Overview
This Guidance is principles-based and should be applied proportionately to your size, complexity, risk profile, and the materiality of the outsourced activity. The Authority may request evidence of compliance during supervision.
What this Guidance covers
- Governance and accountability for outsourcing decisions
- Materiality assessment and risk classification
- Due diligence before engagement and ongoing monitoring
- Contract minimums (audit rights, SLAs, security, incident duties)
- Concentration risk, sub-outsourcing, and exit planning
- Cloud, data protection, and operational resilience expectations
Outsourcing includes delegation of a function, process, service, or activity to a third party that the licensee would otherwise perform itself, including intra-group arrangements where relevant.
A function is “material” where failure or degradation would materially impact: continuity of service; system integrity; confidentiality or data security; client outcomes; compliance; or the Authority’s ability to supervise.
Firms must apply this Guidance proportionately. Higher-risk and material arrangements require deeper governance, stronger contractual protections, and more frequent monitoring.
The licensee remains fully responsible for outsourced activities. Governance must define accountable owners, approval thresholds, and escalation processes for outsourcing decisions and incidents.
Maintain an outsourcing/third-party risk policy that covers: materiality criteria, due diligence, contract standards, oversight cadence, security controls, incident reporting, sub-outsourcing, and exit planning.
Maintain a current register of third-party arrangements including: provider, service, data types, locations, materiality rating, key SLAs, renewal dates, sub-processors, and exit plans.
Before engaging a provider, assess: operational impact, data exposure, cyber risk, compliance impact, service criticality, portability, concentration risk, and substitutability.
Due diligence should include, as applicable:
- corporate and ownership checks (including UBO/controller identification where relevant);
- financial stability and continuity indicators;
- security posture (certifications, controls, penetration testing summaries, vulnerability management);
- data protection posture and data residency capabilities;
- BCP/DR capability, RTO/RPO targets and test evidence;
- service delivery track record and incident history;
- sub-processor mapping and control over onward outsourcing.
Classify third parties (e.g., low/medium/high; material/non-material) and set oversight requirements accordingly. Material/high-risk services must have enhanced controls and documented approvals.
Contracts for material outsourcing should include:
- clear service description, responsibilities, and control boundaries;
- service levels (availability, support hours, response times, performance metrics);
- security obligations (access control, encryption, logging, vulnerability management);
- incident notification obligations with timeframes and cooperation duties;
- audit rights (direct or via independent assurance reports), including regulator access where applicable;
- sub-outsourcing controls (approval rights and full visibility of sub-processors);
- data handling terms (locations, retention, deletion, breach notification);
- business continuity and disaster recovery commitments;
- exit/termination rights, portability, and transition assistance;
- liability, indemnities, and remediation obligations proportionate to risk.
Contracts should require advance notice for material changes (sub-processors, locations, architecture, security posture) and allow the licensee to object or exit where risks become unacceptable.
Monitor performance against SLAs, security posture, incident trends, and control effectiveness. Material arrangements should have scheduled reviews and documented outcomes.
For higher-risk services, obtain independent assurance where available (e.g., SOC reports, ISO certifications, audit summaries) and evaluate exceptions with remediation tracking.
Ensure incident playbooks include third-party coordination, contact points, and clear obligations for evidence preservation, root-cause analysis, and timelines for corrective actions.
Identify dependencies on single providers, regions, or infrastructures (including cloud concentration). Where concentration is high, implement mitigants (multi-vendor strategy, portability planning, enhanced resilience testing).
Licensees must have visibility into sub-processors and retain control through approval rights, security standards, and contractual flow-down obligations.
Maintain exit plans for material providers, including data portability, transition timelines, minimum notice periods, replacement options, and tested restoration of service.
Identify data types processed by third parties and apply data minimisation. Apply stronger controls for sensitive data (identity documents, financial data, KYC records, transaction data).
Document where data is stored/processed, who can access it, and how access is controlled and logged. Ensure appropriate controls for cross-border processing and lawful disclosure requests.
For material services, implement encryption in transit and at rest. Where feasible, adopt robust key management practices and define responsibilities for key custody and rotation.
During supervision, the Authority may request evidence such as:
- outsourcing policy and governance approvals;
- outsourcing register and materiality assessments;
- due diligence pack and ongoing monitoring records;
- contracts (or key clause extracts) for material providers;
- BCP/DR test results, incident reports and remediation tracking;
- sub-processor lists and change notifications.
Licensees should notify the Authority of material outsourcing changes or significant third-party incidents where these may impact continuity, integrity, confidentiality, or compliance.
This Guidance is effective upon publication. Licensees should implement proportionate controls promptly and ensure material arrangements are reviewed and uplifted where gaps exist.
This Guidance supplements the supervisory framework and supports risk-based oversight. It does not replace or override obligations under applicable Acts, license conditions, or codes.