Outsourcing – Guidance on the Legal and Regulatory Framework
Total Page:16
File Type:pdf, Size:1020Kb
Outsourcing – Guidance on the Legal and Regulatory Framework 2020 EU-DOCS\28850674.8 Contents CONTENTS .......................................................................................................... 1 EXECUTIVE SUMMARY ...................................................................................... 3 Scope of this Paper ......................................................................................................................................... 4 KEY THEMES ...................................................................................................... 5 Outsourcing Mapping Table ............................................................................................................................ 6 PART ONE EUROPEAN LEVEL OUTSOURCING GUIDANCE ......................... 9 EBA Guidelines ............................................................................................................................................... 9 EIOPA guidelines .......................................................................................................................................... 12 PART TWO OTHER EUROPEAN LEVEL CONSIDERATIONS ........................ 15 Markets in Financial Instruments Directive (2014/65/EU) (“MiFID II”) ........................................................... 15 MiFID II Commission Delegated Regulation (EU) 2017/565 ......................................................................... 16 General Data Protection Regulation (EU) 2016/679 ...................................................................................... 19 Directive concerning measures for a high common level of security of network and information systems (EU) 2016/1148 ............................................................................................................................... 21 Capital Requirements Directive (2013/36/EU) (“CRD IV”) ............................................................................. 24 Money Laundering Directive (EU) 2015/849 (“MLD”) .................................................................................... 25 Benchmarks Regulation (EU) (2016/1011) (“BMR”) ...................................................................................... 27 ESMA Guidelines On Certain Aspects Of MIFID Compliance Function Requirements (28 September 2012 (Updated 5 June 2020)) (2012/388) (The “ESMA Guidelines”) .................................... 28 Outsourcing post-brexit: EBA and ECB guidance ......................................................................................... 30 The Revised Payment Services Directive (EU) 2015/2366 ........................................................................... 32 PART THREE JURISDICTION SPECIFIC GUIDANCE ..................................... 33 France ........................................................................................................................................................... 34 Germany ....................................................................................................................................................... 39 Ireland ........................................................................................................................................................... 46 Italy ................................................................................................................................................................ 50 Luxembourg .................................................................................................................................................. 62 Spain ............................................................................................................................................................. 66 United Kingdom ............................................................................................................................................. 73 SCHEDULE 1 TEMPLATE OUTSOURCING REGISTER ................................. 81 SCHEDULE 2 PART A – CHECKLIST FOR CONTRACTUAL REQUIREMENTS UNDER THE EBA GUIDELINES ......................................... 84 SCHEDULE 2 PART B - CHECKLIST FOR CONTRACTUAL REQUIREMENTS UNDER THE CLOUD RECOMMENDATIONS ..................... 99 SCHEDULE 3 CHECKLIST FOR CONTRACTUAL REQUIREMENTS UNDER THE EIOPA GUIDELINES ................................................................. 108 SCHEDULE 4 UK SPECIFIC REGULATION .................................................. 125 SCHEDULE 5 COMPARISON MIFID II DELEGATED REGULATION AND EBA GUIDELINES .................................................................................. 136 ABOUT THE AUTHORS .................................................................................. 146 CONTACTS FOR FURTHER ADVICE ............................................................ 147 2 Outsourcing: The Legal and Regulatory Framework EXECUTIVE SUMMARY It is common for firms to outsource certain functions, whether to group entities or to third parties, and firms must comply with a range of regulatory requirements (from different sources) in relation to outsourcing. Compliance and legal teams (both in the first line and the second line) may be responsible for compliance with the regulatory requirements. With this in mind, members of AFME’s Compliance Committee and Compliance Issues working group worked with Latham & Watkins to create this outsourcing reference paper. It consolidates the European legal and regulatory requirements for outsourcing arrangements with group entities and third parties. It also contains information on relevant enforcement decisions. The reference paper is intended to help compliance and legal teams meet their responsibilities in relation to outsourcing arrangements. The reference paper also considers the relationship between branches and head offices in outsourcing arrangements, and provides information on the requirements and approaches in France, Germany, Ireland, Italy, Luxembourg, Spain and the United Kingdom. Where appropriate, we may use the paper as a basis for requesting guidance from regulators (EBA, ECB, EU27, UK) in order to support firms’ compliance. Given the regulatory and legislative changes that are expected to occur in relation to firms’ outsourcing arrangements, we plan to update this reference paper on an ongoing basis. Please note that this Paper is intended for general informational purposes only, and does not provide, and does not constitute, investment, tax, regulatory, business or legal advice to any individual or entity. Latham & Watkins 3 INTRODUCTION In light of the plethora of legislative change and the increasing regulatory focus on outsourcing in the financial services space, as well as the growing range of sources that need to be taken into account to ensure compliance in this area, this document (the “Paper”) is designed to provide a single reference point for compliance, legal and risk teams within regulated firms of the key legislation, rules, and guidance (including from enforcement cases1) that they may wish to consider from an outsourcing perspective. This has become a focus topic in light the growing body of guidance, the need for firms to respond to unforeseen events, increasing reliance on a small range of IT providers (for example, in relation to the cloud), and its interconnectedness to the broader topic of operational resilience. In particular, it is common for firms to outsource certain functions, whether to group entities or to third parties. The business teams or functions responsible for the outsourcing will be responsible for ensuring compliance with applicable regulatory requirements. There is also a reliance on (i) arrangements set up by group functions, and (ii) other branches within the same legal entity, where there are questions around the extent of application of regulatory requirements, particularly in a Brexit context. The purpose of this Paper is therefore to act as a reference point by drawing together the regulatory requirements and relevant enforcement decisions in relation to outsourcing (and to identify the scope requirements), in order to help risk, business, compliance and legal teams with their role in this respect. Scope of this Paper This Paper is divided into the following three parts: Part One – European Level Outsourcing Guidance This part of the Paper provides an overview of the European-wide outsourcing-specific regulatory frameworks laid down by the European Banking Authority (“EBA”) and the European Insurance and Occupational Pensions Authority (“EIOPA”); Part Two – Other European Level Considerations This part of the Paper explores, at a high level, the legal and regulatory considerations that should be taken into account (in addition to the specific requirements covered in Part One) when an applicable firm is entering into outsourcing arrangements; and Part Three – Jurisdiction Specific Guidance This part of the Paper outlines the jurisdiction-specific considerations required by the financial services regulators in the following countries: • France; • Germany; • Ireland; • Italy; • Luxembourg; • Spain; and • UK Brexit The information contained in this Paper may be subject to change as a result of the ongoing Brexit changes. 1 Please note that certain enforcement cases have been referred to, however, this Paper does not provide an exhaustive list of the enforcement cases relevant to this area. 4 Outsourcing: The Legal and Regulatory Framework KEY THEMES As noted in the introduction above, this Paper covers