EBA欧洲银行-EBA-revised-Guidelines-on-outsourcing_DA_39页_540kb
报告摘要
Summary of EBA/GL/2019/02: Guidelines on Outsourcing
Core Content
These guidelines, issued by the European Banking Authority (EBA), outline the appropriate supervisory practices for outsourcing activities within the European financial supervision system. They are based on Article 16 of Regulation (EU) No 1093/2010 and aim to ensure that financial institutions and payment institutions comply with the requirements for outsourcing, particularly for critical or important functions.
Main Points
-
Compliance and Reporting Obligations
Competent authorities and financial institutions must comply with these guidelines. They are required to report to the EBA by a specified deadline whether they are implementing the guidelines or not. Failure to report on time is considered non-compliance. Reports must be submitted via the EBA's designated form to compliance@eba.europa.eu with the reference "EBA/GL/2019/02". -
Scope and Applicability
These guidelines apply to financial institutions, payment institutions, and e-money issuers. They are relevant for outsourcing arrangements, including cloud services. However, certain services like legal compliance, market data, and clearing services are excluded from being classified as outsourcing.
The guidelines also apply to institutions within a group or a deposit insurance scheme, with particular attention to the proportional principle. -
Definitions
- Outsourcing: Any arrangement where a third party performs a function, process, or activity that the institution or payment institution would otherwise carry out.
- Critical or Important Function: Any function that, if not performed properly, could materially impair the institution's ability to comply with its license conditions or legal obligations.
- Cloud Services: Includes public, private, and hybrid cloud infrastructures.
- Third-party Risk: Risks arising from arrangements with external providers.
Key Information
1. Compliance and Reporting
- Competent authorities and financial institutions must report to the EBA on their implementation of these guidelines by a specified deadline.
- Failure to report is considered non-compliance.
- Reports must be submitted using a specific form available on the EBA's website.
2. Scope and Application
- The guidelines apply to all outsourcing arrangements, including those involving cloud services.
- They are applicable to institutions, payment institutions, and e-money issuers.
- Certain services (e.g., legal compliance, market data, clearing services) are explicitly excluded from being considered outsourcing.
- Institutions within a group or deposit insurance scheme must apply the guidelines at both consolidated and individual levels, unless exemptions apply.
3. Proportionality Principle
- Institutions must apply the principle of proportionality when implementing these guidelines.
- This ensures that supervisory requirements are aligned with the institution's risk profile, business model, and complexity.
- The proportional principle also applies to the assessment of third-party risks.
4. Supervisory and Management Requirements
- Institutions must ensure that their management bodies are fully responsible for the supervision of outsourcing activities.
- Management must be able to make informed decisions, monitor, and control outsourcing arrangements.
- Institutions must maintain sufficient resources and competence to ensure proper oversight of outsourcing.
5. Documentation and Control
- Clear responsibilities for documentation, management, and control of outsourcing arrangements must be established.
- Institutions must ensure that all outsourcing activities are documented and monitored.
- Small and less complex institutions may assign these responsibilities to members of their management bodies.
6. Outsourcing Policy
- Management bodies must approve, regularly review, and update a written outsourcing policy.
- The policy must include:
- The management body's role in the decision-making process.
- Involvement of relevant business areas, internal control functions, and other stakeholders.
- Planning and management of outsourcing arrangements.
- Risk assessment and mitigation.
- Procedures for identifying and managing potential conflicts of interest.
- Business continuity planning.
7. Data Protection and Privacy
- Institutions must ensure that data protection and privacy regulations (GDPR) are followed in all outsourcing arrangements.
- Special attention must be given to the handling of personal data by third-party service providers within the EU or third countries.
8. Exit Plans and Substitutability
- Institutions must have exit plans for critical or important functions, which should be communicated to all relevant parties.
- The substitutability of outsourcing arrangements must be assessed, including the ability to transfer functions to another provider if needed.
9. Effective Implementation
- Institutions must ensure that all outsourcing arrangements are effectively managed and monitored.
- They must maintain an appropriate level of control and oversight over their outsourcing activities to ensure compliance with legal and regulatory requirements.
10. Exemptions and Transition Provisions
- Some provisions are subject to transition periods.
- The guidelines came into effect on 30 September 2019, with some exceptions applying from 31 December 2021.
- Previous EBA guidelines on outsourcing were repealed from this date.
Conclusion
The EBA/GL/2019/02 guidelines provide a comprehensive framework for the supervision and management of outsourcing in the European financial sector. They emphasize the importance of risk management, data protection, and the principle of proportionality, while ensuring that financial institutions and payment institutions maintain adequate oversight and control over their outsourcing activities. The guidelines also include specific reporting requirements and transition provisions to ensure smooth implementation.
试读结束,高清完整版pdf/doc/ppt,请点下载