2010年-ECB欧洲央行_Eurosystem_assessment_report_on_the_implementation_of_the_business_continuity_oversight_expectations_for_systemically_important_payment_systems_5页_148kb
报告摘要
Eurosystem Assessment Report on Business Continuity Oversight for Systemically Important Payment Systems
Introduction
Payment systems are a fundamental component of market economies, enabling the smooth functioning of monetary policy and maintaining confidence in the currency, financial system, and economy. They are exposed to various risks, including legal, financial, and operational risks, which can lead to significant losses. To address these risks, the Eurosystem has established oversight expectations aimed at ensuring operational resilience across systemically important payment systems (SIPS) in the euro area.
The Eurosystem published its "Business Continuity Oversight Expectations for Systemically Important Payment Systems" in June 2006, based on the CPSS Core Principle VII. These expectations focus on business continuity strategy, planning, testing, and crisis management. The deadline for implementation and testing was set for end-June 2009, and no system operators requested an extension.
The SIPS assessed in this report include TARGET2, EURO1, and four retail payment systems: POPS (Finland), PMJ (Finland), CORE (France), and CSS (Netherlands). The report summarises the results of the comprehensive assessment of these systems against the Eurosystem's business continuity oversight expectations.
Approach and Methodology
- A harmonised assessment approach was ensured by using the "Guide for the assessment against the business continuity oversight expectations for SIPS", published by the ECB on 12 November 2007.
- The guide provides clear and comprehensive guidelines for assessing compliance and preparing oversight reports.
- The assessment process ensured a level playing field for SIPS and enhanced transparency for system operators.
- The first assessments were conducted by the relevant central banks, with the ECB leading the assessment for TARGET2 and EURO1.
- Retail SIPS were assessed individually by their respective central banks and then subject to peer review by other euro area central banks.
Overall Assessment Result
- The business continuity and crisis communication arrangements of the assessed SIPS are maintained at high standards.
- Recommendations for improvement were made in certain areas, but none of these pose a significant risk to the overall business continuity framework.
- System operators were informed of the findings and agreed to take actions to achieve full compliance.
- The implementation of these recommendations will be monitored by the overseeing central banks and reported in a follow-up assessment.
Assessment by Key Issue
3.1 Key Issue 1: Formulation of Business Continuity Objectives
- All systems were found to meet the requirement of having a well-defined business continuity strategy and monitoring mechanism endorsed by the Board of Directors.
- Recommendations:
- Two systems need to improve procedures for reporting changes in business continuity and crisis management arrangements to the Board.
- One system should clarify recovery times for critical functions in its documentation.
- Two systems should assess the criticality of outsourced functions to third-party providers.
- Overall, the systems have sufficiently addressed the oversight expectations, though some improvements are recommended.
3.2 Key Issue 2: Development of Business Continuity Plans
- All systems were compliant with the requirement to identify plausible scenarios and have a secondary site.
- Recommendations:
- Two systems should reduce dependence on a single third-party service provider.
- One system should revise its business impact analysis to include risks from critical participant failures.
- Another system should complete the definition of critical participants and address associated risks.
- The systems have adequately addressed the main expectations, with specific recommendations to enhance compliance.
3.3 Key Issue 3: Communication and Crisis Management
- Most systems have established crisis management teams and formal procedures.
- Recommendations:
- One system should better define the stages of a crisis and activation criteria.
- Another system should establish a procedure for information sharing on operational resilience and security.
- Two systems should assess communication channels with local authorities.
- The systems have sufficient crisis management and communication arrangements, though some enhancements are needed.
3.4 Key Issue 4: Testing and Updating of Business Continuity Plans
- The assessment highlighted the need for regular testing and updating of business continuity plans.
- Recommendations:
- One system should extend testing scope to include participant involvement.
- Another system should consider participating in Eurosystem-coordinated industry-wide tests.
- One system, due to recent launch, should plan an external review of its arrangements.
- The systems have sufficiently addressed most expectations, but specific recommendations were issued to achieve full compliance.
Conclusion
The Eurosystem assessment concluded that the SIPS in the euro area have met high standards in terms of business continuity and crisis management. While some recommendations for improvement were made, they do not pose a significant risk to the overall resilience of the systems. The system operators have committed to implementing these recommendations, and the Eurosystem will continue to monitor their progress through follow-up assessments.
试读结束,高清完整版pdf/doc/ppt,请点下载