Featured Product

    APRA Updates Guidance on Cloud Computing Services

    September 24, 2018

    APRA released updated guidance, in the form of an Information Paper, on the use of shared computing services, such as cloud, by APRA-regulated entities. The new paper acknowledges that advancements in cloud computing service offerings over the past three years have improved the ability of APRA-regulated entities to manage the risks involved. However, it also emphasizes the need for entities to be mindful of the differing levels of responsibility for operating and managing these arrangements.

    This Information Paper is relevant for a broad audience including boards, senior management, risk management, technical specialists, and internal audit. APRA has a number of existing prudential standards and practice guides that are pertinent to cloud computing services. These Prudential Standards and Prudential Practice Guides include CPS 231 Outsourcing; SPS 231 Outsourcing; HPS231 Outsourcing; PPG 231 Outsourcing; SPG 231 Outsourcing; CPS 232 Business Continuity Management; SPS 232 Business Continuity Management; CPG 233 Pandemic Planning; (draft) CPS 234 Information Security, CPG 234 Management of Security Risk in Information and Information Technology; and CPG 235 Managing Data Risk. This Information Paper applies the concepts included in these standards and guides and APRA intends to reflect the principles in this paper in future guidance updates. For the purpose of this paper, APRA has classified these risks into three broad categories: low, heightened, and extreme.

    • For arrangements with low inherent risk not involving offshoring, APRA would not expect an APRA-regulated entity to consult with APRA prior to entering into the arrangement.
    • For arrangements with heightened risk, APRA would expect to be consulted after the APRA-regulated entity’s internal governance process is completed.
    • For arrangements involving extreme inherent risk, APRA encourages earlier engagement as these arrangements will be subjected to a higher level of scrutiny.

    The new Information Paper updates information on prudential considerations and key principles issued to APRA-regulated entities in July 2015. It has been developed in response to the growing use of the cloud by APRA-regulated entities for higher inherent risk activities and in response to the observed areas of weakness in how entities approach and manage these risks. APRA-regulated entities should note that while this information paper does not constitute formal regulation, APRA intends to incorporate the better practices described in the paper into prudential standards and practice guides in the future. Any such changes will be subject to APRA’s normal processes of consultation. 

     

    Related Links

    Keywords: Asia Pacific, Australia, Banking, Fintech, Cloud Computing, Guidance, APRA

    Related Articles
    News

    EIOPA Report Analyzes Use and Impact of Long-Term Guarantee Measures

    EIOPA submitted—to the European Parliament, the Council of the European Union, and EC—its 2020, fifth, and last annual report on long-term guarantee measures and measures on equity risk.

    December 03, 2020 WebPage Regulatory News
    News

    BIS, SNB, and SIX Announce Successful Completion of CBDC POC

    The BIS Innovation Hub Swiss Centre, SNB, and the financial infrastructure operator SIX announced the successful completion of a joint proof-of-concept (PoC) experiment as part of the Project Helvetia.

    December 03, 2020 WebPage Regulatory News
    News

    EBA Sets Out Treatment of Certain Banking Book Positions Under FRTB

    EBA published the final draft regulatory technical standards for calculation of own funds requirements for market risk, under the standardized and internal model approaches of the Fundamental Review of the Trading Book (FRTB) framework.

    December 03, 2020 WebPage Regulatory News
    News

    EIOPA Consults on Integrating Climate Change into SII Standard Formula

    EIOPA published discussion paper on a methodology for the potential inclusion of climate change in the Solvency II (sometimes also written as SII) standard formula when calculating natural catastrophe underwriting risk.

    December 02, 2020 WebPage Regulatory News
    News

    EU Issues Corrigenda to Investment Firms Directive and Regulation

    EU published, in the Official Journal of the European Union, corrigenda to the Directive and the Regulation on the prudential requirements and supervision of investment firms.

    December 02, 2020 WebPage Regulatory News
    News

    MAS Proposes Changes to Rules Arising from Banking Amendment Act

    MAS proposed amendments to certain regulations, notices, and guidelines arising from the Banking (Amendment) Act 2020.

    December 02, 2020 WebPage Regulatory News
    News

    PRA to Elaborate on Approach to Transposition of CRD5 by Mid-December

    PRA published a statement that explains when to expect further information on the PRA approach to transposing the Capital Requirements Directive (CRD5), including its approach to revisions to the definition of capital for Pillar 2A.

    November 30, 2020 WebPage Regulatory News
    News

    RBNZ Consults on Aspects of Insurance Act, Solvency Standards & IFRS17

    RBNZ launched consultations on the scope of the Insurance Prudential Supervision Act (IPSA) 2010 and on the associated Insurance Solvency Standards.

    November 30, 2020 WebPage Regulatory News
    News

    SRB Sets Out Work Program for 2021-2023

    SRB published the work program for 2021-2023, setting out a roadmap to further operationalize the Single Resolution Fund and to achieve robust resolvability of banks under its remit over the next three years.

    November 30, 2020 WebPage Regulatory News
    News

    EIOPA Consults on KPIs on Sustainability for Non-Financial Reporting

    EIOPA is consulting on the relevant ratios to be mandatorily disclosed by insurers and reinsurers falling within the scope of the Non-Financial Reporting Directive as well as on the methodologies to build these ratios.

    November 30, 2020 WebPage Regulatory News
    RESULTS 1 - 10 OF 6191