
There are now separate Guidelines specifically for “Banks” and “Financial Institutions other than Banks”. An institution should conduct a self-assessment of all existing outsourcing arrangements against these Guidelines. As a result of the updates,
- Guidelines on Outsourcing (Financial Institutions other than Banks) issued on 11 December 2023 takes effect on 11 December 2024. This replaces the Guidelines on Outsourcing issued on 27 July 2016 and last revised on 5 October 2018.
- FAQ on MAS Guidelines on Outsourcing issued on 27 July 2016 was last revised on 11 December 2023.
The key principles of outsourcing remains unchanged. Some of the updates in the Guidelines on Outsourcing (Financial Institutions other than Banks) are as follows:
- There is a newly added Annex 1 that provides a list of exempted outsourced services, for which the Guidelines do not apply.
- Services wholly provided by Government Technology Agency (GovTech) or agents appointed by GovTech.
- Services that are not for the conduct of any financial business of the institution and where the service provider does not receive, handle or have access to the institution’s confidential information or customer information.
- Existing requirements on clouds services have been moved to Annex 5.
- Where MAS is not satisfied with the institution’s observance of the expectations in these Guidelines, MAS may require the institution to take additional measures to address the deficiencies noted, which could include pre-notification of new material outsourcing arrangements.
- Further guidance is provided when performing due diligence. A risk-based approach may be used to determine the frequency for the re-performance of due diligence for outsourcing arrangements (including intragroup arrangements).
- When outsourcing internal auditors to external auditors, institution should conduct periodic assessments to satisfy itself of the continuing ability of the service provider to perform the internal audit function satisfactorily.
For the full details, please refer to https://www.mas.gov.sg/regulation/third-party-risk-management
Disclaimer: The information, views or opinions expressed are provided for general information and should not be relied upon as legal or professional advice.