The Committee of European Banking Supervisors CEBS is publishing today the final set of guidelines on outsourcing of credit institutions' business activities. The aim of the CEBS guidelines is to promote an appropriate level of convergence in supervisory approaches to outsourcing. The proposed guidelines are based on current supervisory and market practices and also take into account international and European developments in the field of outsourcing. The proposed guidelines define outsourcing as "an authorised entity's use of a third party to perform activities that would normally be undertaken by the authorised entity". The use of a third party changes the risk profile of an authorised entity.

Author:Zololabar Nigrel
Language:English (Spanish)
Published (Last):21 September 2007
PDF File Size:13.62 Mb
ePub File Size:17.71 Mb
Price:Free* [*Free Regsitration Required]

The European Banking Authority EBA is an independent EU Authority that works to ensure effective and consistent prudential regulation and supervision across the European banking sector. The EBA outsourcing guidelines provide specific guidance on the relationship between financial institutions and their service providers. In particular, the guidelines specify a set of aspects that should be included in the contract between the financial institution and their service provider, including requirements on sub-outsourcing, security, access, information and audit rights, and termination rights.

We have also created mappings to the guidelines for both GCP and G Suite to assist you with understanding how we can support you with meeting the requirements and assess us as an outsourced service provider. Google Cloud is committed to addressing these requirements regardless of how institutions choose to use our services. Automatically scan various types of logs for suspicious activity to uncover security threats in your GCP environments.

Open source toolkit designed to help give your security teams the confidence that they have the appropriate controls in place across our services. Allows you to move and convert workloads directly into containers in Google Kubernetes Engine. Visibility and monitoring of Google Cloud resources and changes to resources including VM instances, images, and operating systems. When Google Cloud Platform administrators access your content, Access Transparency gives you near real-time logs of their actions.

Managed, production-ready environment for deploying containerized applications offers cutting-edge innovation in productivity, security, and flexibility. Virtual machines hardened by security controls protect enterprise workloads on GCP from remote attacks, privilege escalation, and malicious insiders. Admins can enjoy full visibility into and control over cloud resources by authorizing who can take action on specific resources.

Available to Google Cloud users at no added charge. Monitoring and management for services, containers, applications, and infrastructure. Gathers data to speed root-cause analysis and time to resolution.

Examine potential security risks, measure user collaboration, track who signs in and when, analyze administrator activity, and much more. Protect your organization from the latest security threats by getting real-time actionable alerts and security insights about activity in your domain.

Protect your organization with security analytics and best practice recommendations from Google. Review logs of actions taken by Google staff when accessing user-generated text entered into Gmail, Docs, Sheets, Slides, and other apps. Why Google close Groundbreaking solutions. Transformative know-how. Whether your business is early in its journey or well on its way to digital transformation, Google Cloud's solutions and technologies help chart a path to success.

Learn more. Keep your data secure and compliant. Scale with open, flexible technology. Build on the same infrastructure Google uses. Customer stories. Learn how businesses use Google Cloud. Tap into our global ecosystem of cloud experts. Read the latest stories and product updates. Join events and learn more about Google Cloud. Tools to get work done more safely and securely.

Migration solutions for VMs, apps, databases, and more. Serverless data warehouse with built-in machine learning. Platform to design, secure, analyze, and scale APIs anywhere. Website hosting and deployment with Services and integrations to build and scale apps. Flexible machine learning products for any level of expertise. Analytics and collaboration tools for the retail value chain.

Computing, data management, and analytics tools for finserv. Health-specific solutions to enhance the patient experience. Data storage, AI, and analytics solutions for government agencies. Reduce cost, increase operational agility, and capture new market opportunities. Solutions for content production and distribution operations. Hybrid and multi-cloud services to deploy and monetize 5G. AI-driven solutions to build and scale games faster. Migration and AI tools to optimize the manufacturing value chain.

Multi-cloud and hybrid solutions for energy companies. Teaching tools to provide more engaging learning experiences. Productivity tools, website hosting, analytics, and more. Discovery and analysis tools for moving to the cloud. Solution for running VMware workloads on Google Cloud. Compute, storage, and networking options to support any workload. Tools and partners for running Windows workloads.

Tools for app hosting, real-time bidding, ad serving, and more. Migrate and manage enterprise data with security, reliability, high availability, and fully managed data services. Guides and tools to simplify your database migration life cycle. Upgrades to modernize your operational database infrastructure. Database services to migrate, manage, and modernize data. Service for managing Oracle workloads through partners. Fully managed open source databases with enterprise-grade support.

Develop and run applications using open source and other software without operations staff. Platform for modernizing, running, and building new apps. End-to-end solution for building, deploying, and managing apps. Services and infrastructure for building web apps and websites. Open source service mesh for running microservices.

Back ends, tools, and integrations for mobile development. Cloud services for extending and modernizing legacy apps. Products for making data and services available as APIs.

Platform for writing code and building full-stack applications. Processes and resources for implementing DevOps in your org. Tools for automating and maintaining system configurations. See all application modernization solutions. Generate instant insights from data at any scale with a serverless, fully managed analytics platform that significantly simplifies analytics. Data warehouse to jumpstart your migration and unlock insights. Insights from ingesting, processing, and analyzing event streams.

Solutions for collecting, analyzing, and activating customer data. Services for building and modernizing your data lake. Data analytics tools for collecting, analyzing, and activating BI. Add intelligence and efficiency to your business with AI and machine learning. Products to build and use artificial intelligence. AI model for speaking with customers and assisting human agents. Machine learning and AI to unlock insights from your documents. AI with job search and talent acquisition capabilities.

Detect, investigate, and respond to online threats to help protect your business. App protection against fraudulent activity, spam, and abuse. Solution for analyzing petabytes of security telemetry. Change the way teams work with solutions designed for humans and built for impact. Collaboration and productivity tools for enterprises. Solutions for IT admins to empower mobile employees. Unified platform for IT admins to manage user devices and apps. Cloud storage and collaboration sold separately from G Suite.

Enterprise search for employees to quickly find company information. Command-line tools and libraries for Google Cloud. Managed environment for running containerized apps.

Data warehouse for business agility and insights. Content delivery network for delivering web and video. Streaming analytics for stream and batch processing.


EBA Outsourcing Guidelines

Skip to content. Related Content. The CEBS is made up of high-level representatives from the EU's banking supervisory authorities and central banks, and aims, among other things, to contribute to the convergence of member states' supervisory practices. The new guidelines, which were consulted on in April , aim to promote convergence in supervisory approaches to outsourcing.


What EBA’s Outsourcing Guidelines Mean for Financial Institutions

What do they mean for financial services firms and their technology suppliers? Financial Services FS firms commonly outsource services and business functions, in particular IT and technology, and given that the majority of outsourced services are provided by a select few providers, the EBA has identified that there is a risk to the stability of financial institutions and markets if there are no safeguards in place to regulate the outsourcing process. A reminder of what can go wrong for financial institutions in outsourcing is the case of Raphaels Bank, which was fined by the FCA due to failures to comply with outsourcing rules. Other than an update for cloud service providers, this is the first EU-wide update to outsourcing guidelines for financial institutions since the CEBS Guidelines on outsourcing in [2]. The Guidelines apply to financial institutions but because the Guidelines cover the outsourcing procedure and mandate certain issued to be addressed in outsourcing agreements, suppliers will be indirectly affected by the new Guidelines.


CEBS publishes guidelines on outsourcing by credit institutions

The guidelines create new obligations for financial, payment, and electronic money institutions that will impact cloud outsourcing and deployment of FinTech. By Fiona M. Maclean and Laura Holden. Financial institutions will now only need to consult one set of guidelines for cloud and non-cloud outsourcing. The Guidelines apply to a wider range of entities Covered Entities for the purpose of this article than the CEBS Guidelines and the Cloud Recommendations, including payment or electronic money institutions. The Guidelines now apply to all financial institutions that are:.

Related Articles