Jersey
cybersecurity
9 Jersey regulatory document(s) tagged cybersecurity.
Who is caught
The instruments indexed here address cybersecurity indirectly, through guidance and policy aimed at Jersey-regulated financial services businesses rather than through a dedicated cybersecurity rulebook. Scope is defined by the entities each instrument applies to.
- Regulated financial services firms: The JFSC guidance on the use of AI applies to financial services firms regulated in Jersey, and frames cybersecurity as one of the existing regimes firms must apply when deploying AI.
- Businesses conducting Regulated Activity: The Outsourcing Policy applies to Businesses performing Regulated Activity and to a range of named sectors, including Deposit-taking Business, Fund Services Business, Investment Business, Insurance Business, Money Service Business, and Trust Company Business, when they outsource activity (including Cloud Services) to Service Providers.
- The JFSC itself: The Registry system statement concerns a data security incident affecting the JFSC's own Registry system; it is a disclosure notice and does not bring regulated entities within any new scope.
Sources: Outsourcing Policy (OSP) · Registry system statement (2024-03-07) · Guidance on the use of AI in Jersey's financial services sector
Key duties
None of the indexed instruments is a standalone cybersecurity code. The AI guidance is expressly non-binding and creates no new requirements, while the Outsourcing Policy is binding and carries the operational and notification duties most relevant to cyber and technology risk.
Applying existing frameworks
- Integrate AI into existing controls: Under the AI guidance, firms should integrate AI into their existing cybersecurity and data protection frameworks, ensure lawful bases for processing personal data, validate input data quality, and manage third-party AI dependencies under existing outsourcing policy.
- Governance and oversight: Boards and senior managers should maintain clear ownership, oversight and accountability for AI-assisted processes, with human oversight of higher-impact decisions and stronger controls for autonomous AI.
- AI register: Firms should maintain a register recording AI use cases, data inputs, oversight and risk classification. This is a guidance expectation, not a binding requirement.
Outsourcing and cloud duties
- Prior notification and No Objection: Except where the Outsourcing Policy provides otherwise, a Business must submit an Outsourcing Notification via myJFSC before appointing a Service Provider, and the Service Provider must not begin work until the JFSC issues a No Objection.
- Material change notification: Any subsequent material change to an outsourcing arrangement, including termination or a new Service Provider, must be notified to the JFSC as soon as the Business becomes aware, using the Material Change to Outsourcing Notification.
- Written agreement: A written Outsourcing Agreement reflecting the risk, size and complexity of the activity must be in place before the outsourced activity begins.
- Fit and proper monitoring: A Business must ensure any Service Provider is and remains fit and proper, and maintain adequate capacity to monitor this on an ongoing basis.
- Contingency planning: Suitable contingency plans must be maintained for material disruption or unexpected termination of a Service Provider's performance.
- Regulatory access: A Business must ensure nothing in the Service Provider's performance restricts the JFSC's regulatory powers, and it remains accountable for outsourced activity, including work by sub-contractors or group service providers.
Sources: Outsourcing Policy (OSP) · Guidance on the use of AI in Jersey's financial services sector
Exemptions and carve-outs
The indexed instruments provide limited carve-outs, mostly framed as proportionality rather than exemption.
- Proportionate AI controls: The AI guidance is intended to be proportionate: low-impact productivity tools need only light-touch controls, while higher-impact uses warrant stronger governance, testing, monitoring and record-keeping. The guidance does not create new legal or regulatory requirements.
- Outsourcing notification exceptions: The Outsourcing Policy requires prior notification and a No Objection except where the policy specifically provides otherwise; the summary does not enumerate those specific cases.
- No public action: The Registry system statement states that no action is required from the public and imposes no new filing, reporting or compliance requirements on regulated entities.
Sources: Outsourcing Policy (OSP) · Registry system statement (2024-03-07) · Guidance on the use of AI in Jersey's financial services sector
Enforcement and penalties
The instruments indexed here do not set out specific penalty provisions. The AI guidance is non-binding, and the Registry statement is an informational disclosure. The Outsourcing Policy is binding as a requirement under the JFSC Codes of Practice, but the summaries do not describe the enforcement powers or penalties that apply to a breach.
Documents
| Citation | Regulator | Type |
|---|---|---|
| 2025 MoU between JDPA/Information Commissioner and Jersey Cyber Security Centre | JOIC | Agreement |
| Checklist Breach Response Plan | JOIC | Form |
| Consultation Paper No. 10 2018 - Amendments to Codes of Practice | JFSC | Consultation Paper |
| Guidance on the use of AI in Jersey's financial services sector | JFSC | Statement of Guidance |
| Key Findings from a Full Compliance Audit 2023/4 (2024-08-12) | JOIC | Advisory |
| Outsourcing Policy (OSP) | JFSC | Regulatory Policy |
| Public Statement - CSS Limited (2020-01-28) | JOIC | Notice |
| Public Statement - Jersey Financial Services Commission (2025-10-25) | JOIC | Notice |
| Registry system statement (2024-03-07) | JFSC | Notice |