{"id":"circulars/faq-cssf-faq-circular-cssf-22-806-on-outsourcing-arrangements","title":"CSSF FAQ – Circular CSSF 22/806 on outsourcing arrangements","type":"circular","date":"2022-04-22","kind":"faq","html":"<p>CSSF FAQ – Circular CSSF 22/806 on outsourcing arrangements is a CSSF FAQ, published 22 April 2022.</p>\n<p>Legal basis: <a href=\"/lhoft?page=laws%2F1993-04-05-n1\" class=\"wikiLink\" data-target=\"laws/1993-04-05-n1\">Law of 5 April 1993 on the financial sector</a>, <a href=\"/lhoft?page=laws%2F2009-11-10-n1\" class=\"wikiLink\" data-target=\"laws/2009-11-10-n1\">Law of 10 November 2009 on payment services and electronic money</a>, <a href=\"/lhoft?page=laws%2F2010-12-17-n9\" class=\"wikiLink\" data-target=\"laws/2010-12-17-n9\">Law of 17 December 2010 on undertakings for collective investment</a>.</p>\n<p>Relevant for: Management companies - Chapter 16, Payment institutions, Specialised PFS, Support PFS.</p>\n<p>Keywords: Cloud, Information and communications technology (ICT), Internal governance, Operational risk, Outsourcing.</p>\n<h2>Text</h2>\n<p>on outsourcing arrangements</p>\n<p>on outsourcing arrangements To all credit institutions and professionals of the financial sector within the meaning of the Law of 5 April 1993 on the financial sector (LFS) To all payment institutions and electronic money institutions within the meaning of the Law of 10 November 2009 on payment services (LPS) To all management companies authorised only under Article 125-1 of Chapter 16 of the Law of 17 December 2010 relating to undertakings for collective investment (UCITS Law)</p>\n<p>Luxembourg, 22 April 2022 Ladies and Gentlemen, Supervised entities that fall under the scope of the Law of 5 April 1993 on the financial sector (LFS) and of the Law of 10 November 2009 on payment services (LPS) are required to adopt robust internal governance arrangements, which shall include a clear organisational structure, adequate internal control mechanisms, including sound administrative and accounting procedures and practices allowing and promoting sound and effective risk management, as well as control and security mechanisms for their IT systems. The European Banking Authority (EBA) has issued revised Guidelines on outsourcing arrangements (EBA/GL/2019/02 or the Guidelines). The CSSF, in its capacity as competent authority, applies the Guidelines and consequently, with a view to contribute to supervisory convergence at European level, has integrated them into its administrative practice and regulatory approach. While the Guidelines apply to credit institutions, investment firms and payment and electronic money institutions only, the CSSF has chosen to extend the scope of application of this circular in order to promote convergence on a national level. All entities referred to under point 2 are expected to duly comply with this circular, and to take implementing measures that are proportionate to the nature, scale and complexity, including their risks, of their operations. This circular complements the framework on internal governance arrangements by specifying guiding principles and laying down additional detailed requirements 1 that supervised entities must observe when resorting to outsourcing arrangements. Therefore, this circular shall be read together with those relevant legal provisions 2 and the circulars CSSF on central administration, internal governance and risk management 3 as applicable to supervised entities. This circular contains in one single document the supervisory requirements on outsourcing arrangements related to information and communication technology, that were previously disseminated in individual circulars. Such precisions are provided in italics in Part I and III of the Circular. Outsourcing arrangements shall at all times comply with the organisational requirements for outsourcing in accordance with Articles 36-2 or 37-1(5) LFS and Articles 11(4) or 24-7(4) LPS, where applicable. 3 For example, Circular CSSF 12/552 for credit institutions and Circular CSSF 20/758 for investment firms. 1 2</p>\n<p>This circular is divided in three parts: the first part sets out the requirements in relation to outsourcing arrangements and includes definitions, scope of application, general principles and applicable governance requirements; the second part is dedicated to specific requirements for ICT outsourcing arrangements relying or not on a cloud computing infrastructure and the third part provides for the entry into force of this circular. As of 17 January 2025, the provisions of the Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, apply to all financial entities as defined under Article 2(1), points (a) to (t) of DORA.</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/cssf-faq-circular-cssf-22-806-on-outsourcing-arrangements/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/cssf22_806eng.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}