Advisory

Data Security - A Thematic Report on Practices within the Fiduciary Sector (2014-04)

Guernsey Financial Services Commission (GFSC) · Guernsey

Issued 2014-04-16

Current version last checked: 2026-07-12

Summary

This is a thematic report published by the Guernsey Financial Services Commission summarising the results of a 2013 review of data security practices across Guernsey-licenced fiduciaries (trust and company service providers). It is explicitly stated not to be formal regulatory guidance, but instead sets out examples of good and poor practice observed through a sector-wide questionnaire and follow-up on-site visits.

  • Good practice observed: Up-to-date, board-reviewed security policies; effective third-party due diligence via on-site supplier audits; well-tested business continuity plans.
  • Common weaknesses identified: Data security risk assessed only as a single generic risk category rather than granularly; weak or inconsistent third-party supplier due diligence; inconsistent vetting of temporary staff and contractors compared to permanent employees; senior management unaware of audit trails for key applications; inadequate or one-off staff security awareness training.
  • Governance expectations highlighted: Boards are encouraged to discuss data security regularly (not just annually), formally assign an information security officer role, and run continuous cycles of risk assessment, control review and remediation, benchmarking against ISO 27001.

The report does not itself create new binding rules; it references the Commission's existing Code of Corporate Governance (requiring at least annual board review of risk management effectiveness) and urges licensees to use the findings to self-assess and improve their own data security governance, third-party contracts, staff vetting and training practices.

Applies to

fiduciary licensees, trust and company service providers, personal fiduciary licensees

Topics

Version history

2026-07-12

source file (current)