Featured Product

    RBNZ Consults on Guidance for Managing Cyber Risks

    October 20, 2020

    RBNZ launched consultation on the guidance for what regulated entities should consider when managing cyber resilience. The draft guidance, which is open for feedback until January 29, 2021, outlines the expectations of RBNZ around cyber resilience and draws heavily from leading international and national cybersecurity standards and guidelines. RBNZ will publish a summary of submissions and final guidance in March or April 2021. RBNZ is also developing a detailed framework for information gathering and sharing, for which it plans to consult stakeholders in mid-2021.

    The guidance has four parts—namely, governance, capability building, information sharing, and third-party management. Third-party management is an area of growing importance and the guidance includes a special subsection on the use of cloud computing services in light of the rapid adoption of cloud services by financial sector firms. The guidance is aligned with international standard and guidelines on cyber resilience and provides a set of high-level principle-based recommendations. The draft cyber risk management guidance would apply to all entities RBNZ regulates. This includes registered banks, licensed non-bank deposit-takers, licensed insurers, and designated financial market infrastructures. The consultation paper also seeks feedback on how information gathering and sharing by RBNZ with relevant public-sector bodies can help to build cyber resilience.

    The consultation paper discusses views of RBNZ on a collaborative approach to information gathering and sharing. In the multi-agency landscape, RBNZ plans to promote information gathering and sharing with other relevant government agencies (for example, National Cyber Security Center, Computer Emergent Response Team NZ, and the Financial Market Authority). RBNZ considers that there are merits in following the broad pattern observed in the international practices of establishing a cyber data collection. As a principle, RBNZ will tailor reporting requirements to ensure they stay relevant and minimize the reporting burden. At a very high level, this includes: 

    • A regular but fairly infrequent data collection (perhaps annually or once every few years) on cyber capabilities and resources dedicated to building cyber resilience
    • Establishing an obligation to report cyber incidents to the prudential authority, perhaps with a materiality threshold for reporting incidents as soon as reasonable after they are detected
    • An information collection plan that is applicable to all regulated entities of RBNZ


    Related Links

    Keywords: Asia Pacific, New Zealand, Banking, Insurance, PMI, Guidance, Cyber Risk, Operational Risk, Cloud Computing, RBNZ

    Related Articles

    EBA Finalizes Templates for One-Off Climate Risk Scenario Analysis

    The European Banking Authority (EBA) has published the final templates, and the associated guidance, for collecting climate-related data for the one-off Fit-for-55 climate risk scenario analysis.

    November 28, 2023 WebPage Regulatory News

    EBA Mulls Inclusion of Environmental & Social Risks to Pillar 1 Rules

    The European Banking Authority (EBA) recently published a report that recommends enhancements to the Pillar 1 framework, under the prudential rules, to capture environmental and social risks.

    October 31, 2023 WebPage Regulatory News

    BCBS Consults on Disclosure of Crypto-Asset Exposures of Banks

    As a follow on from its prudential standard on the treatment of crypto-asset exposures, the Basel Committee on Banking Supervision (BCBS) proposed disclosure requirements for crypto-asset exposures of banks.

    October 19, 2023 WebPage Regulatory News

    BCBS and EBA Publish Results of Basel III Monitoring Exercise

    The Basel Committee on Banking Supervision (BCBS) and the European Banking Authority (EBA) have published results of the Basel III monitoring exercise.

    October 18, 2023 WebPage Regulatory News

    PRA Updates Timeline for Final Basel III Rules, Issues Other Updates

    The Prudential Regulation Authority (PRA) recently issued a few regulatory updates for banks, with the updated Basel implementation timelines being the key among them.

    October 18, 2023 WebPage Regulatory News

    US Treasury Sets Out Principles for Net-Zero Financing

    The U.S. Department of the Treasury has recently set out the principles for net-zero financing and investment.

    October 17, 2023 WebPage Regulatory News

    EC Launches Survey on G7 Principles on Generative AI

    The European Commission (EC) launched a stakeholder survey on the draft International Guiding Principles for organizations developing advanced artificial intelligence (AI) systems.

    October 14, 2023 WebPage Regulatory News

    ISSB Sustainability Standards Expected to Become Global Baseline

    The finalization of the two sustainability disclosure standards—IFRS S1 and IFRS S2—is expected to be a significant step forward in the harmonization of sustainability disclosures worldwide.

    September 18, 2023 WebPage Regulatory News

    IOSCO, BIS, and FSB to Intensify Focus on Decentralized Finance

    Decentralized finance (DeFi) is expected to increase in prominence, finding traction in use cases such as lending, trading, and investing, without the intermediation of traditional financial institutions.

    September 18, 2023 WebPage Regulatory News

    BCBS Assesses NSFR and Large Exposures Rules in US

    The Basel Committee on Banking Supervision (BCBS) published reports that assessed the overall implementation of the net stable funding ratio (NSFR) and the large exposures rules in the U.S.

    September 14, 2023 WebPage Regulatory News
    RESULTS 1 - 10 OF 8938