Outsourcing, Technology & Third-Party Service Providers
This guidance explains how licensed entities may outsource functions or rely on technology and third-party service providers while remaining accountable for regulatory compliance.
Purpose of This Guidance
Licensed entities often rely on external providers for technology, operations, or support services. This guidance clarifies the governance standards that apply when functions are outsourced or delegated.
General Principle
Outsourcing does not transfer regulatory responsibility. The licensed entity remains fully accountable for compliance with license conditions and conduct expectations.
Scope of Outsourcing
Outsourcing may include operational support, technology platforms, hosting, customer support, compliance services, or other delegated functions.
Due Diligence and Selection
Before appointing a third-party provider, licensees should assess suitability, competence, financial stability, and ability to meet service and security requirements.
Contractual Controls
- Clearly defined scope of services
- Confidentiality and data protection obligations
- Audit and access rights
- Termination and exit provisions
Ongoing Oversight
Licensees must monitor outsourced arrangements on an ongoing basis and address issues promptly where service or compliance concerns arise.
Notification and Approval
Material outsourcing or technology changes may require notification or prior approval under the change management framework.
Conclusion
Outsourcing can support efficiency and scalability, but accountability always remains with the licensed entity.