Outsourcing increases data management risks: APRA

13 December 2012
| By Staff |
image
image
expand image

Outsourcing data management responsibilities may exacerbate the risk in an institution's data lifecycle controls, the Australian Prudential Regulatory Authority (APRA) has warned.

In its prudential practice guide on data management, APRA said regulated institutions needed to ensure the maintenance of the quality of critical and sensitive data when entering into a data outsourcing arrangement.

The partnership would need to demonstrate a lack of impediments to the regulator's duties as well as comply with legislative and prudential requirements, it said. 

Institutions needed to show they could carry on with operations and core obligations if the provider experienced any loss of service, according to the guide.

APRA said offshoring could introduce even more risks including control framework variations, lack of proximity, reduced corporate allegiance, geopolitical risks and jurisdictional-specific requirements.

Institutions needed to make informed decisions about whether their risk appetite could handle the additional risks, it said.

APRA said it expected institutions to conduct a detailed risk analysis of the underlying service arrangement, including in the analysis the provider, its location, and the critical nature and sensitivity of the data involved.

It listed - as necessary steps to managing data outsourcing risks - enterprise frameworks such as IT security, project management, system development, business continuity management, outsourcing/offshoring management, risk management and delegation limits.

An understanding of the impacts on business processes and sensitivity of the data was also important in assessing a provider's suitability, APRA said.

APRA said it was necessary that board and senior management understood and accepted the risks involved, with the knowledge that any arrangements would be reviewed periodically in line with an institution's risk management framework.

APRA said it envisaged a regulated institution would ensure that appropriate controls were implemented to ensure data quality requirements were met at each stage of its lifecycle.

Read more about:

AUTHOR

Add new comment

The content of this field is kept private and will not be shown publicly.

Recommended for you

sidebar subscription

Never miss the latest developments in Super Review! Anytime, Anywhere!

Grant Banner

From my perspective, 40- 50% of people are likely going to be deeply unhappy about how long they actually live. ...

3 months 4 weeks ago
Kevin Gorman

Super director remuneration ...

4 months ago
Anthony Asher

No doubt true, but most of it is still because over 45’s have been upgrading their houses with 30 year mortgages. Money ...

4 months ago

The ethical investment manager has reported record FUM as its growth trajectory continues apace....

2 hours ago

The $135 billion fund has transitioned away from TAL Life Insurance following an “extensive tender process”....

2 hours 53 minutes ago

The chief investment officers of UniSuper, HESTA, and TelstraSuper have elaborated on opportunities and risks that are top of mind when it comes to illiquid assets like p...

5 hours ago

TOP PERFORMING FUNDS

ACS FIXED INT - AUSTRALIA/GLOBAL BOND