2022-04-22
Added · Updated
This circular establishes supervisory requirements for outsourcing arrangements, extending the scope of application beyond credit institutions, investment firms, and payment institutions to include specialised and support professionals of the financial sector, POST Luxembourg, and management companies authorised under Article 125-1 of the UCITS Law. It mandates that In-Scope Entities adopt robust internal governance arrangements, including clear organisational structures, adequate internal control mechanisms, and sound risk management practices when resorting to outsourcing. The document specifies detailed obligations regarding the assessment, governance framework, contractual phase, oversight, and exit plans for outsourcing processes, with specific additional requirements for ICT outsourcing, including cloud computing infrastructure. As of 17 January 2025, the circular has been amended to align with the Digital Operational Resilience Act (DORA) to avoid duplication of requirements.