Statement of Guidance
Statement of Guidance - Outsourcing Regulated Entities (April 2023)
In forceView on CIMA's website Source document
Summary
This is CIMA's Statement of Guidance on Outsourcing (April 2023), which sets out the Authority's minimum expectations for how regulated entities should establish, manage and oversee outsourcing arrangements (including sub-outsourcing) for material functions or activities. The guidance covers arrangements with both related and unrelated service providers, including intra-group and branch/head-office outsourcing.
Scope of Application
- Applies to: virtually all entities regulated by CIMA under the regulatory Acts, including controlled subsidiaries as defined under the Banks and Trust Companies Act.
- Excludes: regulated mutual funds, private trust companies, and private funds.
Core Requirements
- Materiality assessment: regulated entities must assess the materiality of outsourcing arrangements.
- Governance and accountability: maintain governance and accountability equivalent to in-house functions.
- Risk limits: ensure outsourcing does not increase net risk, alter client relationships, or turn the entity into a 'shell' or 'letter-box' entity.
- Risk management framework: detailed expectations for risk management frameworks and due diligence on service providers.
- Written agreements: written outsourcing agreements with specific required content.
- Monitoring and planning: ongoing monitoring, contingency and exit planning.
- Governance responsibilities: split between the Governing Body and Senior Management.
Notification to CIMA
- Notification duty: entities must notify CIMA in writing of new or terminated outsourcing agreements for material functions and provide specified details.
- Centralized log: keep a centralized log accessible to the Authority.
- Records access: ensure books and records relating to outsourced functions remain accessible to CIMA.
As guidance rather than binding rules, it reflects CIMA's supervisory expectations under section 34 of the Monetary Authority Act rather than creating standalone statutory penalties, but non-compliance is likely to be assessed as part of CIMA's supervisory review of a regulated entity's risk management.
Key obligations
- Assess the materiality of each outsourcing arrangement, considering financial, operational, reputational and data-access impacts before outsourcing a function.
- Treat outsourcing of all or substantially all of a management oversight function as material by default.
- Maintain the same level of oversight, accountability and internal controls over outsourced material functions as over non-outsourced functions, without increasing net risk or altering client relationships.
- Ensure outsourcing does not cause the entity to become a 'shell' or 'letter-box' entity and that required staff/books and records remain in the Cayman Islands where applicable.
- Keep all books and records relating to outsourced material functions readily accessible to CIMA.
- Implement a Governing Body-approved outsourcing policy and a documented risk management framework to identify, assess, control and monitor material outsourcing arrangements.
- Conduct a risk assessment of each material outsourcing arrangement before initiation and thereafter at least annually or more frequently based on risk.
- Conduct risk assessments of the jurisdiction where a service provider is located if outside the Cayman Islands.
- Perform and document written due diligence on a service provider before entering an outsourcing agreement and at least annually thereafter (or more frequently based on risk).
- Maintain a centralized, continuously updated log of all material outsourcing arrangements, accessible to the Authority upon request.
- Have a detailed, legally binding written outsourcing agreement for every material outsourcing arrangement, containing specified minimum content (scope, responsibilities, conflicts of interest, remuneration, contingency/business continuity plans, etc.).
- For intra-group outsourcing of material functions, ensure at minimum a written agreement, business continuity plan, monitoring/reporting process, exit strategy, appropriate record location, and comparable audit/risk controls.
- For branches covered by head-office outsourcing arrangements, obtain written confirmation of specified details and maintain a log of applicable arrangements, ensuring proper assessment and monitoring.
- Notify the Authority in writing, within a reasonable timeframe, of any new outsourcing agreement signed or terminated involving a material function, including specified details (function outsourced, service provider name/location, dates, reason).
- Provide specified minimum details to the Authority upon termination of an outsourcing agreement.
- Disclose to the Authority any matter relating to outsourcing that could materially and adversely affect the entity's financial soundness.
- Ensure Governing Body and Senior Management fulfill specified oversight, approval, monitoring and reporting responsibilities regarding outsourcing arrangements.
- Establish a termination and exit strategy for each material outsourcing arrangement, including provisions in the agreement for termination process and transfer of the outsourced activity.
Applies to
entities regulated by CIMA generally, controlled subsidiaries (as defined in the Banks and Trust Companies Act), branches of regulated entities, entities within group structures
Deadlines
- at least annually: Regulated entities must conduct a risk assessment of each material outsourcing arrangement before initiation and at least annually thereafter (or more frequently based on risk level).
- at least annually: Regulated entities must perform due diligence on each service provider before entering the initial outsourcing agreement and at least annually thereafter (or more frequently based on perceived risk).
- within a reasonable timeframe: Regulated entities must notify the Authority in writing of any new outsourcing agreement signed or terminated involving a material function or activity.