EIOPA has confirmed its guidelines on outsourcing to cloud service providers are now available to national supervisors. The guidelines address:
- how to determine whether cloud services are within the scope of outsourcing;
- principles and elements of governance of cloud outsourcing;
- the analysis that should take place to determine whether a cloud outsourcing relates to a critical and important function or activity, and how to perform due diligence on the provider;
- contractual requirements;
- managing of access and audit rights, security, sub-outsourcing and monitoring and oversight; and
- how supervisors should oversee arrangements, at individual firm and group level.