EBA revised its guidelines on outsourcing arrangements for financial institutions, including credit institutions and investment firms subject to the Capital Requirements Directive (CRD) as well as payment and electronic money institutions. The guidelines cover information technology outsourcing, including fintech and outsourcing to cloud service providers. The guidelines will enter into force on September 30, 2019.
The guidelines set out specific provisions for the governance frameworks of all financial institutions within the scope of the EBA mandate with regard to their outsourcing arrangements and related supervisory expectations and processes. They clarify that the management body of each financial institution remains responsible for that institution and its activities at all times. Outsourcing must not lead to a situation in which an institution becomes an "empty shell" that lacks the substance to remain authorized. Additionally, the guidelines specify which arrangements with third parties are to be considered as outsourcing. The guidelines differentiate between requirements on critical and important outsourcing arrangements and other outsourcing arrangements. Outsourcing of critical and important functions has a higher impact on the institutions' and payment institutions' risk profile. Hence, the requirements for such functions are stricter compared to the requirements for other less risky outsourcing arrangements.
The guidelines aim to established a harmonized framework aimed to ensure that institutions can apply a single framework on outsourcing for all their banking, investment, and payment activities and services. Such a framework also ensures a level playing field between different types of financial institutions. These guidelines replace the 2006 guidelines on outsourcing while the recommendation on outsourcing to cloud service providers, which was published in December 2017, has been integrated into these guidelines.
Effective Date: September 30, 2019
Keywords: Europe, EU, Banking, Fintech, Outsourcing Arrangements, Cloud Outsourcing, Proportionality, EBA
Previous ArticleEC Welcomes Agreement on New Generation of Low-Carbon Benchmarks
Next ArticleEIOPA Publishes Q&A on Regulations in February 2019
APRA announced the standardization of quarterly reporting due dates for authorized deposit-taking institutions.
Bundesbank published a list of "EntryPoints" that are accepted in its reporting system; the list provides taxonomy version and name of the module against each EntryPoint.
The private sector working group of ECB on euro risk-free rates published the recommendations to address events that would trigger fallbacks in the Euro Interbank Offered Rate (EURIBOR)-related contracts, along with the €STR-based EURIBOR fallback rates (rates that could be used if a fallback is triggered).
EBA published the phase 1 of its reporting framework 3.1, with the technical package covering the new reporting requirements for investment firms (under the implementing technical standards on investment firms reporting).
Asia Pacific Australia Banking APS 111 Capital Adequacy Regulatory Capital Basel RBNZ APRA
ESMA published the final guidelines on outsourcing to cloud service providers.
EBA published annual data for two key concepts and indicators in the Deposit Guarantee Schemes (DGS) Directive—available financial means and covered deposits.
OSFI has set out the schedule for release of draft guidance on the management of technology risks by federally regulated financial institutions and private pension plans.
MAS updated rules for new housing loans by banks and finance companies.
HKMA published a statement on the 100% Personal Loan Guarantee Scheme and a guideline on the Green and Sustainable Finance Grant Scheme (GSF Grant Scheme) as announced in the 2021-22 Budget.