Guide to Internal Controls for Credit Rating Agencies

    ESMA launched a consultation on the guidelines on internal controls for credit rating agencies (CRAs).

    December 05, 2019 WebPage Regulatory News
    News

    EU Finalizes Directive and Prudential Rules for Investment Firms

    EU published, in the Official Journal of the European Union, the Directive (2019/2034) and Regulation (2019/2033) on the prudential requirements and supervision of investment firms.

    December 05, 2019 WebPage Regulatory News
    News

    OSFI Revises Guideline on Principles for Management of Liquidity Risk

    OSFI finalized Guideline B-6 on the principles for the management of liquidity risk.

    December 05, 2019 WebPage Regulatory News
    News

    PRA Consults on Framework to Manage Outsourcing and Third-Party Risk

    PRA published a consultation paper CP30/19 that sets out proposals to modernize the regulatory framework on outsourcing and third-party risk management.

    December 05, 2019 WebPage Regulatory News
    News

    BoE, PRA, and FCA Consult to Strengthen Operational Resilience

    BoE, PRA, and FCA published a shared policy summary and coordinated consultation papers on new requirements to strengthen operational resilience in the financial services sector.

    December 05, 2019 WebPage Regulatory News
    News

    EC Amends Rule on Mapping of External Credit Assessment Institutions

    EC published the implementing regulation (EU) 2019/2028, which amends Regulation 2016/1799, regarding the mapping tables specifying correspondence between the credit risk assessments of external credit assessment institutions (ECAIs) and the credit quality steps set out in the Capital Requirements Regulation.

    December 04, 2019 WebPage Regulatory News
    News

    EBA Issues Second Part of Advice on Implementation of Basel III in EU

    EBA published the second part of its advice on the implementation of Basel III in EU, which complements the report published on August 05, 2019.

    December 04, 2019 WebPage Regulatory News
    News

    EU Approves European Council Proposal on CCP Recovery and Resolution

    EU ambassadors approved the position of European Council on a proposed framework for clearing houses and their authorities to prepare for and deal with financial difficulties.

    December 04, 2019 WebPage Regulatory News
    News

    OSFI Releases Guideline on Foreign Bank Branch Deposit Requirements

    OSFI released the final version of Guideline A-10 on foreign bank branch deposit requirements, along with guideline impact analysis statement.

    December 04, 2019 WebPage Regulatory News
    RESULTS 1 - 10 OF 4268