Advisory
Managing Outsourcing Risk - Practices within the Banking Sector (2011-05)
Issued 2011-05-01View on GFSC's website Source document
Summary
This is a thematic report published by the Guernsey Financial Services Commission's Banking Division, summarising the results of a 2011 review into how Guernsey licensed banks manage outsourcing risk. It follows on from a 2008 thematic report and the Commission's April 2010 Outsourcing Risk Guidance Note for Banks, and combines an industry-wide survey (December 2010) with on-site visits to a sample of banks (completed March 2011). The report explicitly states it is not formal regulatory guidance but is intended to highlight examples of good and poor practice.
- Intra-group outsourcing is still outsourcing: The Commission does not accept that intra-group arrangements are inherently less risky than external ones and expects banks to treat them as outsourcing, addressing the same risk and performance issues.
- Exit strategies or contingency plans: Where a bank has not developed an exit strategy for an outsourced activity, the Commission expects an appropriate written contingency plan to be in place instead.
- Local oversight cannot be delegated away: Banks and subsidiaries cannot fully outsource oversight of their outsourcing arrangements to central group functions such as Internal Audit or Risk Management; local boards or branch management must actively monitor outsourced activities and service providers.
- Retained regulatory responsibility: Compliance with Guernsey legal obligations, including financial crime and sanctions screening duties, cannot itself be outsourced even where the underlying activity is performed by a service provider or group entity.
The report does not create new formal rules; it consolidates survey and site-visit findings to help Guernsey licensed banks benchmark and improve their existing outsourcing risk management frameworks against the 2010 Guidance Note and good industry practice.
Key obligations
- Banks should treat intra-group outsourcing arrangements with the same rigour and risk management as external outsourcing arrangements.
- Where a bank does not have an exit strategy for an outsourced activity, it should maintain an appropriate written contingency plan.
- Local boards or branch management must actively monitor outsourced activities and service providers rather than relying solely on central group functions for oversight.
- A bank cannot outsource its underlying regulatory or legal compliance responsibilities, even when related activities (e.g. sanctions screening) are performed by a service provider or intra-group unit.
Applies to
Guernsey Licensed Banks, Guernsey licensed banking subsidiaries, branches of overseas banks operating in Guernsey