FSB全球金融稳定委员会-Regulatory-and-Supervisory-Issues-Relating-to-Outsourcing-and-Third_33页_427kb
报告摘要
Summary of Regulatory and Supervisory Issues Relating to Outsourcing and Third-Party Relationships
Core Content
This Discussion Paper by the Financial Stability Board (FSB) examines the regulatory and supervisory challenges associated with outsourcing and third-party relationships in the financial sector. It builds on the December 2019 FSB report on third-party dependencies in cloud services and the SRC survey conducted in 2020, which assessed the current regulatory and supervisory landscape across FSB member jurisdictions.
The paper highlights that while outsourcing and third-party relationships offer benefits such as operational resilience, cost reduction, and innovation, they also introduce risks that need to be managed effectively. These risks include cybersecurity threats, data protection concerns, supply chain vulnerabilities, and concentration risks that could potentially threaten financial stability.
Main Points
1. Regulatory and Supervisory Landscape
- Variation Across Jurisdictions: Regulations and supervisory expectations differ across countries but share common objectives.
- Common Principles: All jurisdictions agree that outsourcing does not relieve FIs of ultimate accountability for their operations.
- Focus on Critical Services: Supervisory authorities emphasize the importance of managing critical or important functions and shared services that impact financial stability and safety and soundness.
2. Supervisory Approaches
- Governance and Risk Management: FIs are required to implement adequate governance frameworks and internal controls.
- Access and Audit Rights: Authorities expect FIs to ensure they and their regulators have access, audit, and information rights to third parties.
- Legal Powers: Some jurisdictions grant supervisory authorities legal powers to access third-party data, conduct on-site inspections, and supervise services as if they were performed by FIs themselves.
- Examples of Powers:
- ASIC (Australia): Can compel local third parties to provide relevant documents.
- ESMA (EU): Can request information and conduct inspections on third parties.
- PRA (UK): Can require information deemed relevant to the stability of the UK financial system.
- CMBT (Turkey): Has similar powers over service providers of investment firms.
3. Key Challenges
- Practical Challenges:
- Negotiating Access Rights: Rights to access, audit, and obtain information from third parties are often difficult to negotiate and exercise.
- Supply Chain Risks: Managing risks across sub-contractors and supply chains is complex, especially in multi-jurisdictional contexts.
- Cross-Border Challenges:
- Jurisdictional Conflicts: Conflicting legal and regulatory approaches in different jurisdictions can impede supervisory effectiveness.
- Global Supply Chain Disruptions: The COVID-19 pandemic highlighted the vulnerability of supply chains and the importance of business continuity planning.
- Systemic Risk Concerns:
- Concentration Risk: A high level of dependence on a small number of third parties could lead to systemic risks if those parties fail.
- Need for Mitigation: Authorities stress the importance of mitigation strategies, including diversification and exit plans.
4. Lessons from the COVID-19 Pandemic
- Operational Resilience: The pandemic underscored the need for robust business continuity plans and exit strategies.
- Remote Working and Technology Reliance: Increased reliance on third-party technology for remote operations has raised concerns about cybersecurity and data protection.
- Supply Chain Management: FIs faced logistical challenges in obtaining remote working equipment due to supply chain disruptions.
- Critical Personnel: There is a call for third-party providers delivering core services to be treated as essential personnel.
Key Information
- The FSB does not propose specific principles or standards, but aims to promote global dialogue among FIs, supervisory authorities, and third parties.
- Regulatory scope has been broadened in some jurisdictions to cover all third-party relationships, not just traditional outsourcing.
- Business continuity plans and exit strategies are critical to ensuring resilience and minimizing disruption.
- Legal powers to access third-party data and conduct inspections are increasingly being used, though they are often limited to specific types of third parties.
Conclusion
The paper concludes that while the regulatory and supervisory frameworks are evolving, enhanced dialogue and cooperation are essential to address cross-border and systemic risks. The focus on operational resilience and risk mitigation is becoming more prominent, especially in light of the pandemic experience. The FSB invites feedback on the issues outlined, aiming to shape future regulatory and supervisory approaches.
Annex Overview
The Annex provides a detailed overview of responses from SRC member jurisdictions, including regulatory and supervisory approaches to outsourcing and third-party risk management, with a focus on governance, cybersecurity, and supply chain management.
试读结束,高清完整版pdf/doc/ppt,请点下载