Outsourcing regulation in the financial services industry (as per the CSSF circular 22/806)

Formation intra-entreprise

À qui s'adresse la formation?

  • Chief risk officers and (operational) risk managers
  • Regulatory responsible and compliance officers
  • Internal auditors
  • Head of IT, information security officers and information technology officers
  • IT services providers serving entities under the supervision of the CSSF

Niveau atteint

Avancé

Durée

3,00 heure(s)

Langues(s) de prestation

EN

Prochaine session

Objectifs

Organisations in the financial services industry rely significantly on service providers as part of their operating model.

This training intends to provide the participants with an in-depth overview of the main regulatory requirements for outsourcing arrangements as defined by the CSSF circular 22/806.

By the end of this training, participants will be able to:

  • understand the main provisions of the CSSF circular 22/806;
  • identify the key changes introduced by the new circular compared to the existing regulatory framework;
  • distinguish between outsourcing arrangements and third party services;
  • assess the criticality of outsourcing arrangements;
  • understand the regulatory and practical implications of preparing CSSF notifications related to future outsourcing projects

Contenu

Introduction to outsourcing regulation

  • Evolution of regulatory landscape
  • Outsourcing drivers and benefits
  • Types of outsourcing arrangements
  • Identifying outsourcing arrangements
  • Assessing criticality

Outsourcing governance

  • Roles and responsibilities
  • The outsourcing policy
  • The outsourcing register
  • Contractual arrangements
  • Interacting with the regulator
  • Stages of the outsourcing lifecycle

ICT outsourcing and cloud computing

  • Definitions, roles and responsibilities
  • Cloud specific risks and limitations

Informations supplémentaires

This course is coordinated by Cécile Liégeois, Partner, and presented by Xiaoyi Fang, Senior Manager and Vojtech Volf, Manager at PwC Luxembourg.

Cécile has over 23 years of professional experience in Luxembourg and has developed deep knowledge of Luxembourg banking and investment firms regulations, amongst other topics, internal governance, outsourcing arrangements (BPO/ICT/Cloud) and operational/ICT risk management. She is leading projects on new regulations implementation focusing on business, regulatory and operational impacts. Cécile has experience in the external audit (financial and regulatory audit) of entities of the financial sector, mainly in the banking industry, other areas of the financial sector (investment firms, support and specialised PFS), management companies and investment funds.

Xiaoyi Fang, is a senior manager with in-depth experience in implementing European regulatory requirements, in reviewing the compliance framework for financial institutions and familiar with EU regulatory process in financial services.

She has driven and contributed to a number of projects in complex structures and dynamic environments.

Vojtech is a manager in our PwC regulatory and compliance department specialised in ICT compliance.

He has been working on IT compliance related topics for over 6 years and for PwC since 2018.

Vojtech works on various IT subjects related to IT compliance, PSD2, outsourcing (BPO/Cloud/IT), IT and security risks, privacy as well as payment related aspects. He also assists in various licence application processes, be it for e-money or payment institutions, IFMs where he focuses on IT aspects, data privacy as well as operational aspects for payments (payment flows, safeguarding, segregation etc.).

Ces formations pourraient vous intéresser