EBA revised its guidelines on outsourcing arrangements for financial institutions, including credit institutions and investment firms subject to the Capital Requirements Directive (CRD) as well as payment and electronic money institutions. The guidelines cover information technology outsourcing, including fintech and outsourcing to cloud service providers. The guidelines will enter into force on September 30, 2019.
The guidelines set out specific provisions for the governance frameworks of all financial institutions within the scope of the EBA mandate with regard to their outsourcing arrangements and related supervisory expectations and processes. They clarify that the management body of each financial institution remains responsible for that institution and its activities at all times. Outsourcing must not lead to a situation in which an institution becomes an "empty shell" that lacks the substance to remain authorized. Additionally, the guidelines specify which arrangements with third parties are to be considered as outsourcing. The guidelines differentiate between requirements on critical and important outsourcing arrangements and other outsourcing arrangements. Outsourcing of critical and important functions has a higher impact on the institutions' and payment institutions' risk profile. Hence, the requirements for such functions are stricter compared to the requirements for other less risky outsourcing arrangements.
The guidelines aim to established a harmonized framework aimed to ensure that institutions can apply a single framework on outsourcing for all their banking, investment, and payment activities and services. Such a framework also ensures a level playing field between different types of financial institutions. These guidelines replace the 2006 guidelines on outsourcing while the recommendation on outsourcing to cloud service providers, which was published in December 2017, has been integrated into these guidelines.
Effective Date: September 30, 2019
Keywords: Europe, EU, Banking, Fintech, Outsourcing Arrangements, Cloud Outsourcing, Proportionality, EBA
The European Commission (EC) published the Delegated Regulation 2022/786 with regard to the liquidity coverage requirements for credit institutions under the Capital Requirements Regulation (CRR).
The European Banking Authority (EBA) published the final draft regulatory technical standards specifying the criteria to identify shadow banking entities for the purposes of reporting large exposures.
The European Insurance and Occupational Pensions Authority (EIOPA) published a report assessing insurers' exposure to physical climate change risks
The European Commission (EC) published the results of a public consultation, held in October 2021, on the review of the Web Accessibility Directive.
The Network for Greening the Financial System (NGFS) published two reports to aid central banks and regulators in their oversight of the financial sector and in their central bank operations
The Monetary Authority of Singapore (MAS) and the SC-STS are jointly consulting, until June 10, 2022, on setting adjustment spreads for the conversion of legacy SOR contracts to SORA reference rate.
The Office of the Superintendent of Financial Institutions (OSFI) published the strategic plan for 2022-2025 and the departmental plan for 2022-23.
The European Banking Authority (EBA) is consulting, until August 31, 2022, on the draft implementing technical standards specifying requirements for the information that sellers of non-performing loans (NPLs) shall provide to prospective buyers.
The European Council and the Parliament reached an agreement on the revised Directive on security of network and information systems (NIS2 Directive).
The European Banking Authority (EBA) published the final draft regulatory technical standards specifying information that crowdfunding service providers shall provide to investors on the calculation of credit scores and prices of crowdfunding offers.