# Conforming to the FCA’s cloud guidance: the challenge for financial services organisations
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2016-08-22
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Financial Services Cloud Technology: Risk Mitigation Guide
Meta Description: Increase awareness of cloud risks with the latest guidance from the FCA. Learn how to protect sensitive data and ensure compliance with industry regulations.
URL: https://financedigest.com/conforming-to-the-fcas-cloud-guidance-the-challenge-for-financial-services-organisationshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/nigel-hawthorn-1-1736844574657-compressed.jpg)

The rapid adoption of cloud technology within the financial services industry shows no signs of slowing. Businesses are embracing the cloud to reduce IT costs, increase employee productivity, and drive innovation and growth, and the average enterprise within the industry now uses more than 1,000 cloud applications.

 Nigel Hawthorn

Yet, opportunity breeds risk and, in this case, the potential for sensitive data to become compromised is ever-increasing. The issue is there still remains a [lack of awareness around cloud use within the industry](https://www.financedigest.com/carlsbergs-poland-unit-could-stop-production-lack-of-co2-threatens-food-industry.html "Carlsberg’s Poland unit could stop production; lack of CO2 threatens food industry"), both in terms of the number of services actually being utilised and best practice. Any [data breach](https://www.financedigest.com/amazons-twitch-blames-configuration-error-for-data-breach.html "Amazon’s Twitch blames configuration error for data breach") is likely to compromise sensitive information so, to protect customers and consumers, The Financial Conduct Authority (FCA) releases regular guidance. The latest, [_‘Guidance for firms outsourcing to the ‘cloud’ and other third-party IT services’_](http://www.fca.org.uk/your-fca/documents/finalised-guidance/fg16-5) _,_ helps to interpret exactly what is expected of financial services organisations in relation to the ‘ [_Financial services and markets act 2000_](http://www.legislation.gov.uk/ukpga/2000/8/contents)’. The guidance covers the full lifecycle, from the initial decision to use the cloud, right through to exit strategies.

One of the major weaknesses in today’s complex computing [mix is third parties that share data](https://www.financedigest.com/u-s-yield-curve-inverts-after-strong-jobs-data-world-shares-mixed.html "U.S. yield curve inverts after strong jobs data; world shares mixed") without having the same level of security methodology as the primary organisation. Yet, it is the originating business that will be held responsible for any data loss suffered by the cloud application, or by anyone else along the [supply chain](https://www.financedigest.com/volkswagen-sticks-to-outlook-as-size-offset-supply-chain-woes.html "Volkswagen sticks to outlook as size offset supply chain woes"). The guidance sets out areas for firms to consider before commencing use of any [cloud service](https://www.financedigest.com/uk-to-examine-cloud-services-dominated-by-amazon-microsoft-and-google.html "UK to examine cloud services dominated by Amazon, Microsoft and Google") but it’s not easy to conform to them all. For example, when discussing cloud [services’ supply chains](https://www.financedigest.com/amazon-introduces-seller-storage-service-to-tackle-supply-chain-woes.html "Amazon introduces seller storage service to tackle supply chain woes"), it states that businesses “should review sub-contracting arrangements”, to ensure that data is protected by the relevant measures wherever it is. However, many of these agreements are confidential meaning complete visibility isn’t always possible without [strong contracts that demand](https://www.financedigest.com/plastic-caps-screw-caps-closures-in-demand.html "Plastic Caps & Closures Witness Strong Sales in Line with Convenience Packaging Trend; Screw Caps & Closures in Demand") this information.

In order to mitigate the risk, [companies must](https://www.financedigest.com/three-must-do-think-about-before-opening-a-company-in-hong-kong.html "Three Must-Do Think about Before Opening a Company in Hong Kong") carry out comprehensive due diligence. Everything from data centre locations and ease of access to data, to encryption capabilities and compliance with international regulations must be scrutinised. All can lead to an organisation [falling short](https://www.financedigest.com/countries-emissions-pledges-still-fall-short-of-global-climate-goals-un-says.html "Countries’ emissions pledges still fall short of global climate goals, UN says") of the guidance if they don’t meet the requirements. After each application is evaluated and given a [risk rating](https://www.financedigest.com/boe-flags-risk-of-recession-and-10-inflation-as-it-raises-rates-again.html "BoE flags risk of recession and 10% inflation as it raises rates again"), the business will be able to create a whitelist of approved services and a blacklist of ones that should be avoided.

At the start of relationships with [cloud service providers](https://www.financedigest.com/can-companies-minimise-their-dependency-on-cloud-service-providers.html "Can companies minimise their dependency on cloud service providers?"), some organisations don’t give too much thought to what happens at the end. Even after relationships cease, the business will still face the wrath of impacted parties and regulators if data is compromised. The guidance states firms should “know how it would remove [data from the service](https://www.financedigest.com/meeting-the-data-challenge-in-financial-services.html "Meeting the data challenge in financial services") provider’s systems on exit”, this involves ensuring data will be returned, migrated to another application or permanently deleted.

The FCA will judge organisations on all cloud usage, regardless of whether the IT department is completely aware of the full range of applications in use or not. It’s common for employees to use services without the knowledge of IT to help them do their jobs better. Yet, they often don’t think about the bigger picture and the risk they are introducing to the organisation. Some [cloud services](https://www.financedigest.com/tech-amigos-provides-unrivalled-aws-cloud-service-support-for-autorama-groups-leading-brand-vanarama-2.html "Tech Amigos provides unrivalled AWS cloud service support for Autorama Group’s leading brand, Vanarama"), for example, automatically gain ownership of data as soon as its uploaded, a big problem if workers are using them to share sensitive information with colleagues. In [order to conform with the guidance](https://www.financedigest.com/italys-leonardo-raises-fy-orders-guidance-after-strong-nine-months.html "Italy’s Leonardo raises FY orders guidance after strong nine months"), it’s imperative for businesses to be able to monitor and report on overall cloud usage. This should include the applications being utilised, the type and amount of [data being uploaded and whether services](https://www.financedigest.com/financial-services-and-data-how-do-we-meet-the-challenge.html "Financial services and data – how do we meet the challenge?") are inside or outside the EU.

What is becoming apparent is, as the [adoption of the cloud continues to increase and regulations](https://www.financedigest.com/why-are-commercial-food-products-manufacturers-adopting-insect-growth-regulators.html "Why are Commercial Food Products Manufacturers Adopting Insect Growth Regulators") become more stringent, it’s now too complex to manage without further tools. [Cloud Access Security](https://www.financedigest.com/dont-let-the-promises-of-virtual-desktop-security-cloud-your-judgement.html "Don’t let the promises of virtual desktop security cloud your judgement") Brokers (CASBs) technology enables IT departments to view answers to many of the questions posed in the FCA guidance, monitor all cloud use across the enterprise and to measure the risk posed. Red flags are produced when unusual traffic patterns or high risk applications are identified, giving businesses time to resolve situations before they escalate and encourage employees to use approved alternatives.Furthermore, such technology empowers companies to ensure cloud services comply with the business’ own cybersecurity standards. Imagine if you lent someone your car, you’d want them to look after it in the same way you do – firms must think similarly about their data. Extra [security capabilities can be added on to services](https://www.financedigest.com/maintaining-security-and-compliance-amid-digital-transformation-in-financial-services.html "Maintaining Security and Compliance amid Digital Transformation in Financial Services") too, such as enhanced logging, multiple encryption modes and external collaboration control.

Ultimately, the guidance acts as a best practice for [financial services](https://www.financedigest.com/can-financial-services-brands-ever-be-credible-on-social.html "Can financial services brands ever be credible on social? ") organisations as they use the cloud. Conforming completely won’t be straightforward and firms must understand that it is no longer simply the remit of IT or the compliance team. Businesses must take it upon themselves to provide the relevant training – [ensuring all employees are aware of the risks of unsanctioned cloud services and how to safely](https://www.financedigest.com/france-demands-twitter-ensure-it-can-preserve-safe-environment.html "France demands Twitter ensure it can preserve ‘safe environment’") use approved ones.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

