EBA欧洲银行-Session-4-NY-and-DB-EBA-Recs-on-cloud-and-Outsourcing-GLs-17-Oct-18_11页_1mb
报告摘要
EBA Summary: Recommendations on Cloud Outsourcing and Draft Guidelines on Outsourcing Arrangements
Core Content
The European Banking Authority (EBA) has issued Recommendations on Outsourcing to Cloud Service Providers and is developing Draft Guidelines on Outsourcing Arrangements to provide comprehensive guidance on the use of cloud computing in the banking sector. These documents aim to ensure that financial institutions can benefit from cloud technologies while effectively managing associated risks.
Main Points of the EBA Recommendations on Cloud Outsourcing
Scope and Application
- The Recommendations are based on the NIST definition of cloud computing, which includes all service models (IaaS, PaaS, SaaS) and deployment models (private, hybrid, public).
- They apply to competent authorities, credit institutions, and investment firms.
- The proportionality principle is central, meaning that the application of the recommendations should be appropriate to the scale and complexity of the institution's activities.
Objectives
- To promote common EU-wide guidance for the use of cloud services.
- To harmonise supervisory expectations across the EU.
- To allow institutions to leverage the benefits of cloud services while ensuring risks are identified and managed.
Key Topics Covered
- Materiality assessment – Institutions must evaluate the significance of cloud outsourcing activities.
- Duty to inform supervisors – Institutions are required to notify competent authorities in advance about material outsourcing activities.
- Access and audit rights – Contractual access and audit rights must be ensured, and audits can be conducted in a proportionate manner (e.g., pooled audits, third-party certifications).
- Security of data and systems – Institutions must ensure data confidentiality, continuity, security, integrity, and traceability.
- Location of data and processing – Institutions must consider the geographic location of data and data processing to ensure compliance with EU regulations.
- Chain outsourcing – Institutions must manage the chain of sub-contractors to avoid compliance and governance risks.
- Contingency plans and exit strategies – Institutions should put in place secure transfer and removal mechanisms for data and activities to avoid lock-in situations.
Opportunities and Challenges of Cloud Adoption in Banking
Opportunities
- Economies of scale: More efficient resource utilization and access to state-of-the-art systems.
- Cost-effectiveness: "Pay as you use" model reduces large upfront costs.
- Operational efficiencies: Streamlined processes and reduced infrastructure costs.
- Flexibility and scalability: On-demand infrastructure allows for dynamic resource allocation.
- Business agility: Enables faster deployment of new services and supports innovation (e.g., FinTech).
Challenges
- Data security and protection: Risks include system and network vulnerabilities, browser security failures, and data import/export bottlenecks.
- Concentration risk: Large cloud providers can become a single point of failure.
- Compliance and governance risks: Cross-border operations and complex subcontracting chains may lead to regulatory issues.
- Provider lock-in: Institutions must avoid dependency on a single provider and ensure secure data exit.
Draft Guidelines on Outsourcing Arrangements
Overview
- The Draft Guidelines update and integrate the 2006 CEBS Guidelines on Outsourcing and the 2017 EBA Recommendations on Cloud Outsourcing.
- They are applicable to both credit institutions and investment firms.
- The consultation period ended on 24 September 2018, and the guidelines are expected to be published in the first quarter of 2019.
Key Content
- The guidelines align with MiFID, PSD2, and Commission delegated Regulation (EU) 2017/565.
- They address outourcing within and outside the group.
- The goal is to avoid "empty shells" (i.e., entities that appear to be part of the group but do not perform meaningful functions).
- Institutions are required to assess all risks before outsourcing and to monitor them continuously.
- Differentiated requirements are applied to:
- Critical or important operational functions (more stringent)
- Other operational functions (less strict)
- The guidelines also specify access and audit rights and documentation requirements.
Key Information
- Final Recommendations on Cloud Outsourcing were published in December 2017.
- Translations in official EU languages were completed by March 2018.
- A comply/or explain procedure was introduced by May 2018.
- The application date of the recommendations is 1 July 2018.
- The recommendations are integrated into the review of the Outsourcing Guidelines and will be replaced by the new EBA Guidelines on Outsourcing.
Conclusion
The EBA’s Recommendations and Draft Guidelines aim to provide a structured and proportionate approach to cloud outsourcing and general outsourcing arrangements in the banking sector. They focus on risk management, transparency, and regulatory compliance, ensuring that financial institutions can adopt cloud technologies safely and effectively.
试读结束,高清完整版pdf/doc/ppt,请点下载