CHANGES TO POLICY STATEMENT TO REGULATION 24-102 RESPECTING CLEARING AGENCY REQUIREMENTS
- Section 2.1 of Policy Statement to Regulation 24-102 respecting Clearing Agency
Requirements is changed by adding, at the end of the first paragraph, the following sentence:
“Applicants will also need to demonstrate equivalent compliance with the requirements of Regulation 26-101 respecting Information Technology System Integrity (indicate here the reference).”.
- The paragraph after the title of Division 3 of Part 4 of the Policy Statement is
repealed.
- Sections 4.6 to 4.9 of the Policy Statement are repealed.
- Section 4.10 of the Policy Statement is replaced by the following:
“4.10. A recognized clearing agency that chooses to outsource a key system or service should ensure that the system or service meets the same standards that would apply internally. This requirement applies regardless of whether the outsourcing arrangements are with third-party service providers or with affiliated entities of the clearing agency.
Section 4.10 sets out requirements applicable to a recognized clearing agency
that outsources any of its key services or systems to a service provider. Key services and systems are services and systems that are necessary for a clearing agency to operate effectively and in compliance with regulatory requirements and appropriate standards. These may include, for example, a clearing agency’s audit function.22 To promote a harmonized approach to the regulation of outsourcing, section 4.10 incorporates by reference the outsourcing requirements set out in section 21 of Regulation 26-101 respecting Information Technology System Integrity. Generally, the clearing agency is required to establish, implement, maintain and enforce policies and procedures to evaluate and approve outsourcing agreements with service providers regarding the outsourcing of key systems or services. Such policies and procedures should include assessing the suitability of potential service providers and the ability of the clearing agency to continue to comply with securities legislation in the event of the service provider's bankruptcy, insolvency or termination of business. The clearing agency is also required to monitor and evaluate the on-going performance and compliance of the service provider to which they outsourced key services, systems or facilities. Accordingly, the clearing agency should define key performance indicators that will measure the service level. Further, the clearing agency should have robust arrangements for the substitution of such providers, timely access to all necessary information, and the proper controls and monitoring tools. A contractual relationship should be in place between the clearing agency and the service provider allowing it and relevant authorities to have full access to necessary information. The contract should ensure that the clearing agency's approval is mandatory before the service provider can itself outsource material elements of the service provided to the clearing agency, and that in the event of such an arrangement, full access to the necessary information is preserved. Clear lines of communication should be established between the outsourcing clearing agency and the service provider to facilitate the flow of functions and information between parties in both ordinary and exceptional circumstances. Where the clearing agency outsources a key system or service, it should disclose the nature and scope of this dependency to its participants. It should also identify the risks from its outsourcing and take appropriate actions to manage these dependencies through appropriate contractual and organisational arrangements. The clearing agency should inform 22 Critical services and systems, a subset of key systems and services, are separately regulated by Regulation 26-101 respecting Information Technology System Integrity (indicate here the reference).
2 the securities regulatory authority about any such dependencies and the performance of its service providers. To that end, the clearing agency can contractually provide for direct contacts between the service provider and the securities regulatory authority, contractually ensure that the securities regulatory authority can obtain specific reports from the service provider, or the clearing agency may provide full information to the securities regulatory authority.”.
5. Annex II of the Policy Statement is changed by adding, at the end of the title, the
following footnote:
“1 The CSA notes that the terms “critical system” and “critical service” in Annex II are used in the context of the PFMIs and do not necessarily reflect the way these terms are used in Regulation 26-101 respecting Information Technology System Integrity.”.