Skip to main content

EIOPA Guidelines on outsourcing to cloud service providers: Implementation and how to become complia

Page 1

EIOPA Guidelines on outsourcing to cloud service providers: Implementation and how to become compliant


1

Ole Horsfeldt

Tue Goldschmieding

Partner

Partner

D +45 33 41 43 65 M +45 24 28 68 40 oho@gorrissenfederspiel.com

D +45 33 41 42 03 M +45 24 28 68 75 tgg@gorrissenfederspiel.com


Introduction EIOPA as an institution

EIOPA Guidelines The European Insurance and Occupational Pension Authority (“EIOPA”) issued a consultation paper on 1 July 2019 on their draft guidelines for outsourcing to cloud service providers. The consultation period ended in September 2019 and EIOPA subsequently released the final report on the 7 February 2020 (“EIOPA Guidelines”). In light of the release of the final report. we recommend that our clients commence the process of reviewing their current and upcoming cloud outsourcing arrangements, in order to ensure that they are compliant with the EIOPA Guidelines in accordance with the relevant deadlines. The EIOPA Guidelines are addressed to competent authorities to provide guidance on how insurers and reinsurers (“Undertakings”) should apply the outsourcing provisions in Directive 2009/138/EC (“Solvency II Directive”) and the Commission Delegated Regulation (EU) 2015/35 (“Delegated Regulation”) to outsourcings to cloud service providers. Moreover, the EIOPA Guidelines also build on the EIOPA Guidelines on System of Governance (EIOPA-BoS-14/253).

Further, in order to avoid regulatory fragmentation, the EIOPA Guidelines take account of the EBA guidelines on outsourcing arrangements EBA/GL/2019/02 (“EBA Guidelines”), which may also apply to such Undertakings. Furthermore, as with the EBA Guidelines, the EIOPA Guidelines may be implemented into the Danish legislative framework. The draft amendment to the Danish Financial Business Act (Lov om finansiel virksomhed) specifically allows the minister of industry, business and financial affairs (Erhvervsminister) to implement an Executive Order on outsourcing for insurance and reinsurance undertakings.

2


Application of Guidelines … and what to consider

1

Definition of Outsourcing The EIOPA Guidelines refer to the definition of “outsourcing” provided under Solvency II Directive, meaning “an arrangement of any form between an insurance or reinsurance undertaking and a service provider, whether a supervised entity or not, by which that service provider performs a process, a service or an activity, whether directly or by sub-outsourcing, which would otherwise be performed by the insurance or reinsurance undertaking itself” (Article 13(28), Solvency II Directive). In addition, the EIOPA Guidelines further state that when assessing whether an arrangement with a cloud service provider constitutes an “outsourcing”, an Undertaking must assess whether the function or activity (or a part thereof) outsourced is performed on a recurrent or an ongoing basis and whether this function or activity (or part thereof) would normally fall within the scope of functions or activities that would or could be performed by the Undertaking in its regular business activities. Recommendation: The EIOPA Guidelines do not materially amend the definition of an outsourcing, as stated under the Solvency II Directive, meaning that no major re-appraisal of an Undertaking’s outsourcing arrangements should be required (as was the case with regard to the EBA Guidelines). These considerations, along with the additional clarifications in the EIOPA Guidelines relating to service providers covering multiple functions and activities, should be employed when evaluating whether an arrangement with a cloud service provider constitutes an “outsourcing”.

3


2

Cloud Outsourcing The scope of the EIOPA Guidelines is limited to outsourcing to cloud service providers ­ (i.e. a cloud outsourcing). A cloud service in this context means “services provided using cloud computing, that is, a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g. networks, servers, storage, applications and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction” (cf. EIOPA Guidelines, Introduction). However, the EIOPA Guidelines further clarify that where the Undertaking outsources operational functions or activities to service providers which are not cloud service providers but which rely significantly on cloud infrastructures to deliver their services, the arrangement for such outsourcing also falls within the scope of the EIOPA Guidelines. Recommendation: Undertakings are therefore encouraged to review all cloud arrangements, as well as outsourcings to non-cloud service providers which may significantly rely on cloud infrastructures to deliver services, to assess to what extent they fall under the scope of the EIOPA Guidelines.

3

Critical or important operational functions and activities The EIOPA Guidelines state that “prior to entering any cloud outsourcing arrangement, the Undertaking should assess whether the cloud outsourcing arrangement relates to an operational functional or activity that is critical or important” (reflecting the terminology used in the Solvency II Directive and Delegated Regulation). In order to conduct this assessment, the EIOPA Guidelines include a number of additional factors that should be considered when evaluating whether operational functions or activities are critical or important, such as the potential impact of outages and the ability to transfer the cloud outsourcing to a replacement service provider. Specific requirements under the EIOPA Guidelines apply to such critical and important cloud outsourcings, though some general requirements shall also apply to non-critical or important arrangements. Recommendation: Undertakings must therefore conduct an assessment of the criticality and importance of operational functions and activities being outsourced, in order to establish which of the compliance obligations of the EIOPA Guidelines shall apply to the outsourcing arrangement. Moreover, it may be necessary to reconduct this assessment if the nature, scale and complexity of the risks inherent in an arrangement materially changes.

4


Timeline for compliance

1 Ja

All new or am must be in ­EIOPA Guid Updates policies an (where ­app comple

31 January 2020

1 July 2019 EIOPA released consultation paper on the draft guidelines for insurers and reinsurers out­ sourcing to cloud service providers.

5

EIOPA released final ­report on guidelines on outsourcing to cloud ­service providers.


anuary 2021

31 December 2022 All cloud arrangements, new and existing, which ­relate to critical or important operational functions or a ­ ctivities must be compliant with the revised EIOPA G ­ uidelines. If such cloud outsourcing arrangements are not compliant by this date, the Undertaking must ­inform its supervisory authority (i.e. the Danish FSA for Danish U ­ ndertakings). Documentation requirements for such cloud out­ sourcings must also be ­implemented by this date.

mended arrangements compliance with the delines from this date. s to Undertakings’ nd internal processes plicable) must also be eted by this date.

Potential implementation There may be some local implementation of the EIOPA Guidelines in Denmark (e.g. an executive order), as we have seen with the EBA Guidelines.

6


7


Requirements

Internal governance requirements The EIOPA Guidelines outline several requirements for Undertakings’ internal governance setup, including both new requirements as well as an elaboration on existing requirements. The scope of these governance requirements include: ▪ Obligations relating to pre-outsourcing analysis to be conducted by Undertakings, including: (a) assessing if the cloud outsourcing arrangement concerns a critical or important operational function or activity, (b) conducting a risk assessment of cloud outsourcing, (c) undertaking appropriate due diligence on a prospective cloud service provider, and (d) identifying any conflicts of interest.

While these requirements largely build on existing obligations and/or good practice, they introduce additional bureaucratic requirements when entering into new outsourcing arrangements and maintaining oversight of active arrangements, which must be incorporated into Undertakings governance procedures. It should also be noted that any updates to Undertakings’ written outsourcing policies must be completed by 1 January 2021, while the documentation requirements for cloud outsourcing arrangements related to critical or important functions or activities should be implemented by 31 December 2022.

▪ Updating the Undertakings written outsourcing policy and other relevant internal policies (e.g. information security policy), with regard to specifically highlighted considerations. ▪ Document all cloud outsourcing arrangements, for example, in the form of a dedicated register, to be kept updated. Specific information must be recorded for cloud outsourcing arrangements related to critical or important functions or activities. ▪ Monitor on an ongoing basis the service providers performance of activities, security measures and adherence to service levels.

8


Notification

Contractual requirements

Building on the written notification obligations under the Solvency II Directive (Article 49(3)), as further detailed in the EIOPA Guidelines on System of Governance (EIOPA-BoS-14/253), Undertakings must give notice to supervisory authorities when amending or entering into new cloud outsourcing arrangements which relate to critical or important functions and activities.

The contractual requirements imposed by the EIOPA Guidelines build on the specific contractual requirements outlined in the Delegated Regulation, Article 274. The scope of these contractual requirements apply to the outsourcing of critical or important operational functions or activities to cloud service providers.

The scope of what should be included in such notification is subject to the principle of proportionality but should include as a minimum the items listed in the EBA Guidelines. This includes, for example, a description of the operational function or activity outsourced and a brief summary of the reasons why the outsourced operational function or activity is considered critical or important. While the obligation to notify supervisory authorities of an outsourcing of critical or important functions or activities is not a new requirement, the scope of what is to be included has been significantly expanded. Moreover, it is unclear whether the scope of any previous notifications of the outsourcing of critical or important functions and activities to cloud service providers will be sufficient, or whether new notifications should be prepared on the basis of the new scope of notifications. In order to avoid the risk of non-compliance, we are advising our clients to prepare notifications on all arrangements which involve the outsourcing of critical or important operational functions and activities to cloud service providers. 9

Generally, we welcome these additional requirements as many of them touch upon areas which, in our opinion, are highly important to regulate in order to achieve a useful and practically manageable outsourcing agreement. However, at the same time, the introduction of these additional contractual requirements together with a need for compliance not only for new but also for all existing cloud outsourcing arrangements, will become a complex and comprehensive task for all Undertakings in the near future. Given that these new requirements are based on what we believe will become mandatory legal requirements, we do not expect the implementation process into existing outsourcing contracts to be difficult. However, the commercial aspects relating to such implementation are not governed by the Guidelines and thus the need for new and stricter provisions may lead to renewed negotiations on price and risk allocation.


Clear service descriptions Financial obligations

System and data security Data privacy protection Risk analysis and contingency plans Governing law and dispute resolution Sub-contractors and service locations Reporting obligations to authorities Termination, re-transfer and step-in Access, monitoring and audit rights 10


GF’s EIOPA Guidelines compliance offerings

Benefits ▪ Efficient training of existing and new team members ▪ Access to best practice policies and procedures ▪ Consistent and cost efficient assessments ▪ Use of best practice compliant contract terms and conditions ▪ Easy accessible and concise document of compliance

11


Gorrissen Federspiel is establishing an offering aimed at insurance and reinsurance ­organisations, which will include the following features:

E-learning module ▪ Fixed price assessment of needs for updating per document or portfolio of documents

Assessment of current or future agreements ▪ Fixed price assessment of needs for updating per document or portfolio of documents ▪ Provision of compliant best practice terms and conditions in rider format ▪ Negotiation support leveraging our experience from dealings with suppliers across many engagements

Template policies, notifications, assessments, and registers ▪ Customised and completed to meet specific client requirements

Compliance documentation per contract ▪ Completed GF tracker tool per contract

12


Axeltorv 2 1609 Copenhagen V Denmark T +45 33 41 41 41 Silkeborgvej 2 8000 Aarhus C Denmark T +45 86 20 75 00 gorrissenfederspiel.com


Turn static files into dynamic content formats.

Create a flipbook
EIOPA Guidelines on outsourcing to cloud service providers: Implementation and how to become complia by Gorrissen Federspiel - Issuu