At the 2018 Curious Thinkers Conference in Sydney, the APRA Chairman Wayne Byres examined the potential impact of financial technologies on the financial sector. In this context, he believes that the task of APRA is to ensure that regulated entities are adequately managing change and not exposing customers to undue risks. APRA should also ensure that regulation and supervision are fit for the future and can adapt as the financial system and its participants evolve.
APRA Chair revealed that an APRA review of the systems hygiene in the banking sector, suggested that the issues identified reflect persistent underinvestment over a number of years. The reviews emphasize that, to facilitate new technology, investment budgets need to be increased, not just reprioritized. APRA released its first information security prudential standard for consultation in March and it wants cyber-soundness to be thought about in the same way as institutions think about financial soundness. Additionally, in the area of cloud computing, APRA released an updated version of its 2015 paper, which acknowledges advancements in the safety and security in using the cloud, along with the increased appetite for doing so, especially among new and aspiring entities that want to take a cloud-first approach to data storage and management. In addition to reinforcing steps to minimize the risks of cloud usage, the information paper also summarizes observed weaknesses that industry must continue to focus on. While cloud usage, as with all other shared service arrangements, involves a degree of shared responsibility, boards and senior management of regulated entities remain ultimately accountable for the security of their data. That accountability cannot be outsourced.
A major challenge that technology poses for regulators is the growing trend toward outsourcing and partnering, according to Mr. Byres. Outsourcing and partnering is increasingly occurring for business-critical functions, not just at the periphery of activities. Many of these new partners and providers of critical functions sit outside regulators’ reach. The prudential supervisors’ ability to “kick the tyres” will be much harder in future, without new tools and methods. This gives rise to the systemic risk of an ostensibly large and diverse number of entities all dependent on just a few unregulated providers for critical services, creating a substantial concentration risk and increasing the threat of contagion in the event of a service failure. Applicants for new banking licenses may not fit the traditional mold and that is another risk posed by technology. Consequently, APRA has established a new licensing regime to provide for easier entry—but not lower standards—to the banking system for applicants with unconventional or non-traditional business models. The goal of the new Restricted Authorized Deposit-taking Institution regime is to allow applicants to commence limited banking business while still developing their capabilities and resources. It also allows APRA to learn about, and gain comfort with, new ways of doing things.
APRA is increasing effort to ensure that it has the expertise, knowledge, and technology in place to monitor and interpret the changing nature of the financial sector. APRA has established an internal Fintech Council to examine developments and trends in the fintech sector. Guided by the Council, APRA has stepped up the engagement with a range of players from outside the regulated sphere, such as Fintech Australia, the RegTech Association, and InsureTech Australia. The purpose of this engagement is to create a dialog with players in these emerging sectors to ensure APRA is up-to-speed with developments and to keep ahead of emerging issues that may cause regulatory challenges. He also welcomed the valuable insights gained from participating in ASIC’s Digital Finance Advisory Committee. Finally, he said that one of APRA’s key strategic priorities over the coming years is to broaden its risk-based supervision.
Related Link: Speech
Previous ArticleAPRA Consults on Regulatory Framework for Stored-Value Facilities
Next ArticleBIS Publishes the Quarterly Review in September 2018
HM Treasury announced that the new Financial Services Bill has been introduced in the Parliament.
PRA published the consultation paper CP17/20 to propose changes to certain rules, supervisory statements, and statements of policy to implement elements of the Capital Requirements Directive (CRD5).
US Agencies adopted a final rule that applies to advanced approaches banking organizations and aims to reduce interconnectedness in the financial system as well as to reduce contagion risks associated with the failure of a global systemically important bank (G-SIB).
US Agencies (FDIC, FED, and OCC) adopted a final rule that implements the net stable funding ratio (NSFR) for certain large banking organizations.
FSB finalized the toolkit of effective practices to assist financial institutions in their cyber incident response and recovery activities.
ECB published eleventh issue of the Macroprudential Bulletin, which provides insight into the ongoing work of ECB in the field of macro-prudential policy.
HM Treasury issued a call for evidence seeking views to reform the prudential regulatory regime—also known as Solvency II—of the insurance sector in UK.
ESRB responded to the EC consultation on review of Solvency II regime.
HM Treasury launched a consultation on Phase II of the Future Regulatory Framework Review, with the comment period ending on January 19, 2021.
EC adopted the work program for 2021.