Featured Product

    AMF Publishes Guideline on ICT Risk Management

    February 27, 2020

    AMF published the guideline on information and communications technology (ICT) risk management. The guideline takes into account developments in ICT risk management and reflects observations made by AMF in the course of its supervisory activities in relation to the financial institutions concerned. The effective date of this guideline is February 27, 2020. With respect to the legal obligation imposed on the institutions to follow sound and prudent management practices, AMF expects each institution to adopt the principles of this guideline by developing strategies, policies, and procedures commensurate with its nature, scale, complexity, and risk profile.

    The guideline is intended for authorized insurers, federations of mutual companies, financial services cooperatives, and legal persons belonging to a cooperative group, authorized trust companies, savings companies, and certain other deposit institutions. It describes the expectations of AMF with respect to ICT risk. The ultimate goal of these expectations is to strengthen the financial sector’s resilience in response to the risk of data being lost, leaked, stolen, corrupted, or accessed without authorization. These expectations are intended to ensure the development of appropriate security hygiene through the implementation of measures that will help prevent a major incident and limit its impact.

    Each institution is responsible for clearly understanding all its ICT risks and ensuring that they are appropriately considered in light of the institution’s nature, size, complexity, and risk profile. AMF is also responsible for staying current on the best practices in ICT risk management and adopting them to the extent that they meet its needs. The standards or policies adopted by a federation with respect to financial services cooperatives and mutual insurance associations that are members of the federation should be consistent, if not convergent, with the principles of sound and prudent management set down in legislation and clarified in this guideline.

     

    Effective Date: February 27, 2020

    Keywords: Americas, Canada, Banking, Insurance, Guideline, ICT, Cyber Risk, Data Protection, AMF

    Related Articles
    News

    ESAs Issue Multiple Regulatory Updates for Financial Sector Entities

    The three European Supervisory Authorities (ESAs) issued a letter to inform about delay in the Sustainable Finance Disclosure Regulation (SFDR) mandate, along with a Call for Evidence on greenwashing practices.

    November 15, 2022 WebPage Regulatory News
    News

    ISSB Makes Announcements at COP27; IASB to Propose IFRS 9 Amendments

    The International Sustainability Standards Board (ISSB) of the IFRS Foundations made several announcements at COP27 and with respect to its work on the sustainability standards.

    November 10, 2022 WebPage Regulatory News
    News

    IOSCO Prioritizes Green Disclosures, Greenwashing, and Carbon Markets

    The International Organization for Securities Commissions (IOSCO), at COP27, outlined the regulatory priorities for sustainability disclosures, mitigation of greenwashing, and promotion of integrity in carbon markets.

    November 09, 2022 WebPage Regulatory News
    News

    EBA Finalizes Methodology for Stress Tests, Issues Other Updates

    The European Banking Authority (EBA) issued a statement in the context of COP27, clarified the operationalization of intermediate EU parent undertakings (IPUs) of third-country groups

    November 09, 2022 WebPage Regulatory News
    News

    OSFI Sets Out Work Priorities and Reporting Updates for Banks

    The Office of the Superintendent of Financial Institutions (OSFI) published an annual report on its activities, a report on forward-looking work.

    November 07, 2022 WebPage Regulatory News
    News

    APRA Finalizes Changes to Capital Framework, Issues Other Updates

    The Australian Prudential Regulation Authority (APRA) finalized amendments to the capital framework, announced a review of the prudential framework for groups.

    November 03, 2022 WebPage Regulatory News
    News

    BIS Hub and Central Banks Conduct CBDC and DeFI Pilots

    The Bank for International Settlements (BIS) Innovation Hubs and several central banks are working together on various central bank digital currency (CBDC) pilots.

    November 03, 2022 WebPage Regulatory News
    News

    ECB Sets Deadline for Banks to Meet Its Climate Risk Expectations

    The European Central Bank (ECB) published the results of its thematic review, which shows that banks are still far from adequately managing climate and environmental risks.

    November 02, 2022 WebPage Regulatory News
    News

    ESAs, ECB, & EC Issue Multiple Regulatory Updates for Financial Sector

    Among its recent publications, the European Banking Authority (EBA) published the final standards and guidelines on interest rate risk arising from non-trading book activities (IRRBB)

    October 31, 2022 WebPage Regulatory News
    News

    EC Adopts Final Rules Under CRR, BRRD, and Crowdfunding Regulation

    The European Commission (EC) recently adopted regulations with respect to the calculation of own funds requirements for market risk, the prudential treatment of global systemically important institutions (G-SIIs)

    October 26, 2022 WebPage Regulatory News
    RESULTS 1 - 10 OF 8582