Statement of Guidance
Statement of Guidance: Outsourcing – Regulated Entities (April 2023)
In forceView on CIMA's website Source document
Summary
This is CIMA's April 2023 Statement of Guidance on Outsourcing, setting out the Authority's minimum expectations for how regulated entities should establish, manage and oversee outsourcing arrangements (including sub-outsourcing) for material functions or activities. It applies to all entities regulated by CIMA, including controlled subsidiaries as defined under the Banks and Trust Companies Act, but expressly excludes regulated mutual funds, Private Trust Companies and Private Funds as defined in their respective Acts.
The Guidance emphasizes that a regulated entity's Governing Body and Senior Management remain ultimately responsible for outsourced functions regardless of outsourcing.
- Materiality assessment: Assessing the materiality of outsourcing arrangements.
- Intra-group and branch outsourcing: Managing intra-group and branch outsourcing.
- Risk management framework: Implementing a risk management framework.
- Due diligence: Conducting due diligence on Service Providers.
- Written agreements: Entering into detailed written outsourcing agreements.
- Oversight and audit rights: Maintaining oversight and audit rights.
- Termination and exit planning: Planning termination/exit strategies.
- Books and records: Keeping books and records accessible to CIMA.
It also imposes ongoing obligations to notify CIMA of new or terminated outsourcing agreements for material functions, to maintain a centralized log of material outsourcing arrangements, and to conduct risk assessments and due diligence reviews at least annually or more frequently based on risk. While framed as guidance rather than binding rules, CIMA treats it as setting supervisory expectations that regulated entities are expected to follow, and non-compliance can factor into CIMA's supervisory assessments.
Key obligations
- Assess the materiality of all outsourcing arrangements considering financial, operational, reputational and control impacts (section 4).
- Treat outsourcing of all or substantially all of a management oversight function as material by default.
- Implement a Governing-Body-approved outsourcing policy and an adequate risk management framework, systems, policies and processes to assess, control and monitor material outsourcing arrangements.
- Conduct a risk assessment of each material outsourcing arrangement before initiation and at least annually thereafter (or more frequently based on risk).
- Conduct risk assessments of the jurisdiction of any Service Provider located outside the Cayman Islands and mitigate identified risks.
- Perform and document (in writing) due diligence on each Service Provider before entering into an outsourcing agreement and at least annually thereafter (or more frequently based on risk).
- Maintain a centralized, continuously updated log of all material outsourcing arrangements, accessible to CIMA upon request.
- Enter into a detailed, legally binding written outsourcing agreement for all material outsourcing arrangements, covering scope, responsibilities, conflicts of interest, remuneration, contingency/business continuity plans, audit rights, and termination provisions.
- Ensure books and records pertaining to outsourced material functions/activities remain readily accessible to CIMA.
- For branches covered by head-office outsourcing arrangements, obtain written confirmation of specified details and maintain a log of applicable outsourcing arrangements.
- Establish termination and exit strategies for outsourcing arrangements, including transfer-back or transition-to-new-provider processes.
- Notify CIMA in writing, within a reasonable timeframe, of any new outsourcing agreement signed or terminated involving a material function or activity, including specified details (function outsourced, Service Provider name/status, location, commencement/expiration dates, reasons).
- Notify CIMA of termination of an outsourcing agreement with Service Provider name, termination date, reason, and how the function will subsequently be performed.
- Disclose to CIMA any matter that could materially and adversely affect the financial soundness of the regulated entity in connection with outsourcing.
- Where uncertain whether a function is material, communicate with CIMA.
Applies to
all entities regulated by CIMA, controlled subsidiaries as defined in the Banks and Trust Companies Act, banks, branches of regulated entities
Deadlines
- at least annually: Regulated entities should complete risk assessments of material outsourcing arrangements at least annually or more frequently depending on risk and materiality.
- at least annually: Due diligence assessments of Service Providers should be performed before the initial outsourcing agreement and thereafter at least annually or in keeping with perceived risk.
- within a reasonable timeframe: Regulated entities should notify the Authority in writing of any new outsourcing agreement signed or terminated involving a material function or activity.