Amendments to Regulations on Outsourcing and IT Risk Management
CORRECTED COPY BANGKO STNTRAL NG PILIPINAS OFFICE OF THE GOVERNOR CIRCULAR NO. 1137 Series of 2c22 Subject : Amendments to Regulations on Outsourcing and lT Risk Management The Monetary Board, in its Flesolution No. l9O dated tO February 2022, approved the amendments to Sections ll2, Appendices 78 and lO3 of the Manual of Flegulations for Banks (MORB) and Sections lll-Qil3-Snl2-PltOZ- Nnl2-T and Appendices Q-36/Q-65 of the Manual of Flegulations for Non- Bank Financial Institutions (MORNBFI). Section l. Section ll2 of the MORB on outsourcing shall be amended, as follows: ' .1I2 MANAGEMENT CONTRACTS AND OUTSOURCING xxx Outsourcing.Xxx Definition. Xxx. Banks shall assess whether an outsourcing arrangement is material or non-material to the business. An outsourcing arrangement shall be considered material if a business disruption of an outsourced activity, service delivery failure and/or data/security breach will result in significant impact to bank's operations, financial condition, reputation, customers, and compliance with laws, rules and regulations. Prohibition againstoutsourcing of inherent banking functions. No bank shall outsource inherent banking functions such as: a. Taking of deposits from the public; b. Granting of loans and extension of other credit exposures; c. Managing of risk exposures; and d. General management.
Authorlttr to outrcurce. For material outsourcing arrangement, only banks with a SAFr composite ratingr of at least 3" shall be allowed to outsource designated activities without prior Bangko Sentral approval, subject to notification requirements provided in Appendix I49 - Section B. Banks with sAFr 'rating of below 3" must secure approval from the appropriate supervising department2 of the Bangko Sentral prior to the implementation of material outsourcing arrangements (see Appendix 149 - Section C for the list of requirements), which covers any of the fiollowing: a. New material outsourcing arrangements; b. Changes in existing material outsourcing arrangements that have significant impact in the delivery of outsourcing selvices, business operations, reputation and profitability; and c. Changes in existing outsourcing arrangements resulting in the reclassification of the arrangements as material such as, but not limited to those affecting the nature, scop€, and complexityof qystems and processes. Governatrce and mamglng ofotttsourclng rlsksvx a. Conduct materialitlr assessment (see Annex "A') of the outsourcing activigl, which shall consider the fiollowing factors: (l) Level of importance xxx xxx (5) Exposure to risk of conftdentiality xxx Periodic assessments shall be conducted to ensure that outsourcing risks, both on a contract-specific level and on an institution-wide level, are managed vis-i-vis the impact to the overall operations. In cases when the risk management qystem xxx b. Establish policies and criteria xxx xxx t In lieu of the SAFr composite rating. the CAMELS composite rating of at least 3'shall be used. lf neither a SAFr nor CAMELS rating ls available, other BSP ratlng may be used as basls provided that the overall assessment of the BSFI satisfies the descrlptlve criterla of SAFr composite rating 3', as follows: BSFI ls stable. Rislcs are adeguately managed across the organization. Superuisory concerns are wlthin the abilitlr of tln bard and managernent to address. The BSFI3 butrerc wlll enable it to withstand mostadver*senB. 2 Technology outsourcing applicationdnotifications shall be submitted to the Technology Risk and Innovation Superuision Department [fRlSD] Meanwhile, non-technology outsourcing applications/notifications shall be submitted to the repective Financial SupeMslon Department tFsDI Page 2 of6
f. Ensure the portability of the outsourced seruice (e.g., degree of difficulty, cost, and time in switching to an alternative service provider or to bring the activity in-house) and the impact to business continuity and recovery and resolution plans of the financial institution. .wx Other Upes of ottBotttclng arrangetnenE. The guidelines and requirements of outsourcing to third-party seryice providers shall be observed when a bank (il acts as the seruice provider, (iil participates in intra- group outsourcing, or (iiil engages in oftshore outsourcing. a. Bank as a seruice provider. The bank may enter into an outsourcing agreement outside its business group, provided that the bank delivering the outsourced service shall adhere to the guidelines on outsourcing, as well as relevant laws and pertinent Bangko Sentral rules and regulations. It may also render services to its own depositors on account of the bank acting as the depository institution. The seruice provider and seruice recipient should establish a clear understanding on rights and responsibilities on management of risks attendant to the outsourced activity, compliance with relevant laws, rules and regulations, and establishment of complaints handling and resolution process. b. Intra-group outsourcing. Banks may enter into an intra-group outsourcing agreementwithout prior Bangko Sentralapproval, in case: (i) the services rendered are perbrmed in the ordinarycourse of business; (ii) the service provider is likewise a regulated financial institution; and (iii) the service is rendered to subsidiaries, affiliates and companies related to the service provider through common ownership. The intra-group service provider may enter into a subcontracting agreement provided that said arrangement is regulated and authorized, as applicable, by the intra-group service providefs relevant regulatory authority. The bank should ensure that the service provider has a sound financial condition and has the necessary competency to provide such senrice. c. Offuhore outsourcing. Ofkhore outsourcing of bank's domestic operations is permitted only when: (i) the seruice agreement defines counterparties' right and responsibilities on confidentiality and data privacy; and (ii) the service prcvideroperates in jurisdictionswith existing confidentiality and/or data privacy laws that are not in conflict with existing Philippine laws and relevant regulations. Page 3 of6
When the service provider is located in other countries, the bank should take into account and closely monitor, on continuing basis, government policies and other conditions in countries where the service provider is based during the risk assessment process. The bank shall also develop appropriate contingency and exit strategies. Meanwhile, a domestic subsidiaryof a foreign bank mayenter into a materialoffshore intra-group outsourcing agreement without prior Bangko Sentral approval, provided that the outsourcing service is either engaged or provided by.its parent bank, central service operations center, or designated entity within the group, which are duly regulated in their respective home jurisdictions. The bank shall have the primary responsibility to ascertain the adequacy of design and effectiveness of service provider's security control mechanisms through audit procedures conducted by third party auditors or bank's internal audit function. In the event that results from alternative audit mechanism and third-party validation do not satisff the objectives and requirements of the outsourcing regulations, the Bangko Sentral shall obtain from the bank relevant information in relation to the outsourced operations. lf reasonable means to conduct offsite procedures have been exhausted, the Bangko Sentral shall be given access to the service provider and those relating to the outsourced domestic operations of the bank. Such access may be fulfilled through coordination with host authorities, if necessary. The domestic subsidiary of a foreign bank shall be principally liable in cases where the clients are prejudiced due to errors, omissions and frauds of the service provider located offshore. The Bangko Sentral may require the bank to terminate xxx. Section 2. The amendments to Appendices lO3 and Q-36 of the MORB and MORNBFI, respectively, are attached as Annex "B" of this Circular. Section 3. Appendix 78 of the MORB (lT Risk Management Stand'ards and Guidelines, Area: lT Outsourcing/r'endor Management) on emerging outsourcing models shall be amended as follows: XXX 3.2 Service Provider Selection. Before selecting a service provider, the BSFI should perform appropriate due diligence of the provider's financial soundness, reputation, managerial skills, technical capabilities, operational capability and capacity in relation to the services to be outsourced. The depth and formality of the due diligence performed may vary depending on the nature of the outsourcing arrangement and the BSFI's familiarity with the prospective service providers. For arrangements involving data transfer and handling, BSFIs should identiff potential risks arising from physical and logical access of Technology Service Provider (TSP) employees, subcontractors, and other parties. As such, background checkt oT these Page 4 of6
logical access of Technology Service Provider ffSP) employees, subcontractors, and other parties. As such, background checks on these companies ar€ important to ensure that data are not being hosted by an organization that has a history or track record of not upholding confidentiality of information or that is engaging in malicious or fraudulent activity. Business resilience and technical capability of the TSP in providing security and controls, audit and compliance, monitoring, and reporting requirements of the BSFI should also be carefully considered. Contract negotiation should xxx xxx xxx 5.6 Security and Privacy. With growing concerns on data privacy and data securi$/, BSFIs shall ensure that all confidential and sensitive data and information exposed to the TSP environment are well-managed and protected. BSFIs shall ensure that all data being handled, processed, and/or stored thru an outsourcing arrangement are included in its data inventory and data classification process. BSFIs shall likewise ensure that TSPs fiollow appropriate data handling procedures and employ robust access contrcl mechanisms. Moreover, BSFIs shall see to it that the TSP conducts periodic monitoring and reporting of security-related threats, incidents, and events on its networks/systems. The TSP should also have proactive incident response and problem management process in place, eguipped with digital forensic tools and capabilities. In order to assess the TSP's ability to enforce appropriate technical, physical, and administrative safeguards (i.e., access controls, data segregation, etc.) across its organization, BSFIs may refer to independent assessments (e.9., external audit, security certificates, among others) which provide attestation on the effectiveness of the TSP's control environment and security mechanisms. 3.7 Data Ouvnership and Data Locatlon and Retrieval. One of the most common areas of concern in technology outsourcing is data transit, storage, and retrieval particularly in view of the multi-region cloud deployment setup. Such arrangement heightens challenges in assessing the design and control effectiveness of systems and processes across multiple physical locations. Moreover, laws, rules, regulations, and other compliance requirements may widely vary across jurisdictions where data is being transmitted, processed, and/or stored. To address this, BSFIs must obtain a sound understanding of the TStrs physical and logical controls over its information assets. BSFIs should be able to identiff where the data is being processed and/or stored and assess Page 5 of6
whether the corresponding jurisdictions uphold data sovereignty laws. In any case, BSFIs should ensure that ownership rights over its data must be clearly defined in the contract to establish the proper level of data access and control. At a minimum, the contract should contain the fiollowing provisions: i) the BSFI retains exclusive ownership over all of its data; ii) tha TSP acquires no rights whatsoever to use the BSFI's data for its own purpose or br any purpose other than what is required based on the scope of service; and iii) the TSP does not have the right to prevent the duly authorized access of BSFI to its own data. For these provisions to work as intended, the terms of data ownership must not be subject to unilateral amendment by the TSp. 5.8 Business Contlnul$ Plannlng Consideratlon. The BSFI should integrate the TSP's BCP into its own plan, communicate functions to the appropriate personnel, and maintain and periodically review the combined plan. lt should ensure that the TSP tests its plan annually and notiff the institution of any resulting modifications. BSFIs shall likewise establish contingency plans in case the TSP becomes unavailable or inaccessible. Appropriati contingency and resumption strategies should be fiormulated to consider both short-term and prolonged unavailabiliU/inaccessibility of the TSp. 3.9 Compllance with Bangko Sentral Regulations. xxx section 4. section 4 of Appendix 78 of the MORB (tr Risk Management standards and Guidelines, Area: lr outsourcingy'vendor Management) on emerging outsourcing models and Annex A of Appendix 28 of the MoRB shall be deleted. sectlon 5. section ll2-T of the MORNBFI is hereby amended to read, as follows: "Sectlon 112-T Guldelfups on OuBantelng. The rules on outsourcing of services as shown under Sec.Il2 of the MORB and Appendix Q-36 in so far as applicable, shall apply to TCs. Section 6. Eftctivlty.This Circular shall take effect fifteen 05) calendar days following its publication either in the Offrcial Gazette or in a newspaper of general circulation. FOR THE MONETARY BOARD: c cq. BENJAMIN E. DIOKNO Governor l( r"bru" ry Zo22 Page 6 of6
Annex "A" Appendix I49 OUTSOU RCING MATERIALIW ASSESSM ENT Compliance with Section II2 and Appendix 78 lT Outsourcinglr/endor Management of the Manual of Regulations for Banks FACTORS IN EVALUATINC THE IMPACT OF THE SERVICE PROVIDER BSFI ASSESSMENT TO THE OVERALL OPERATIONS OF THE BANK (l ) Level of importance to the bank of the activity to be outsourced and potential impact on bank's operations, financial condition, reputation, and ability to achieve its objectives, strategies and plans. should the service provider fail to perform the services; (2) Outsourcing costs in proportion to totaloperating expenses and compared with costs of developing own infrastructure and expertise; (3) Aggregate exposure to a particular service provider, in cases when the bank outsources various functions to the same service provider; (a) Ability to maintain appropriate controls and meet regulatory requirements, in cases of operational constraints of the service provider;and (5) Exposure to risk of confidentiality, integrity and availability of customer and bank data. OVERALL MATERIALITY ASSESSM ENT (Materia I/llon - M ateria | ): Page 1 of1
Annex "B" Appendix 'lO3/Q-36 DOCUMENTS REQUIRED UNDER THE REVTSED OUTSOURCING FRAMEWORK FOR BSFIs [Appendix to Sections ll2,lll-Q,7Ol-Q (Outsourcing of internet and mobile electronic services), ll3-S, 162-P and lO2-N] Section A. For all outsourcing arrangements An outsourcing register covering all outsourcing arrangements of the BSFlshall be maintained and made available upon request of the Bangko Sentral. At a minimum, the following information should be included: l. Outsourced Servicet 2. Description of Outsourced Service 3. Materiality (Material or Non-Material) 4. lf material, date of BSP approval (if applicable) 5. Outsourcing arrangement 5.1. Technology or Non-Technology 5.2. Intragroup or Third-Party 6. Name of Service Provider 7. Business Address of Service Provider 8. Has the BSFI identified an Alternate Service Provider? (yes/no) 8.1. lf yes, name of the Alternate Service Provider 9. lf cloud outsourcing, indicate the following: 9.1. Cloud service model (laaS, PaaS, SaaS, etc.) 9.2. Cloud deployment model (Private, Public, Community, Hybrid ) tO. Outsourcing agreement 'lO.l. Start date 1O.2. Last renewal date (if applicable) 1O.3. End date 11. Does it involve deposit/customer information? (yes/no) ll.l. lf deposit/customer information is involved, location where outsourcing services are performed 12. Business Continuity Plan of the Service Provider 12.1. Date last tested 13. Due Diligence/Periodic Service Performance Assessment 13.I. Date last conducted 13.2. Conducted by 14. Independent and/or third-party audit/review 14.1. Date last conducted 14.2. Conducted by I Each service indicated in the master service agreement should be listed in a separate row Page I of 5
Annex "B" Appendix lo3lQ-36 Section B. For material outsourcing that DO NOT REQUIRE prior Bangko Sentral approval Submit to the appropriate supervising department of the Bangko Sentral at least 5O banking days prior to the implementation of new or changes in material outsourcing arrangement, the following requirements: t. Notification letter signed by the president or officer of eqr.rivalent rank, indicating that the BSFI will engage in material outsourcing arrangement/s, including the description of the outsourcing arrangement/s; 2. Corporate secretary's certificate on the approval of the board of directors of the BSFI (or a loca/regional management committee, in case of foreign banks), of the outsourcing activity, including the determination of whether an outsourcing arrangement is considered material or non-material and the specific service provider with which the BSFI is entering into an outsourcing contract; and 3. Certification signed by the president or officer of equivalent rank and the Chief Compliance Officer (CCO), certifying that the BSFI has complied with all the prudential criteria under Section lll of the MORB or Section llI-Q of the MORNBFI on licensing, whichever is applicable, including the conduct of risk assessment of the outsourcing arrangement indicating the results thereof, as well as the contractual provisions pursuant to Appendix 78 and established sound risk management system on the following ?r€€ts: a. Legal and Regulatory Compliance; b. Governance and Risk Management; c. Due Diligence; d. Vendor Management/Performance and Conformance; e. Security and Privacy; f. Data Ownership and Data Location and Retrieval; and 9. Business Continuity Planning Within the 50-day period, the Bangko Sentral reseles the right to require additional documents from the BSFI relative to the material outsourcing arrangement and correspondingly, issue a notice of no objection. In the absence of such notice after the lapse of the 3O-day period, BSFIs may proceed with the implementation of the material outsourcing arrangement.
Annex "B" Appendix lO3/Q-36 Section C. For material outsourcing that REQUIRE prior Bangko Sentral approval Submit to the appropriate supervising department of the Bangko Sentral at least 35 banking days prior to the implementation of new or changes in material outsourcing arrangement, the following requirements: l. Application letter signed by the president or officer of equivalent rank signiffing the BSFI's intent/plans to engage in material outsourcing arrangement/s, including the description of the outsou rci ng arra ngement/s; 2. A comprehensive policy on outsourcing, duly approved by the board of directors of the BSFI. 3. Proposed master service agreement or contract between the BSFI and the service provider, which shall, at a minimum, include all of the following: a. Complete description of the work to be performed or services to be provided; b. Fee structure; c. Provisions governing amendment and pre- termination of contract; d. Flesponsibility, fines, penalties, and accountability of the service provider for errors, omissions, and frauds; e. Confidentiality clause covering all data and information; solidarity liability of service provider and bank for any violation of R.A. No. 1405, (the Bank Deposits Secrecy Law) actions that the 'breach bank may take against the service provider for of confidentiality or any form of disclosure of confidential information; and the applicable penalties; f. Segregation of the data of the BSFI from that of the service provider and its other clients; 9. Disaster recovery/business continuity contingency plans and procedures; h. Guarantee that the service provider will provide necessary levels of transition assistance if the BSFI decides to convert to other service providers or other arrangements; Access to the financial information of the service provider;
Annex "B" Appendix 1O3/Q-36 j. Access of internal and external auditors to information regarding the outsourced activities/ services in line with the fulfillment of their respective responsibilities; k. Access of Bangko Sentral to the operations of the service provider in order to review the same in relation to the outsourced activities/services in the event that results of alternative audit mechanisms (i.e., independent review or validation, third-party attestation, etc.) do not satisff the requirements and supervisory objectives of the Bangko Sentral; l. Provision which requires the service provider to promptly take the necessary corrective measures to satisfli the findings and recommendations of Bangko Sentral examiners and those of the internal and/or external auditors of the BSFI and/or the iervice provider; m. Flemedies for the BSFI in the event of change of ownership, assignment, attachment of assets, insolvency, or receivership of the service provider; and n. Provision allowing the BSFI to cancel the contract by contractual notice of dismissal or extraordinary notice of cancellation if so required by the Bangko Sentral due to non-compliance with regu latory requ irements. Additional Requirements for lT outsourcing: o. Provisions regarding on-line communication availability, transmission line security, and transaction authentication; p. Flesponsibilities regarding hardware, software, and infrastructure upgradesi q. Mandatory notification by the service provider of all systems changes that wif l affect the bank; r. Details of all security procedures and standards; Adequate general insurance coverage (e.g., fidelity and fire liability), if applicable; and Ownership/maintenance of the computer hardware, software (program source code), user and system documentation, master and transaction data files.
Annex "B" Appendix lO3/Q-36 4. corporate secretary's certificate on the minutes of meeting of the board of directors of the BSFI (or a local/regional management committee, in case of foreign banks) explicitly approving the activity to be outsourced, the determination of whether an outsourcing arrangement is considered material or non-material and the specific service provider with which the BSFI is entering into an outsourcing contract; 5. Profile of the selected service provider; 6. lf outsourcing an lT service involving cloud service provider, a Service Organization Control (SOC) 2 Type 2 or any equivalent Third Pa rty/l ndependent Report; 7. Certification signed by the president or officer of equivalent rank and the Chief Compliance Officer (CCO), certifying the results of the risk assessment conducted on the outsourcing arrangement with the service provider; 8. Certification signed by the president or officer of equivalent rank and the Chief Compliance Officer (CCO), certifying that the BSFI has assessed the outsourcing arrangement as "material outsourcing" based on the factors enumerated in Section 112 of the MORB on governance and management of outsourcing risks; and 9. Accomplished lT Outsourcing Questionnaires and details of compliance with the requirements on lT Outsourcingfuendor Management of Section 148 and Appendix 78 of the MORB/Section 147-Qfi45-51142-P/.26-N/Appendix Q-65 of the MORNBFt, as shown in Appendices 149-I and 149-2. Ensure that supporting documents are attached and specific references thereto are clearly indicbted.
Appendix l03-l/Q-36-l IT OUTSOURCING QUESTIONNAIRE FOR BSFI compliancowith section ll2 and Appendix 78 of the Manualof Regulations for Banks (MoRB) and AppendixQ-55 of the Manual ofRegulations for Non.Bank Financial lnstitutions (MoRNBFI) on lT Outsou rcingtrltendor Management Note This self-assessment should be maintained by high-level ofticers who have direct understanding ofthe institution! outsourcing atangements. C-suite executives must review and sign-otrpriot to submission to BSP. Please indicate specific rcferences (e.9., index, page section, or title) to supporting documents. NAME OF BANK / t{Ot{-AANK FINANCIAL INSTITUTION (NBFI): DATE ACCOMPLISHED: A. l. Name of Technoloqv Service Provider (TSP) 2. Service commencement date. (MM/DD/VY) 3. ldentifu and describe: 3.a Proposed activities, operations and services to be outsourced; and 3.b Data to be processed, stored, and accessed by TSP, including the data access methods. and BSFI's information classification standards. B. : i'F,fry* Determine the extent of compliance with the followins: f*s j i ;+ :FfrPIiEMENTED EC'NTROL8FOMFT.IA}EE ffiii:li'+*li ts& if !!foi aplgiliaC t. Legal and Regulatory Comptiance, Governance and Risk Management, and Due Diligence a. Law on Secrecv of Deposits (R.A. No.1405 b, Foreiqn Currencv Deposit Svstem R..A.6426 c. Anti-Money Laundering Act (R.A.No.9160, as amended), particularly on data/ file retention d. Electronic Commerce Act (R.A. 8792) e. Data Priva Law (R.A.]O]73 rime Prevention Act (R.A.'lO]75 BSP lT Outsourcing Questionnaire for BSFI template updated as of 3l January 2022 Pagei of5
Appendix l03-l/Q-36-1 ct. General Bankinq Law (R.A. 8791) h. Electronic Bankinq Services (BSP Circular lO33) i. Consumer Protection (BSP Circular lO48) 2.,,: €overnance end Risk Manacrement a. Adoption of written, board-approved outsourcing policy. Please provide details on policv title, Board approval and last review date b. Risk assessment procedure, results and justification in pursuing a technoloqv outsou rcinq enqaqement c. BSFI's internal audit role/involvement prior to and after the enqaqement of a TSP I. Due Djliqsnse Formally defined and documented TSP selection process. Provide briefly the following: a. Selection Criteria b. Considerations for other vendors/service providers c. Reason for choosinq the TSP 4. Vendor Manaqement Performance and Suppott a. BSFI's monitorinq process to manaqe the outsourced lT service b. Process to audit TSP to assess its compliance with entity's policy, procedures, securiW controls and requlatory requirements c. BSFI's procedures in identifoing, reporting, and responding to securitv incidents and violations d. BSFI's contingency plan for replacing the TSP in the event of its cessation 5. Securitv and Privacv a. Information security policies and initiatives to incorporate activities outsourc6d to TSP and risks pertaining to compromise of confidential/sensitive information processed and/or stored by the TSP. b. A comprehensive data invdntory and a suitable data classification process to facilitate TSP's implementation of identity and access controls BSP lT Outsourcing Questionnaire for BSFI template updated as of 3l January 2022 Page 2 of 5
Appendix l03-1/Q-36-1 c. Monitoring and management for integrity checking, compliance checking, security monitoring, comprehensive incident response methodoloqies, and network performance d. Procedures established to securely destroy or remove the data when the need arises (e.9., upon contract termination, either on expiry or prematurelv) 6. BusinessContinuityPlannlns a. Responsibilities and procedures for availability, data backup, incident response and recovery, Maximum Tolerable Period of Disruption (MTPD), Recovery Time Objectives (RTO), and Recovery Point Obiectives (RPO) of svstems or applications outsourced b. Frequency of business continuity and disaster recovery tests, validation process and testinq methodoloqv c. Continqency plan for replacing the TSP in the event of its cessation The Memorandum of Agreement (MOA)/Service Level Agreement (SLA) has been reviewed and ascertained by a legal counsel to include all pertinent provisions stated in the revised outsourcing framework. Provide the following details: l. Reviewer 2. Review Date 3. Results of Review BSP lT Outsourcing Questionnaire for BSFI template updated as of 31 January 2C22 Page 3 of5
Append ix I 03-'llQ-36-'l Master Seruice Agreernent or contract betureen tte bankft.lBFt and the sewice provider, which shall, at a minimum, include alt of the fiollowilu: a. Complete description of the work to be performed or services to be provided; b. Fee structure; c. Provisions governing amendment and pre- termination of contract: d. Responsibility, fines, penalties, and accountability of the service provider for errors, omissions and frauds; e. Confidentiality clause covering all data and information; solidarity liability of service provider and bank/NBFI for any violation of Fl.A. No. 1405, (the Bank Deposits Secrecy Law) actions that the bank/NBFI may take against the service provider for breach of confidentiality or any form of disclosure of confidential information; ahd the applicable penalties; f . Segregation of the data of the bank/NBFI from that of the service provider and its other clients; g. Disaster recovery/business continuity contingency plans and procedures; h. Guarantee that the service provider will provide necessary levels of transition assistance if the bank/NBFI decides to convert to other service providers or other arranqements; i. Access to the financial information of the service provider; j. Access of internal and external auditors to information regarding the outsourced activities/ services which they need to fulfill their respective responsi bi ities; I k. Access of Bangko Sentral to the operations of the service provider - in order to review the same in relation to the outsourced activities/ services in the event that results of alternative audit mechanism and third-party validation do not satisflT requirements and examination obiectives of the requlator/s; l. Provision which requires the service provider to promptly take the necessary corrective measures to satisfo the findings and recommendations of Banqko Sentral examiners and those of the BSP lT Outsourcing Questionnaire for BSFI template updated as of 31 January 2022 Page 4 of 5
Append ix'l 03-l/Q-36-l internal and/or external auditors of the bank and/or the service provider; m. Flemedies for the bank/NBFI in the event of change of ownership, assignment, attachment of assets, insolvency, or receivership of the service provider; and n. Provision allowing the bank/NBFI to cancel the contract by contractual notice of dismissal or extraordinary notice of cancellation if so required by the Bangko Sentral due to non- compliance with requlatorv requirements. Additional Requirernents for lT Outsourcinq: o. Provisions regarding on-line communication availability, transmission line securiW, and transaction authentication; p. Flesponsibilities regarding hardware, software and infrastructure uoqrades: q. Mandatory notification by the service provider of all systems chanqes that will affect the bank/NBFI; r. Details of all securiW procedures and standards: s. Adequate general insurance coverage (e.g., fidelity and fire liabilitv). if applicable: and t. Ownership/maintenance of the computer hardware, software (program source code), user and system documentation, master and transaction data files. BSP lT Outsourcing Questionnaire for BSFI template updated as of 3l January 2022 Page 5 of 5
Appendix l03-2lQ-36-2 IT OUTSOURCING QUESTIONNAINE FOR TSP Compliancewith Section ll2 ahd Appendix 78 ofthe Manual ofRegulations for Banks (MORB) and AppendixQ-55 of the Manual ofRegulations for Non-Bank Flnancial Institutions (MORNgFll on lT Outsourcinglrendor Management Note: This self-assessment should be maintained by high-level officeE wha have dircct understanding ofthe institution s outsourcing arrangements. C-suite executives must feview and sign-offprior to submission to BSP, Please indicate specifrc references (e.9., index, page section or title) to supporting documents NAME OF TECHNOLOGY SERVICE PROVIDER (TSP): DATE ACCOMPLISHED: :.; 'i'A&. '1. Provide brief description on the company profile: a. History b. Location c. Business purpose and services offered d. Credibility and Certifications e. Partners, affiliates, and sub-vendors f. Contact lnformation and website 2. Service commencement date. (M 3. ldentifu and describe: 3.a Proposed services to be provided 3.b Data to be processed/stored and its information classification standards BSP lT Outsourcing Questionnaire for TSP template updated as of 3'l January 2022 Page i of3
Appendix 1o3-2/Q-36-2 services. Please provide background information of all vendors/subcontractors that are in critical path of the TSP b. TSP's guarantee of availability and extent of liability if SLAs are not met c. Crant of BSP access to TSP's operations in the event that results of alternative audit mechanism and third-party validation do not satisfu requirements and examination obiectives of the regulators. d. TSP's procedures in identifying, reporting, and responding to operational incidents and violations and its involvement in providinq support to the BSFI 2. Seeuritv and Privacv a. A comprehensive data inventory and a suitable data classification process to facilitate TSP's implementation of identity and access controls b. lmplementation of adequate security controls and procedures to protect storage and transmission of confidential or sensitive information/data between hosts and terminals. lnclude discussion on: o Security features o lnformation and cyber security controls. . End-to-end encryption c. For cloud outsourcing, the location of primary and secondary sites and phvsical and environmental controls in place d. Monitoring and management for integrity checking, compliance checking, security monitoring, comprehensive security incident response methodoloqies, and network performance e. Procedures established to securely destroy or remove the data when the need arises (e.9., upon contract termination, either on expiry or prematurelv) and validate proper data purge BSP lT Outsourcing Questionnaire for TSP template updated as of 31 3anuary 2022 Page 2 of 3
Appendix 1O3-2/Q-36-2 3. Data €hrrnerchip and Data Loeatinn and Retrieval a. Location where data/information is stored and the extent of control over those data/i nformation b. Clear stipulation of legal ownership rights over the data to enable a basis for trust and privacy of data c. Data seqreqation and isolation from other subscriber's data t*. Business Continuity Planning a. Responsibilities and procedures for availability, data backup, incident response and recovery, Recovery Time Objectives (RTO), and recovery point objectives (RPO) of systems or applications outsourced b. Prioritization arrangements in case of multiple/simultaneous disasters c. Frequency of business continuity and disaster recovery tests, validation process and testinq methodology 5. Audit and Securiw Reviews a. TSP's audit solutions that will allow BSFIs to perform audit and compliance review of their lT security configurations, in the event that alternative audit mechanisms are deemed insufficient b. Periodic independent security audits/reviews (Discuss briefly) c. In relation to the previous item, list down all the security reports conducted in the past year and indicate the following information: i. Name of report/s ii. Brief description iii. Assessment/audit scope iv. Date/s conducted v. Conducted by vi. Audit ratinq/results BSP fT Outsourcing Questionnaire for TSP template updated as of 3'l January 2022 Page 3 of 3
同类文件 BSP Circulars
- Temporary Relief in the Inclusion of Effective Interest Rates in the Pawn Ticket as required under Circular No. 754 dated 17 April 2012(BSP Circular No. 787)
- Risk weight of credit exposures guaranteed by the LGU Guarantee Corporation (LGUGC); and Treastment of guarantees under the risk-based capital adequacy framework of stand-alone thrift banks, rural banks and cooperative banks(BSP Circular No. 717)
- Implementing Guidelines for the Setting of Variable Grace Period for Long-Gestating Agriculture and Fisheries Project(BSP Circular No. 217)
- Computation of the legal reserves on deposits and deposit substitutes of banks(BSP Circular No. 1367)
- Amend the definition of non-performing loans as provided for under Circular No. 202(BSP Circular No. 248)
- Amendment to Appendix I of CB Circular 1389, s. 1993 on List of Regulated Commodities(BSP Circular No. 2)
- Short-term deliverable forward contracts with non-residents(BSP Circular No. 344)
- Rationalizing the Regulatory Requirements of Trust, Other Fiduciary and Investment Management Accounts under Discretionary and Non-Discretionary Mandates(BSP Circular No. 966)
想要这份文件的分析?
让 ASG 法律 AI 为你总结、与其他判例对比,或说明它如何适用于你的情形 — 它检索的正是同一个数据库。