Featured Product

    BoM Revises Guideline on Outsourcing by Financial Institutions

    October 13, 2020

    BoM revised the guideline setting out a broad framework for financial institutions that have entered into outsourcing or are planning to outsource their business activities to service providers. The guideline covers risk management framework in outsourcing, evaluation of risks involved in outsourcing, classification of outsourcing activities, and the use of cloud-based services by financial institutions. This guideline is applicable to all financial institutions falling under the regulatory purview of BoM.

    The guideline is based on a three-tier classification of activities: material activities that require authorization, non-material activities that do not require authorization, and core activities that cannot be outsourced. BoM considers cloud-based services operated by service providers as a form of outsourcing and recognizes that financial institutions may have recourse to such services to enhance their operations and service efficiency. The usage of cloud-based services by financial institutions shall be restricted to non-core activities only. Financial institutions are required to take appropriate measures with respect to data access, confidentiality, integrity, sovereignty, recoverability, regulatory compliance, and auditing. They should ensure that the service providers have the capacity to identify and segregate customer data using strong physical or logical controls. As per the guideline, financial institutions are ultimately responsible and accountable for maintaining oversight of cloud-based services and managing the attendant risks of adopting cloud-based services, as in any other form of outsourcing arrangement.

    Financial institutions should conduct an assessment of all their existing outsourcing arrangements against this guideline. Where the outsourcing is considered material, financial institutions should inform BoM in writing about the level of compliance with the guideline and report weaknesses, if any. Institutions should also submit a plan and timeframe on how such weaknesses would be rectified. This should be done within four months from when the guideline becomes effective. Financial institutions should annually submit to BoM a Return on Outsourced Activities, containing a list of all material and non-material activities that have been outsourced, in such form and manner prescribed by BoM. This return should be submitted within the next twenty working days of the previous calendar year. The guideline follows the high-level principles on outsourcing in financial services, developed by the Joint Forum comprising BCBS, IOSCO, and IAIS.

     

    Related Links

    Keywords: Middle East and Africa, Mauritius, Banking, Outsourcing, Cloud Computing, Regtech, BoM

    Related Articles
    News

    EBA Proposes Standards for IRRBB Reporting Under Basel Framework

    The European Banking Authority (EBA) proposed implementing technical standards on the interest rate risk in the banking book (IRRBB) reporting requirements, with the comment period ending on May 02, 2023.

    January 31, 2023 WebPage Regulatory News
    News

    FED Issues Further Details on Pilot Climate Scenario Analysis Exercise

    The U.S. Federal Reserve Board (FED) set out details of the pilot climate scenario analysis exercise to be conducted among the six largest U.S. bank holding companies.

    January 17, 2023 WebPage Regulatory News
    News

    US Agencies Issue Several Regulatory and Reporting Updates

    The Board of Governors of the Federal Reserve System (FED) adopted the final rule on Adjustable Interest Rate (LIBOR) Act.

    January 04, 2023 WebPage Regulatory News
    News

    ECB Issues Multiple Reports and Regulatory Updates for Banks

    The European Central Bank (ECB) published an updated list of supervised entities, a report on the supervision of less significant institutions (LSIs), a statement on macro-prudential policy.

    January 01, 2023 WebPage Regulatory News
    News

    HKMA Keeps List of D-SIBs Unchanged, Makes Other Announcements

    The Hong Kong Monetary Authority (HKMA) published a circular on the prudential treatment of crypto-asset exposures, an update on the status of transition to new interest rate benchmarks.

    December 30, 2022 WebPage Regulatory News
    News

    EU Issues FAQs on Taxonomy Regulation, Rules Under CRD, FICOD and SFDR

    The European Commission (EC) adopted the standards addressing supervisory reporting of risk concentrations and intra-group transactions, benchmarking of internal approaches, and authorization of credit institutions.

    December 29, 2022 WebPage Regulatory News
    News

    CBIRC Revises Measures on Corporate Governance Supervision

    The China Banking and Insurance Regulatory Commission (CBIRC) issued rules to manage the risk of off-balance sheet business of commercial banks and rules on corporate governance of financial institutions.

    December 29, 2022 WebPage Regulatory News
    News

    HKMA Publications Address Sustainability Issues in Financial Sector

    The Hong Kong Monetary Authority (HKMA) made announcements to address sustainability issues in the financial sector.

    December 23, 2022 WebPage Regulatory News
    News

    EBA Updates Address Basel and NPL Requirements for Banks

    The European Banking Authority (EBA) published regulatory standards on identification of a group of connected clients (GCC) as well as updated the lists of identified financial conglomerates.

    December 22, 2022 WebPage Regulatory News
    News

    ESMA Publishes 2022 ESEF XBRL Taxonomy and Conformance Suite

    The General Board of the European Systemic Risk Board (ESRB), at its December meeting, issued an updated risk assessment via the quarterly risk dashboard and held discussions on key policy priorities to address the systemic risks in the European Union.

    December 22, 2022 WebPage Regulatory News
    RESULTS 1 - 10 OF 8699