THE EUROPEAN BANKING AUTHORITY (“EBA”) PUBLISHES ITS RECOMENDATIONS ON THE USE OF CLOUD OUTSOURCING SERVICES BY FINANCIAL INSTITUTIONS

10/08/2017

The consultation document is part of the project for the definition of a clear and safe regulatory framework in the field of outsourcing for European credit institutions. In particular, EBA aims at adopting recommendations in execution of the CEBS (“Committee of European Banking Supervisors”) guidelines on outsourcing of December 14, 2006 (for the complete text, see https://www.eba.europa.eu/documents/10180/104404/GL02OutsourcingGuidelines.pdf.pdf).

 

Here are the main contents of the EBA Recommendations:

  • Security of data: financial institutions, before outsourcing their services, should conduct a thorough risk assessment and should ensure that the confidentiality of the information is protected;
  • Location of data and processing: financial institutions should inform regulators of the country where the service will be performed, proposing – if necessary – a revision of the legislation on data processing. Special attention should be paid when outsourcing services concern extra UE Countries;
  • Audit: financial institutions should provide systems that allow themselves – and the regulators of the countries – full access to the business premises where the outsourcing service is performed, providing the possibility to analyse and verify the systems and devices used for providing the services outsourced;
  • Chain outsourcing: in the case of subcontract of the outsourced service, also the subcontractor shall be required to fully comply with the measures and recommendations described above;
  • Contingency planning: financial institutions shall provide well tested exit and emergency plans and make sure the outsourcing service provider is obliged to make an orderly transfer of the services so as to maintain business continuity.