Featured Product

    APRA Updates Guidance on Cloud Computing Services

    September 24, 2018

    APRA released updated guidance, in the form of an Information Paper, on the use of shared computing services, such as cloud, by APRA-regulated entities. The new paper acknowledges that advancements in cloud computing service offerings over the past three years have improved the ability of APRA-regulated entities to manage the risks involved. However, it also emphasizes the need for entities to be mindful of the differing levels of responsibility for operating and managing these arrangements.

    This Information Paper is relevant for a broad audience including boards, senior management, risk management, technical specialists, and internal audit. APRA has a number of existing prudential standards and practice guides that are pertinent to cloud computing services. These Prudential Standards and Prudential Practice Guides include CPS 231 Outsourcing; SPS 231 Outsourcing; HPS231 Outsourcing; PPG 231 Outsourcing; SPG 231 Outsourcing; CPS 232 Business Continuity Management; SPS 232 Business Continuity Management; CPG 233 Pandemic Planning; (draft) CPS 234 Information Security, CPG 234 Management of Security Risk in Information and Information Technology; and CPG 235 Managing Data Risk. This Information Paper applies the concepts included in these standards and guides and APRA intends to reflect the principles in this paper in future guidance updates. For the purpose of this paper, APRA has classified these risks into three broad categories: low, heightened, and extreme.

    • For arrangements with low inherent risk not involving offshoring, APRA would not expect an APRA-regulated entity to consult with APRA prior to entering into the arrangement.
    • For arrangements with heightened risk, APRA would expect to be consulted after the APRA-regulated entity’s internal governance process is completed.
    • For arrangements involving extreme inherent risk, APRA encourages earlier engagement as these arrangements will be subjected to a higher level of scrutiny.

    The new Information Paper updates information on prudential considerations and key principles issued to APRA-regulated entities in July 2015. It has been developed in response to the growing use of the cloud by APRA-regulated entities for higher inherent risk activities and in response to the observed areas of weakness in how entities approach and manage these risks. APRA-regulated entities should note that while this information paper does not constitute formal regulation, APRA intends to incorporate the better practices described in the paper into prudential standards and practice guides in the future. Any such changes will be subject to APRA’s normal processes of consultation. 

     

    Related Links

    Keywords: Asia Pacific, Australia, Banking, Fintech, Cloud Computing, Guidance, APRA

    Related Articles
    News

    EBA Updates List of Validation Rules for Reporting by Banks

    EBA issued a revised list of validation rules with respect to the implementing technical standards on supervisory reporting.

    September 10, 2020 WebPage Regulatory News
    News

    EBA Responds to EC Call for Advice to Strengthen AML/CFT Framework

    EBA published its response to the call for advice of EC on ways to strengthen the EU legal framework on anti-money laundering and countering the financing of terrorism (AML/CFT).

    September 10, 2020 WebPage Regulatory News
    News

    NGFS Advocates Environmental Risk Analysis for Financial Sector

    NGFS published a paper on the overview of environmental risk analysis by financial institutions and an occasional paper on the case studies on environmental risk analysis methodologies.

    September 10, 2020 WebPage Regulatory News
    News

    MAS Issues Guidelines to Promote Senior Management Accountability

    MAS published the guidelines on individual accountability and conduct at financial institutions.

    September 10, 2020 WebPage Regulatory News
    News

    APRA Formalizes Capital Treatment and Reporting of COVID-19 Loans

    APRA published final versions of the prudential standard APS 220 on credit quality and the reporting standard ARS 923.2 on repayment deferrals.

    September 09, 2020 WebPage Regulatory News
    News

    SRB Chair Discusses Path to Harmonized Liquidation Regime for Banks

    SRB published two articles, with one article discussing the framework in place to safeguard financial stability amid crisis and the other article outlining the path to a harmonized and predictable liquidation regime.

    September 09, 2020 WebPage Regulatory News
    News

    FSB Workshop Discusses Preliminary Findings of Too-Big-To-Fail Reforms

    FSB hosted a virtual workshop as part of the consultation process for its evaluation of the too-big-to-fail reforms.

    September 09, 2020 WebPage Regulatory News
    News

    ECB Updates List of Supervised Entities in EU in September 2020

    ECB updated the list of supervised entities in EU, with the number of significant supervised entities being 115.

    September 08, 2020 WebPage Regulatory News
    News

    OSFI Identifies Focus Areas to Strengthen Third-Party Risk Management

    OSFI published the key findings of a study on third-party risk management.

    September 08, 2020 WebPage Regulatory News
    News

    FSB Extends Implementation Timeline for Framework on SFTs

    FSB is extending the implementation timeline, by one year, for the minimum haircut standards for non-centrally cleared securities financing transactions or SFTs.

    September 07, 2020 WebPage Regulatory News
    RESULTS 1 - 10 OF 5796