EBA欧洲银行-State-street-EBA-ConsultationDraft-Guidelines-on-Outsourcing-Arrangements_8页_327kb
报告摘要
EBA Consultation: Draft Guidelines on Outsourcing Arrangements - Summary
Core Content
The European Banking Authority (EBA) published a consultation on draft guidelines regarding outsourcing arrangements in the financial sector. State Street Corporation, a major global provider of financial services to institutional investors, has provided detailed comments on the proposed guidelines. The main focus of the feedback is to ensure that the guidelines are proportionate, clear, and flexible, particularly in relation to the application of requirements to different types of outsourcing arrangements, including intra-group and external outsourcing.
Main Views and Key Recommendations
Proportionality and Flexibility
- The proposed guidelines are perceived as overly prescriptive, lacking the flexibility needed for proportionate application.
- State Street recommends distinguishing between regulatory requirements and guidance to allow institutions to tailor their compliance efforts based on the risk and criticality of each outsourcing arrangement.
- The guidelines should allow for minor differences between internal and external outsourcing, particularly in terms of data collection and recertification.
Supervisory Cooperation and Jurisdictional Issues
- The current requirement for institutions to ensure cooperation agreements between supervisory authorities is impractical.
- State Street suggests that local supervisory authorities should maintain and issue lists of appropriate jurisdictions for outsourcing, rather than requiring institutions to make these determinations themselves.
- There is concern that the guidelines may force firms to use third-party providers in jurisdictions that restrict access to financial information, potentially leading to compliance issues. An exception mechanism should be introduced in collaboration with national competent authorities.
Definitions and Criticality of Functions
- The definition of "critical or important function" should be left to the discretion of the institution, as not all tasks performed by internal control functions are of equal risk significance.
- State Street emphasizes that the final guidelines should clarify that the determination of whether a function is critical or important is a matter for the institution itself, not a regulatory mandate.
Audit Rights and Risk Assessment
- The guidelines should clarify that audit rights are the responsibility of the outsourcing arrangement owner, not the corporate audit function, to avoid conflicts of interest.
- The assessment of a service provider’s risk appetite and control procedures should be the responsibility of the outsourcing arrangement owner, not the corporate audit function.
- The requirement for unrestricted access and audit rights is not realistic and should be balanced with confidentiality and privacy concerns.
Documentation and Registers
- The outsourcing register should be flexible, allowing institutions to capture data equivalent to what is outlined in the guidelines, without being overly prescriptive.
- State Street supports the idea of providing the full register to competent authorities but recommends that institutions only disclose critical or important functions unless specifically requested.
- Data on sub-service providers should only be required for critical or important functions or those under GDPR, to avoid unnecessary administrative burden.
Sub-Outsourcing and Exit Strategies
- Sub-outsourcing requirements should be linked to the materiality of the risk and the criticality of the function.
- Exit strategies should be calibrated based on whether the provider is internal or external, and the level of risk involved.
Legal and Practical Challenges
- There are concerns about the legal feasibility of requiring direct audit rights over sub-outsourcing providers, especially when these providers are not subject to the same regulatory oversight.
- The use of pooled auditors in intra-group outsourcing should be clarified, including whether they are applicable to internal providers only.
Conclusion
State Street Corporation advocates for a more proportionate and flexible approach to the drafting of the EBA's outsourcing guidelines. They emphasize the need for clear distinctions between regulatory mandates and guidance, the importance of local supervisory authority oversight, and the necessity of allowing exceptions in specific jurisdictions. Additionally, they recommend that audit rights and documentation requirements be aligned with the criticality of the function being outsourced to avoid unnecessary burdens on financial institutions.
试读结束,高清完整版pdf/doc/ppt,请点下载