RBNZ launched consultation on the guidance for what regulated entities should consider when managing cyber resilience. The draft guidance, which is open for feedback until January 29, 2021, outlines the expectations of RBNZ around cyber resilience and draws heavily from leading international and national cybersecurity standards and guidelines. RBNZ will publish a summary of submissions and final guidance in March or April 2021. RBNZ is also developing a detailed framework for information gathering and sharing, for which it plans to consult stakeholders in mid-2021.
The guidance has four parts—namely, governance, capability building, information sharing, and third-party management. Third-party management is an area of growing importance and the guidance includes a special subsection on the use of cloud computing services in light of the rapid adoption of cloud services by financial sector firms. The guidance is aligned with international standard and guidelines on cyber resilience and provides a set of high-level principle-based recommendations. The draft cyber risk management guidance would apply to all entities RBNZ regulates. This includes registered banks, licensed non-bank deposit-takers, licensed insurers, and designated financial market infrastructures. The consultation paper also seeks feedback on how information gathering and sharing by RBNZ with relevant public-sector bodies can help to build cyber resilience.
The consultation paper discusses views of RBNZ on a collaborative approach to information gathering and sharing. In the multi-agency landscape, RBNZ plans to promote information gathering and sharing with other relevant government agencies (for example, National Cyber Security Center, Computer Emergent Response Team NZ, and the Financial Market Authority). RBNZ considers that there are merits in following the broad pattern observed in the international practices of establishing a cyber data collection. As a principle, RBNZ will tailor reporting requirements to ensure they stay relevant and minimize the reporting burden. At a very high level, this includes:
- A regular but fairly infrequent data collection (perhaps annually or once every few years) on cyber capabilities and resources dedicated to building cyber resilience
- Establishing an obligation to report cyber incidents to the prudential authority, perhaps with a materiality threshold for reporting incidents as soon as reasonable after they are detected
- An information collection plan that is applicable to all regulated entities of RBNZ
Keywords: Asia Pacific, New Zealand, Banking, Insurance, PMI, Guidance, Cyber Risk, Operational Risk, Cloud Computing, RBNZ
PRA published a statement that explains when to expect further information on the PRA approach to transposing the Capital Requirements Directive (CRD5), including its approach to revisions to the definition of capital for Pillar 2A.
SRB published the work program for 2021-2023, setting out a roadmap to further operationalize the Single Resolution Fund and to achieve robust resolvability of banks under its remit over the next three years.
EIOPA is consulting on the relevant ratios to be mandatorily disclosed by insurers and reinsurers falling within the scope of the Non-Financial Reporting Directive as well as on the methodologies to build these ratios.
ECB finalized guidance on the way it expects banks to prudently manage and transparently disclose climate and other environmental risks under the current prudential rules.
BCBS published a technical amendment to the capital treatment of securitizations of non-performing loans by banks.
BoE announced that the Data and Statistics Division is planning to move collection of statistical data to the BoE Electronic Data Submission (BEEDS) portal.
APRA published the updated reporting standards and guidance for the collection of Economic and Financial Statistics (EFS), following a consultation process. Also published was a response letter to the feedback received on the proposal for amending the EFS reporting standards and guidance.
EC is consulting on a draft delegated regulation to supplement the Taxonomy Regulation (2020/852) by establishing the technical screening criteria for determining the conditions under which an economic activity qualifies as environmentally sustainable.
The IFRS Foundation published material highlighting the ways in which existing requirements in IFRS standards require companies to consider climate-related matters when their effect is material to the financial statements.
FSB published a progress report on the implementation of reforms to major interest rate benchmarks, including the London Inter-bank Offered Rate (LIBOR) benchmark.