{"id":"circulars/faq-faq-on-the-assessment-of-it-outsourcing-materiality","title":"FAQ on the assessment of IT outsourcing materiality","type":"circular","date":"2026-03-04","kind":"faq","html":"<p>FAQ on the assessment of IT outsourcing materiality is a CSSF FAQ, published 4 March 2026.</p>\n<p>Relevant for: AIFMs, AISPs, Credit institutions, E-money institutions, Investment firms, Investment fund managers, Management companies - Chapter 15, Management companies - Chapter 16, Payment institutions, Payment institutions/electronic money institutions/AISPs, Specialised PFS, Support PFS.</p>\n<p>Keywords: Cloud, Information and communications technology (ICT), Outsourcing.</p>\n<h2>Text</h2>\n<p>Frequently Asked Questions on the assessment of IT outsourcing materiality Disclaimer: The answers to the “Frequently Asked Questions” (hereafter “FAQs”) solely intend to assist the supervised entities in assessing the materiality of their IT outsourcing projects. Based on this assessment, the supervised entities might be required to inform the CSSF or request for authorization, as specified in the circulars CSSF 12/552, 17/654, 17/656, 18/698 and 20/758. We remind the supervised institutions that whatever the materiality of an IT outsourcing, they always have to perform a due diligence and a risk analysis of their IT outsourcing project. For clarity purpose, in this document “material IT outsourcing” refers to any “IT outsourcing that support material activities”.</p>\n<p>QUESTION 1: What does “IT outsourcing” mean? Updated on 4 December 2019 IT outsourcing means an arrangement of any form between the institution and a service provider (including of the same group) by which that service provider performs an IT process, an IT service or an IT activity that would otherwise be undertaken by the institution itself.</p>\n<p>QUESTION 2: What does “material activity” mean? Date of publication: 27 March 2019 Any activity that, when it is not carried out in accordance with the rules, reduces the institution’s ability to meet the regulatory requirements or to continue its operations as well as any activity necessary for sound and prudent risk management shall be deemed to be \"material\".</p>\n<p>QUESTION 3: How to assess the materiality of an IT outsourcing? Updated on 4 December 2019 An IT outsourcing is considered material if at least one of the following statements is met:</p>\n<p>FREQUENTLY ASKED QUESTIONS ON THE ASSESSMENT OF IT OUTSOURCING MATERIALITY Version: Dated 4 December 2019</p>\n<p>From a technical point of view, the outsourced IT operational functions, activities or services safeguard the security and continuity of critical parts of the IT infrastructure. A deficiency in these outsourced IT operational functions, activities or services may significantly disrupt the ability of the supervised entity to protect its IT infrastructure and, therefore, the ability of the supervised entity to operate its material activities in a controlled manner.</p>\n<p>From a business point of view, the outsourced IT operational functions, activities or services support a material activity. In case of failure or dysfunction of the IT operational functions, activities or services, there is a major impact on the business activity. This major impact may be one of the following in nature1: </p>\n<p>A financial impact, including (but not limited to) loss of funds or assets, potential customer compensation, legal and remediation costs, contractual damages, loss of revenue.</p>\n<p>A potential for business disruption, considering (but not limited to) the criticality of the financial services affected; the number of customers and/or branches and employees potentially affected.</p>\n<p>A potential reputational impact on the institution based on the criticality of the financial service or operational activity affected (e.g. theft of an important volume of customer data); the external profile/visibility of the IT systems and services affected (e.g. mobile or on-line banking systems, point of sale, ATMs or payment systems).</p>\n<p>A regulatory impact, including the potential for public censure by the regulator, fines or even variation of permissions.</p>\n<p>A strategic impact on the institution, for example if strategic product or business plans are compromised or stolen.</p>\n<p>QUESTION 4: Can you provide examples of materiality assessment for IT outsourcing? Date of publication: 27 March 2019 The following examples use the above mentioned definitions and rules to assess the materiality of an IT outsourcing.</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/faq-on-the-assessment-of-it-outsourcing-materiality/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/FAQ_materiality.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}