ESMA proposes cloud outsourcing guidelines
The European Securities and Markets Authority (ESMA) has launched a consultation paper on guidelines for financial services firms outsourcing to cloud service providers.
According to ESMA, the proposed guidelines aim to mitigate any potential risks firms may face as a result of outsourcing cloud services and ensure they are handled appropriately.
The proposed guidelines set out the following:
- Governance, documentation, oversight and monitoring mechanisms firms need to have in place
- Assessment and due diligence which needs to be completed prior to outsourcing
- Minimum elements outsourcing and sub-outsourcing agreements must include
- Exit strategies, access and audit rights to which should be catered for
- Notification to competent authorities
- Supervision by competent authorities
While cloud outsourcing can bring a number of benefits,...
Categories: OutsourcingIT & cyber securityRegs & ComplianceTechnologyTech providers