State Bank of Pakistan (SBP) has allowed the use of limited outsourcing of cloud computing services to banks and financial… Read More
The post SBP Allows Use of Limited Outsourcing of Cloud Services To Financial Institutions appeared first on .
State Bank of Pakistan (SBP) has allowed the use of limited outsourcing of cloud computing services to banks and financial institutions (FIs) mainly for the non-core operations and business support processes.
According to the banking regulator, financial institutions’ can avail all types of cloud service models including Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (IaaS), etc. from domestic and off-shore Cloud Service Providers (CSPs).
FI(s) can use cloud services for non-core operations and business support processes such as
Financial institutions are not allowed to share customers’ details
All other banking applications and allied infrastructure, which are used to store and process customers’ information relating to deposits, loans and credits and details of balances and transactions in ledger accounts of customers or borrowers, shall not be placed under cloud-based outsourcing arrangements.
FI(s) shall ensure that their internal/ external auditors and SBP have the right to conduct an audit and on-site inspection of the CSP or its subcontractor. Further, there should be no restriction or prohibition on visits by audit or SBP staff or such visits are otherwise not impractical.
In case, where audit cannot be conducted for a valid reason(s), FI(s) may rely on internationally recognized third party certifications and reports made available by CSP. However, reliance on these third-party certifications and reports shall be supported by adequate understanding and review of the scope, the methodology applied therein, and the ability of third parties and CSP to clarify matters relating to the audit. These reports shall be shared with SBP as and when required.
SBP instructed banks and financial institutions to ensure certain aspects while entering into an outsourcing arrangement with CSPs.
Notwithstanding the instruction contained in section IX (h) of ‘Framework for Risk Management in Outsourcing Arrangements by Financial Institutions’, subcontracting is allowed in outsourcing arrangements with CSPs provided they shall comply with all relevant laws and SBP’s regulations.
All outsourcing arrangements to cloud service providers by FIs shall be governed under ‘Enterprise Technology Governance and Risk Management Framework for Financial Institutions (FIs)’, SBP circular said.
The post SBP Allows Use of Limited Outsourcing of Cloud Services To Financial Institutions appeared first on .
28/09/2020 11:33 AM
28/09/2020 01:34 PM
28/09/2020 01:48 PM
28/09/2020 12:59 PM
28/09/2020 02:24 PM
28/09/2020 12:32 PM
2014 © Pakistani apps and news