EBA revised its guidelines on outsourcing arrangements for financial institutions, including credit institutions and investment firms subject to the Capital Requirements Directive (CRD) as well as payment and electronic money institutions. The guidelines cover information technology outsourcing, including fintech and outsourcing to cloud service providers. The guidelines will enter into force on September 30, 2019.
The guidelines set out specific provisions for the governance frameworks of all financial institutions within the scope of the EBA mandate with regard to their outsourcing arrangements and related supervisory expectations and processes. They clarify that the management body of each financial institution remains responsible for that institution and its activities at all times. Outsourcing must not lead to a situation in which an institution becomes an "empty shell" that lacks the substance to remain authorized. Additionally, the guidelines specify which arrangements with third parties are to be considered as outsourcing. The guidelines differentiate between requirements on critical and important outsourcing arrangements and other outsourcing arrangements. Outsourcing of critical and important functions has a higher impact on the institutions' and payment institutions' risk profile. Hence, the requirements for such functions are stricter compared to the requirements for other less risky outsourcing arrangements.
The guidelines aim to established a harmonized framework aimed to ensure that institutions can apply a single framework on outsourcing for all their banking, investment, and payment activities and services. Such a framework also ensures a level playing field between different types of financial institutions. These guidelines replace the 2006 guidelines on outsourcing while the recommendation on outsourcing to cloud service providers, which was published in December 2017, has been integrated into these guidelines.
Effective Date: September 30, 2019
Keywords: Europe, EU, Banking, Fintech, Outsourcing Arrangements, Cloud Outsourcing, Proportionality, EBA
The Australian Prudential Regulation Authority (APRA) published a new set of frequently asked questions (FAQs) to clarify the regulatory capital treatment of investments in the overseas deposit-taking and insurance subsidiaries.
The Prudential Regulation Authority (PRA) issued the policy statement PS20/21, which contains final rules for the application of existing consolidated prudential requirements to financial holding companies and mixed financial holding companies.
The European Banking Authority (EBA) published the final report on the guidelines specifying the criteria to assess the exceptional cases when institutions exceed the large exposure limits and the time and measures needed for institutions to return to compliance.
The European Banking Authority (EBA) revised the guidelines on stress tests to be conducted by the national deposit guarantee schemes under the Deposit Guarantee Schemes Directive (DGSD).
The Hong Kong Monetary Authority (HKMA) issued a circular, for all authorized institutions, to confirm its support of an information note that sets out various options available in the loan market for replacing USD LIBOR with the Secured Overnight Financing Rate (SOFR).
The Office of the Comptroller of the Currency (OCC) issued a new "Problem Bank Supervision" booklet of the Comptroller's Handbook. The booklet covers information on timely identification and rehabilitation of problem banks and their advanced supervision, enforcement, and resolution when conditions warrant.
The Monetary Authority of Singapore (MAS) launched a consultation on the standards for market risk capital and the associated reporting requirements for banks incorporated in Singapore.
The tech lab of the Federal Deposit Insurance Corporation (FDIC) selected three winning teams in a tech sprint designed to explore new technologies and techniques to help banks meet the needs of unbanked consumers.
PRA published a "Dear CEO" letter that sets out findings of a review on the reliability of regulatory reporting and reiterates the supervisory expectations on regulatory reporting.
The Australian Prudential Regulation Authority (APRA) confirmed that its new data collection solution APRA Connect will go live on September 13, 2021.