Advisory

Managing Outsourcing Risk - Practices within the Banking Sector (2011-05)

Guernsey Financial Services Commission (GFSC) · Guernsey

Issued 2011-05-01

Current version last checked: 2026-07-12

Summary

This is a thematic report published by the Guernsey Financial Services Commission's Banking Division, summarising the results of a 2011 review into how Guernsey licensed banks manage outsourcing risk. It follows on from a 2008 thematic report and the Commission's April 2010 Outsourcing Risk Guidance Note for Banks, and combines an industry-wide survey (December 2010) with on-site visits to a sample of banks (completed March 2011). The report explicitly states it is not formal regulatory guidance but is intended to highlight examples of good and poor practice.

  • Intra-group outsourcing is still outsourcing: The Commission does not accept that intra-group arrangements are inherently less risky than external ones and expects banks to treat them as outsourcing, addressing the same risk and performance issues.
  • Exit strategies or contingency plans: Where a bank has not developed an exit strategy for an outsourced activity, the Commission expects an appropriate written contingency plan to be in place instead.
  • Local oversight cannot be delegated away: Banks and subsidiaries cannot fully outsource oversight of their outsourcing arrangements to central group functions such as Internal Audit or Risk Management; local boards or branch management must actively monitor outsourced activities and service providers.
  • Retained regulatory responsibility: Compliance with Guernsey legal obligations, including financial crime and sanctions screening duties, cannot itself be outsourced even where the underlying activity is performed by a service provider or group entity.

The report does not create new formal rules; it consolidates survey and site-visit findings to help Guernsey licensed banks benchmark and improve their existing outsourcing risk management frameworks against the 2010 Guidance Note and good industry practice.

Key obligations

  • Banks should treat intra-group outsourcing arrangements with the same rigour and risk management as external outsourcing arrangements.
  • Where a bank does not have an exit strategy for an outsourced activity, it should maintain an appropriate written contingency plan.
  • Local boards or branch management must actively monitor outsourced activities and service providers rather than relying solely on central group functions for oversight.
  • A bank cannot outsource its underlying regulatory or legal compliance responsibilities, even when related activities (e.g. sanctions screening) are performed by a service provider or intra-group unit.

Applies to

Guernsey Licensed Banks, Guernsey licensed banking subsidiaries, branches of overseas banks operating in Guernsey

Topics

Version history

2026-07-12

source file (current)