2016年-SWIFT环球同业银行金融电讯_CPSS-IOSCO039S_Principles_for_Financial_Market_Infrastructures_FMIs_10页_760kb
报告摘要
Summary of Document Content
Core Content
This document outlines the importance of consistent and objective assurance for Critical Service Providers (CSPs) within Financial Market Infrastructures (FMIs). It emphasizes the need for enhanced compliance and risk management practices in response to new regulatory principles introduced by CPSS-IOSCO. The document also highlights SWIFT's commitment to meeting these standards and proposes a common assurance framework for CSPs based on international standards, such as ISAE 3000, to ensure transparency, efficiency, and comparability across the industry.
Main Views
- FMIs and CSPs are central to the stability of the global financial system, and their compliance with risk management and operational standards is essential.
- CPSS-IOSCO has raised the bar for compliance by introducing 24 Principles for FMIs, which apply to various types of FMIs and their CSPs.
- SWIFT, as a key CSP, has already demonstrated compliance with the Expectations for CSPs outlined in Annex F of the CPSS-IOSCO Principles.
- SWIFT proposes a scalable, cost-efficient, and coherent assurance framework that includes external independent validation to ensure uniformity and transparency across the industry.
- A single, uniform assurance methodology will benefit all stakeholders – FMIs, CSPs, and regulators – by promoting a common standard and enabling comparative analysis of CSP performance.
Key Information
CPSS-IOSCO Principles for FMIs
- The Principles include 24 broad governance, business, and operational standards.
- They are intended to be adopted by CPSS and IOSCO members by the end of 2012.
- Principle 17 focuses on operational risk, requiring FMIs to manage the risks posed by their CSPs.
- The assessment methodology and disclosure framework are designed to ensure objectivity and comparability across jurisdictions, but do not cover the Expectations for CSPs.
SWIFT as a CSP
- SWIFT is a key CSP for various FMIs, providing messaging services and infrastructure hosting.
- SWIFT has been subject to similar oversight requirements since 2007 and has conducted annual self-assessments.
- SWIFT has already met the expectations for CSPs, but self-assessment alone is not sufficient for full compliance; external validation is recommended.
Proposed Assurance Framework
- Based on international assurance standards, particularly ISAE 3000.
- Requires independent external validation to ensure consistency and transparency.
- Allows for scalable and cost-efficient compliance assessments that are proportional to the size and complexity of the CSP.
- Supports continuous monitoring and periodic reporting (typically annual) to ensure up-to-date compliance.
Benefits of the Framework
- Enables coherent and objective compliance for all stakeholders.
- Promotes market transparency and a common level of observance of the Expectations.
- Provides a level playing field for CSPs by ensuring equal quality and rigor in compliance assessments.
- Is future-proof, allowing for flexibility in the event of regulatory changes.
- Reduces the total cost of ownership for CSPs and improves efficiency for FMIs and regulators.
Takeaways
- Takeaway #1: A uniform, standardised assessment and disclosure methodology with external validation is the best way to ensure effective, efficient, and transparent compliance for all stakeholders.
- Takeaway #2: FMIs should ensure that dependencies on CSPs are identified and that independent assurance is obtained on the CSPs' full compliance with the Expectations.
- Takeaway #3: A single uniform assurance methodology benefits all FMIs, CSPs, and regulators.
- Takeaway #4: Based on self-assessment and subject to external validation in 2013, SWIFT believes it meets each of the oversight expectations applicable to CSPs.
Appendix A Summary
- SWIFT has implemented appropriate policies and procedures to meet the Expectations for CSPs.
- It has mature processes for identifying, managing, and mitigating security, technology, financial, and vendor-related risks.
- The Board ensures proper supervision and risk management.
- The Chief Risk Officer (CRO) oversees the risk management framework and reports to the Board.
- SWIFT has a strong, independent Internal Audit group that aligns with international standards.
- The Internal Audit group is reviewed by independent third parties and includes ERM and Security Risk Management (SRM) in its scope.
Conclusion
- The Principles and Expectations significantly increase the assurance requirements for FMIs and CSPs.
- SWIFT advocates for industry-wide adoption of a common assurance framework to ensure consistent and objective compliance.
- This framework is scalable, cost-efficient, and future-proof, and will be implemented by SWIFT as of 2013.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载