Outsourcing increases data management risks: APRA

13 December 2012
| By Staff |
image
image
expand image

Outsourcing data management responsibilities may exacerbate the risk in an institution's data lifecycle controls, the Australian Prudential Regulatory Authority (APRA) has warned.

In its prudential practice guide on data management, APRA said regulated institutions needed to ensure the maintenance of the quality of critical and sensitive data when entering into a data outsourcing arrangement.

The partnership would need to demonstrate a lack of impediments to the regulator's duties as well as comply with legislative and prudential requirements, it said. 

Institutions needed to show they could carry on with operations and core obligations if the provider experienced any loss of service, according to the guide.

APRA said offshoring could introduce even more risks including control framework variations, lack of proximity, reduced corporate allegiance, geopolitical risks and jurisdictional-specific requirements.

Institutions needed to make informed decisions about whether their risk appetite could handle the additional risks, it said.

APRA said it expected institutions to conduct a detailed risk analysis of the underlying service arrangement, including in the analysis the provider, its location, and the critical nature and sensitivity of the data involved.

It listed - as necessary steps to managing data outsourcing risks - enterprise frameworks such as IT security, project management, system development, business continuity management, outsourcing/offshoring management, risk management and delegation limits.

An understanding of the impacts on business processes and sensitivity of the data was also important in assessing a provider's suitability, APRA said.

APRA said it was necessary that board and senior management understood and accepted the risks involved, with the knowledge that any arrangements would be reviewed periodically in line with an institution's risk management framework.

APRA said it envisaged a regulated institution would ensure that appropriate controls were implemented to ensure data quality requirements were met at each stage of its lifecycle.

Read more about:

AUTHOR

Recommended for you

sub-bgsidebar subscription

Never miss the latest developments in Super Review! Anytime, Anywhere!

Grant Banner

From my perspective, 40- 50% of people are likely going to be deeply unhappy about how long they actually live. ...

11 months ago
Kevin Gorman

Super director remuneration ...

11 months 1 week ago
Anthony Asher

No doubt true, but most of it is still because over 45’s have been upgrading their houses with 30 year mortgages. Money ...

11 months 1 week ago

Jim Chalmers has defended changes to the Future Fund’s mandate, referring to himself as a “big supporter” of the sovereign wealth fund, amid fierce opposition from the Co...

3 days 17 hours ago

Demand from institutional investors was the main driver of growth in Australia’s responsible investment (RI) market in 2023, as the industry continued to gain momentum....

3 days 17 hours ago

In a new review of the country’s largest fund, a research house says it’s well placed to deliver attractive returns despite challenges....

3 days 18 hours ago