Featured Product

    APRA Updates Guidance on Cloud Computing Services

    September 24, 2018

    APRA released updated guidance, in the form of an Information Paper, on the use of shared computing services, such as cloud, by APRA-regulated entities. The new paper acknowledges that advancements in cloud computing service offerings over the past three years have improved the ability of APRA-regulated entities to manage the risks involved. However, it also emphasizes the need for entities to be mindful of the differing levels of responsibility for operating and managing these arrangements.

    This Information Paper is relevant for a broad audience including boards, senior management, risk management, technical specialists, and internal audit. APRA has a number of existing prudential standards and practice guides that are pertinent to cloud computing services. These Prudential Standards and Prudential Practice Guides include CPS 231 Outsourcing; SPS 231 Outsourcing; HPS231 Outsourcing; PPG 231 Outsourcing; SPG 231 Outsourcing; CPS 232 Business Continuity Management; SPS 232 Business Continuity Management; CPG 233 Pandemic Planning; (draft) CPS 234 Information Security, CPG 234 Management of Security Risk in Information and Information Technology; and CPG 235 Managing Data Risk. This Information Paper applies the concepts included in these standards and guides and APRA intends to reflect the principles in this paper in future guidance updates. For the purpose of this paper, APRA has classified these risks into three broad categories: low, heightened, and extreme.

    • For arrangements with low inherent risk not involving offshoring, APRA would not expect an APRA-regulated entity to consult with APRA prior to entering into the arrangement.
    • For arrangements with heightened risk, APRA would expect to be consulted after the APRA-regulated entity’s internal governance process is completed.
    • For arrangements involving extreme inherent risk, APRA encourages earlier engagement as these arrangements will be subjected to a higher level of scrutiny.

    The new Information Paper updates information on prudential considerations and key principles issued to APRA-regulated entities in July 2015. It has been developed in response to the growing use of the cloud by APRA-regulated entities for higher inherent risk activities and in response to the observed areas of weakness in how entities approach and manage these risks. APRA-regulated entities should note that while this information paper does not constitute formal regulation, APRA intends to incorporate the better practices described in the paper into prudential standards and practice guides in the future. Any such changes will be subject to APRA’s normal processes of consultation. 

     

    Related Links

    Keywords: Asia Pacific, Australia, Banking, Fintech, Cloud Computing, Guidance, APRA

    Related Articles
    News

    MAS Amends Notice 610 on Reporting Templates for Banks in Singapore

    MAS published amendments to Notices 610 and 1003 related to submission of statistics and returns, along with the reporting templates and frequently asked questions (FAQs) associated with these Notices.

    January 24, 2020 WebPage Regulatory News
    News

    HKMA Updates Policy Module on Supervisory Review Process

    HKMA is issuing, by notice in the Gazette, revised versions of two Supervisory Policy Manual modules as statutory guidelines under section 7(3) of the Banking Ordinance. The Supervisory Policy Manual modules are CA-G-5 on “Supervisory Review Process” and SB-2 on “Leveraged Foreign Exchange Trading.”

    January 24, 2020 WebPage Regulatory News
    News

    PRA Amends Pillar 2 Capital Framework for Banks

    PRA published the policy statement PS2/20 that contains the final amendments to the Pillar 2 framework and provides feedback to responses to the consultation paper CP5/19 on updates related to Pillar 2 capital framework.

    January 23, 2020 WebPage Regulatory News
    News

    BIS Survey Examines Progress of Central Banks Toward Digital Currency

    BIS published a paper that presents the results of a survey that asked central banks how their plans are developing in the area of central bank digital currency (CBDC).

    January 23, 2020 WebPage Regulatory News
    News

    FED Proposes to Revise Information Collection Under Market Risk Rule

    FED proposed to revise and extend, for three years, FR 4201, which is the information collection under the market risk capital rule.

    January 22, 2020 WebPage Regulatory News
    News

    HKMA Consults on Stay Rules on Financial Contracts Under FIRO

    HKMA published proposals for making rules related to contractual stays on termination rights in financial contracts for authorized institutions under FIRO or the Financial Institutions (Resolution) Ordinance (Cap. 628).

    January 22, 2020 WebPage Regulatory News
    News

    MAS Amends Notices on Minimum Liquid Asset Requirements for Banks

    MAS published amendments to Notices 1015, 613, and 649 related to the minimum liquid assets (MLA) requirements.

    January 21, 2020 WebPage Regulatory News
    News

    APRA Publishes Submission on Fintech and Regtech

    APRA published its submission, to the Senate Select Committee, on financial technology and regulatory technology.

    January 21, 2020 WebPage Regulatory News
    News

    OSFI to Implement Operational Risk Capital Rules for Banks in Q1 2022

    OSFI decided to move domestic implementation of the revised Basel III operational risk capital requirements from the first quarter of 2021 to the first quarter of 2022.

    January 20, 2020 WebPage Regulatory News
    News

    ECB Consults on Guideline on Threshold for Credit Obligations Past Due

    ECB published a draft guideline, along with the frequently asked questions (FAQs), on the definition of the materiality threshold for credit obligations past due for less significant institutions.

    January 20, 2020 WebPage Regulatory News
    RESULTS 1 - 10 OF 4541