2026-07-03
Added · Updated
The Central Bank of the Republic of Kosovo approved a regulation establishing an internal governance and risk management framework for outsourcing, specifically targeting critical or important functions. The regulation applies to banks, electronic money institutions, payment institutions, microfinance institutions, and non-bank financial institutions, requiring them to define criticality criteria, maintain an outsourcing register, and ensure management bodies retain full responsibility for compliance. It mandates the development of outsourcing policies, conflict of interest management, and documented exit plans for critical functions, while allowing for centralized monitoring within groups or institutional protection schemes under specific oversight conditions.
CBK published 3 documents in the last 30 days — get each new one by email the day it lands.
Pursuant to Article 35, paragraph 1 subparagraph 1.1 and Article 65 of the Law No. 03/L–209 on Central Bank of the Republic of Kosovo (Official Gazette of the Republic of Kosovo, No. 77/16 August 2010), amended and supplemented by Law No. 05/L–150 (Official Gazette of the Republic of Kosovo, No.10/03 April 2017), pursuant to Article 21 and 136 of the Law No. 10/L-026 on Payment Services (Official Gazette of the Republic of Kosovo, No.10 / 14 May 2026), Article 8, Article 58 paragraph 1 of the Law No. 08/L-304 on Banks (Official Gazette of the Republic of Kosovo, No.2 / 27 January 2026), and Article 114 of the Law No. 04/L-093 on Banks, Microfinance Institutions and Non-Bank Financial Institutions (Official Gazette of the Republic of Kosovo, No.11 / 11 May 2012), the Board of the Central Bank of the Republic of Kosovo, at its meeting held on June 29, 2026, approved the following:
REGULATION ON OUTSOURSING
CHAPTER I
GENERAL PROVISIONS
Article 1
Purpose and scope
2.3. “Critical or important function” means any function that is considered critical or
important as set out in this Regulation;
2.4. “Sub-outsourcing” means a situation where the service provider under an outsourcing
arrangement further transfers an outsourced function to another service provider;
2.5. “Service provider” means a third-party entity that is undertaking an outsourced process,
service or activity, or parts thereof, under an outsourcing arrangement;
2.6. “Cloud services” means services provided using cloud computing, that is, a model for
enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction;
2.7. “Public cloud” means cloud infrastructure available for open use by the general public.
2.8. “Private cloud” means cloud infrastructure available for the exclusive use by a single
institution or payment institution.
2.9. “Community cloud” means cloud infrastructure available for the exclusive use by a
specific community of institutions or payment institutions, including several institutions of a single group.
2.10. “Hybrid cloud” means cloud infrastructure that is composed of two or more distinct cloud
infrastructures.
2.11. “ICT” means information and communication technologies.
2.12. “Institutional protection scheme” means a contractual or legal obligation arrangement
which protects those institutions that are a member of the scheme and in particular ensures their liquidity and solvency to avoid bankruptcy where necessary.
2.13. “Management body” means:
2.13.1. for banks, microfinance institutions and non-bank financial institutions, this terms
as the same meaning as in Article 36, of the Law No.08/L-304 on Banks, Article 96 of the Law No. 04/L-093 on Banks, Microfinance Institutions and Non-Bank Financial Institutions respectively;
2.13.2. for payment institutions or electronic money institutions, this term means directors
or persons responsible for the management of the payment institutions and electronic money institutions and, where relevant, persons responsible for the management of the payment services activities of the payment institutions and electronic money institutions;
2.13.3. for PSPs referred to in subparagraphs 1.4, 1.5 and 1.6 of Article 1 of the Law on
Payment Services, this term has the meaning conferred to it by the Law on Payment Services;
2.14. “Institutions” means banks, electronic money institutions, payment institutions,
microfinance institutions and non-bank financial institutions;
2.15. “Law on protection of personal data” means Law No. 06/L–082 on Protection of Personal
Data and/or the Law in force for Protection of Personal Data;
2.16. “Law on Banks” means Law No. 08/L-304 on Banks and/or the applicable Law on Banks;
2.17. “Law on Microfinance Institutions and Non-Bank Financial Institutions” means Law
no. 04/L-093 for Banks, Microfinance Institutions and Non-Banking Financial Institutions and/or the Law in force for MFI and NBFI;
2.18. “Law on Payment Services” means Law No. 10/L-026 on Payment Services.
CHAPTER II
PROPORTIONALITY: GROUP APPLICATION AND INSTITUTIONAL PROTECTION SCHEMES
Article 3
Proportionality
Institutions and CBK shall apply the principle of proportionality to ensure that governance
arrangements, including those related to outsourcing, are consistent with the individual risk profile, the nature and business model of the institution and the scale and complexity of their activities so that the objectives of the regulatory requirements are effectively achieved.
When applying the requirements set out in this regulation, institutions should take into account the
complexity of the outsourced functions, the risks arising from the outsourcing arrangement, the criticality or importance of the outsourced function and the potential impact of the outsourcing on the continuity of their activities.
Article 4
Outsourcing by groups and institutions that are members of an institutional protection scheme
This regulation should also apply on a sub-consolidated and consolidated basis, taking into account
the prudential scope of consolidation. For this purpose, the parent undertakings should ensure that internal governance arrangements, processes and mechanisms in their subsidiaries, including payment institutions, are consistent, well integrated and adequate for the effective application of this regulation at all relevant levels.
Institutions in accordance with paragraph 1 of this Article, and institutions that, as members of an
institutional protection scheme, use centrally provided governance arrangements should comply with the following where those institutions:
2.1. have outsourcing arrangements with service providers within the group or the institutional
protection scheme, the management body of those institutions retains, also for these outsourcing arrangements, full responsibility for compliance with all regulatory requirements and the effective application;
2.2. outsource the operational tasks of internal control functions to a service provider within the
group or the institutional protection scheme, for the monitoring and auditing of outsourcing arrangements, institutions should ensure that, also for these outsourcing arrangements, those operational tasks are effectively performed, including through the receiving of appropriate reports.
In addition to paragraph 2 of this Article, institutions within a group for which no waivers have
been granted, institutions that are a central body or that are permanently affiliated to a central body for which no waivers have been granted, or institutions that are members of an institutional protection scheme should take into account the following:
3.1. where the operational monitoring of outsourcing is centralized (e.g., as part of a master
agreement for the monitoring of outsourcing arrangements), institutions should ensure that, at least for outsourced critical or important functions, both independent monitoring of the service provider and appropriate oversight by each institution is possible, including by receiving, at least annually and upon request from the centralized monitoring function, reports that include, at least, a summary of the risk assessment and performance monitoring. In addition, institutions should receive from the centralized monitoring function a summary of the relevant audit reports for critical or important outsourcing and, upon request, the full audit report;
3.2. institutions should ensure that their management body will be duly informed of relevant
planned changes regarding service providers that are monitored centrally and the potential impact of these changes on the critical or important functions provided, including a summary of the risk analysis, including legal risks, compliance with regulatory requirements and the impact on service levels, in order for them to assess the impact of these changes;
3.3. where those institutions within the group, institutions affiliated to a central body or
institutions that are part of an institutional protection scheme rely on a central preoutsourcing assessment of outsourcing arrangements, as referred to in Articles 14 to 16 of this regulation, each institution should receive a summary of the assessment and ensure that it takes into consideration its specific structure and risks within the decision-making process;
3.4. where the register of all existing outsourcing arrangements, as referred to in Article 15 of
this regulation, is established and maintained centrally within a group or institutional protection scheme, all institutions should be able to obtain their individual register without undue delay. This register should include all outsourcing arrangements, including outsourcing arrangements with service providers inside that group or institutional protection scheme;
3.5. where those institutions rely on an exit plan for a critical or important function that has been
established at group level, within the institutional protection scheme or by the central body, all institutions should receive a summary of the plan and be satisfied that the plan can be effectively executed.
CHAPTER III
OUTSOURCING MANAGEMENT
Article 5
Assessment of outsourcing arrangements
Institutions shall establish whether the entrusting by an institution of the performance of processes,
services or activities to a service provider falls under the definition of outsourcing.
For the purposes of this Regulation, the following shall not be considered as outsourcing:
2.1. services of global financial communication services (e.g., SWIFT) if key information system
resources needed for the provision of such service are within the institution;
2.2. function that is legally required to be performed by a service provider, (e.g., statutory audit);
2.3. market information services (e.g., provision of data by Bloomberg, Moody’s, Standard &
Poor’s, Fitch);
2.4. global network infrastructures (e.g., Visa, MasterCard) and telecommunication services;
2.5. clearing and settlement arrangements between clearing houses, central contractual parties and
settlement institutions and their members;
2.6. global financial messaging infrastructures that are subject to oversight by relevant authorities;
2.7. correspondent banking services;
2.8. the acquisition of services that would otherwise not be undertaken by the institution (e.g.
advice from an architect, providing legal opinion and representation in front of the court and administrative bodies, cleaning, gardening and maintenance of the institution’s premises, medical services, servicing of company cars, catering, vending machine services, clerical services, travel services, post-room services, receptionists, secretaries and call center operators), goods (e.g. plastic cards, card readers, office supplies, personal computers, furniture) or utilities (e.g. electricity, gas, water, telephone line);
2.9. software which, being off-the-shelf, is commercially available in the market and does not
require substantial customization; and
2.10. other services similar to those under subparagraphs 2.1 to 2.9 of this paragraph subject to the
CBK’s prior opinion stating that the provisions of this Regulation shall not apply to the use of those services.
Institutions shall not transfer authorizations and competences of its management and supervisory
bodies to the service provider.
Each service provider involved in the outsourcing must have a separate legal identity distinct from
the institution outsourcing the services.
Institutions shall, proportionally to the nature, scale and complexity of its activities and the risks
inherent in its business model, manage risks to which it is or might be exposed, which result from the entrusting of the performance of processes, services or activities to the service provider, regardless of whether that entrusting falls under the definition of outsourcing.
The prior opinion of the CBK referred to in paragraph 2.10 of paragraph 2 of this article, if it
relates to an application or request by an institution, a service provider or a prospective institution or service provider, shall be issued within a maximum period of two months from the date of submission of the application or request.
Article 6
Assessment of criticality or importance of function/service to be outsourced
Institutions should always consider a function as critical or important in the following situations:
1.1. where a defect or failure in its performance would significantly impair, financial
performance and continuity of institution’s activity.
1.2. when operational tasks of internal control functions are outsourced, an assessment must be
conducted to determine whether a failure to provide the outsourced function or inappropriate provision thereof would adversely impact the effectiveness of the internal control function.
It is necessary to determine the criticality or importance, of the function that shall be outsource in
order to manage outsourcing risk.
Institutions must establish criteria and define methodology in order to assess the criticality or
importance of a function, including its impact on regulatory compliance and licensing, influence on financial performance, contribution to operational resilience and continuity of services, importance in maintaining customer trust and service quality, potential impact on the institution's reputation or market standing, and degree of dependency on core business operations.
The assessment of criticality or importance is an ongoing process that should be conducted at
regular intervals. The assessment of criticality or importance shall be reviewed regularly to ensure it stays relevant as business conditions, regulations, and operations change over time.
The assessment of critical or important functions involves a structured approach to determine the
significance of each function to the institution's operations and regulatory obligations. This assessment is essential for making informed decisions about outsourcing and ensuring that outsourced arrangements do not compromise operational resilience or regulatory compliance.
Article 7
Organizational structure
Institutions shall ensure:
1.1. a clear, transparent and documented decision-making process on outsourcing;
1.2. a clear allocation of powers and responsibilities of organizational units or employees
responsible for documenting, managing and overseeing the process of entering into and implementing any outsourcing arrangements; and
1.3. adequate resources to ensure compliance with the provisions of regulations and good practices
governing outsourcing.
Institutions shall establish an outsourcing function or designate a senior staff member (e.g., a
person responsible for the work of a control function) responsible for overseeing the risks of outsourcing arrangements and overseeing the documentation of outsourcing arrangements.
Notwithstanding paragraph 2 of this Article, Institutions may assign the outsourcing function to a
member of the senior management.
When outsourcing, institutions shall at least ensure the following:
4.1. the adoption and implementation of decisions related to its business activities and critical or
important functions;
4.2. the maintenance of the orderly conduct of its business and the provision of financial services;
4.3. adequate identification, assessment, management and mitigation of risks arising from
outsourcing;
4.4. where applicable, appropriate confidentiality arrangements regarding data and other
information;
4.5. the maintenance of an appropriate flow of relevant information with service providers;
4.6. with regard to the outsourcing of critical or important functions, the undertaking of at least
one of the following actions, within an appropriate time frame:
4.6.1.1. transfer of the function to alternative service providers;
4.6.1.2. reintegration of the function into institution; or
4.6.1.3. discontinuation of the business activities that are depending on the function; and
4.7. where personal data are processed by service providers located in the third countries, data are
processed in accordance with Law on Protection of Personal Data.
Institutions shall ensure that outsourcing does not result in the transfer of responsibilities from the
responsible persons of the institution to the service provider.
Article 8
Outsourcing by a group of institutions
Where institutions outsource functions to service providers within the group of institutions to
which it belongs, the management and the supervisory board of the institution that outsourced the activity or service in question shall, in line with their competence, be responsible also for those outsourced services and activities and shall retain full responsibility for compliance with all regulatory requirements and the effective implementation of this Regulation.
Where institutions entrusts the performance of some control function tasks to a service provider
within the group of institutions to which it belongs, for the monitoring and auditing of outsourcing arrangements, it shall ensure that those operational tasks are effectively performed, including through the receiving of appropriate reports.
Where the operational monitoring of a particular outsourcing arrangement is centralized within the
group of institutions to which an institution belongs (e.g., as part of a master agreement for the monitoring of outsourcing arrangements), the institution shall ensure that, at least for outsourced critical or important functions:
3.1. both independent monitoring of the service provider and appropriate oversight is possible,
including by receiving, at least annually and upon request from the centralized monitoring function of the group of institutions, reports that include, at least, a summary of the risk assessment and performance monitoring; and
3.2. it is possible to receive from the centralized monitoring function of the group of institutions a
summary of the relevant audit reports for critical or important outsourcing arrangements and, upon request, the full audit report.
4. Institutions shall ensure that its management body will be duly notified of relevant planned
changes regarding service providers that are monitored centrally within the group of institutions to which the institution belongs and of the potential impact of these changes on the critical or important functions provided, including a summary of the risk analysis, including legal risks, compliance with regulatory requirements and the impact on service levels.
5. Where institutions relies on an assessment of outsourcing arrangements, as referred to in Article
14 of this Regulation, which is carried out centrally within the group of institutions to which the institution belongs, before entering into an arrangement with a service provider, it shall ensure that it receives a summary of the assessment and ensure that its specific structure and risks are taken into consideration within the decision-making process.
6. Where the register of all existing outsourcing arrangements is maintained centrally within the
group of institutions to which an institution belongs, the institution shall ensure that it is able to obtain without delay its individual register, which contains all outsourcing arrangements with service providers, including outsourcing arrangements with service providers inside that group of institutions, at least to the extent laid down in Article 13 of this Regulation.
7. Where institutions relies on an exit plan for a critical or important function that has been
established for the group of institutions to which the institution belongs, it shall ensure that it receives a summary of the plan and be satisfied that the plan can be effectively executed.
Article 9
Outsourcing policy
3.2.1.5. the identification, assessment, management, mitigation or prevention of actual or
potential conflicts of interest;
3.2.1.6. business continuity planning; and
3.2.1.7. the approval of new outsourcing arrangements;
3.3. the implementation, monitoring and management of outsourcing arrangements, including:
3.3.1.1. the ongoing assessment of the service provider’s performance;
3.3.1.2. the procedures for being notified and responding to changes to an outsourcing
arrangement or service provider;
3.3.1.3. the independent review and audit of compliance with legal and regulatory
requirements and policies; and
3.3.1.4. the renewal processes;
3.4. the documentation and register maintenance; and
3.5. the exit strategies and termination or cancellation processes, including a requirement for a
documented exit plan for each critical or important function to be outsourced, where such an exit is considered possible taking into account possible service interruptions or the unexpected cancellation or termination of an outsourcing agreement with the service provider.
Article 10
Conflict of interest
maintain and periodically test appropriate business continuity plans with regard to outsourced critical or important functions. Institutions and payment institutions within a group or institutional protection scheme may rely on centrally established business continuity plans regarding their outsourced functions.
2. Business continuity plans should take into account the possible event that the quality of the
provision of the outsourced critical or important function deteriorates to an unacceptable level or fails. Such plans should also take into account the potential impact of the insolvency or other failures of service providers and, where relevant, political risks in the service provider’s jurisdiction.
Article 12
Internal audit function
1.6. a brief description of the outsourced activity;
1.7. description of the data that the service provider has access to or are in its possession, and/or
the information on whether the data were transferred to another service provider;
1.8. information on whether the outsourced activity is critical/key or affects critical/key business
processes;
1.9. the name of the country or countries in which the outsourced activity is carried out and the
country or countries in which the data are located;
1.10. information about the model and type of cloud service;
1.11. the date of the last assessment of the level of the service provided and the risk assessment of
the information system in connection with outsourced activities;
1.12. information about sub-outsourced services (short description of the service, basic data about
the subservice provider, etc.).
2. Institutions shall, when requested or in the periodicity determined by the CBK, submit to the CBK
an excerpt from the records containing an overview of all outsourced activities of the institution’s activities to a third party.
CHAPTER IV
OUTSOURCING PROCESS
Article 14
Pre-outsourcing analysis
1.1. the service provider is authorized by a competent authority or entered in an appropriate
register with a competent authority to perform that function; or
1.2. the service provider is authorized to perform that function if such specific authorization for
the performance of that function is required under the relevant legislation in force.
2. Where an institution outsources a function directly connected to the provision of core financial
services to a service provider located in a third country, the following conditions must be met:
2.1. the service provider is authorized or entered in an appropriate register with a competent
authority to perform that function in the third country and is supervised by a relevant competent authority; and
2.2. there is an appropriate cooperation agreement between the CBK and the supervisory authority
responsible for the supervision of the third-country service provider.
3. Regardless of outsourced functions, an institution shall maintain at all times sufficient substance
and shall ensure that:
3.1. it meets all the conditions of its authorization at all times;
3.2. its management and supervisory boards effectively carry out their responsibilities;
3.3. it retains a clear and transparent organizational framework and structure that enables it to
ensure compliance with prescribed requirements;
3.4. where operational tasks of control functions are outsourced, it monitors and manages the risks
arising from the outsourcing of critical or important functions; and
3.5. it has sufficient resources to ensure compliance with subparagraphs 3.1. to 3.4. of this
paragraph.
Article 16
Assessment and management of risks arising from outsourcing
Before entering into an arrangement with a service provider and during ongoing monitoring of the
service provider’s performance, institutions shall assess risks and establish an appropriate system for managing operational and concentration risks and other risks arising from outsourcing.
Where the arrangement with a service provider includes the possibility that the service provider
sub-outsources critical or important functions to other service providers, institutions shall when carrying out the risk assessment take into account at least the following:
2.1. the risks associated with sub-outsourcing, including the additional risks that may arise if the
sub-contractor is located in a third country or a different country from the service provider; and
2.2. the risk that long and complex chains of sub-outsourcing reduce the ability of the institution
to oversee the outsourced critical or important function and the ability of the CBK to effectively supervise them.
Before entering into outsourcing arrangements, institutions shall assess the potential impact of
outsourcing arrangements on its operational risk and take into account the assessment results when deciding if the function should be outsourced to a service provider.
Institutions shall take appropriate steps to avoid undue additional operational risks before entering
into outsourcing arrangements.
Institutions rules for the establishment and implementation of a risk management system according
to relevant legal acts and regulations adopted under those laws shall apply mutatis mutandis to the management of risks arising from outsourcing.
Outsourced functions must be adequately covered by institutions' internal control system.
Institutions rules for the establishment and implementation of the internal control system and control functions according to relevant laws and regulations adopted under those laws shall apply mutatis mutandis to outsourced functions.
Article 17
Due diligence
Before entering into outsourcing arrangements and taking into account the assessment of
operational risks related to the function to be outsourced, institutions shall ensure in its selection and assessment process that the service provider is suitable.
When assessing the suitability of an outsourcing service provider of a critical or important
function, institutions shall assess whether the service provider:
2.1. is of good repute;
2.2. has appropriate abilities, the expertise, the resources (e.g., human, ICT, financial), the
organizational structure; and
2.3. if applicable, has the authorization to perform that function or is entered in an appropriate
register with a competent authority.
When conducting due diligence on a prospective outsourcing service provider of a critical or
important function, institutions shall also consider the following:
3.1. the business model of the service provider, its nature, scale, complexity, financial situation,
ownership structure and, where the service provider is a member of a group, the structure of the group to which it belongs;
3.2. the long-term relationships with service providers that have already been assessed and
perform services for the institution;
3.3. whether the service provider is a parent undertaking or subsidiary of the institution and
whether it is part of the accounting scope of consolidation; and
3.4. whether or not the service provider is supervised by the competent supervisory authority.
Where outsourcing involves the processing of personal or confidential data, institutionsshall verify
that the service provider implements appropriate technical and organizational measures to protect the data.
Article 18
Contractual relationship between institutions and a service provider
2.15. the duration of the contractual relationship or an indication that the agreement is of indefinite
duration;
2.16. a description of the conditions for the termination and/or cancellation of the agreement with
defined notice periods for the institution and for the service provider;
2.17. the rights of the institution to terminate or cancel an agreement with the service provider, if
so ordered by the CBK;
2.18. the selection of the applicable Law; and
2.19. the method of dispute settlement.
3. Where institutions and the service provider enter into an outsourcing agreement for critical or
important functions, the agreement must, in addition to the content specified in paragraph 2, contain the following:
3.1. the obligation of the service provider to ensure access and audit rights to the institution in the
manner laid down in Article 22, paragraph 2 of this Regulation;
3.2. provisions on the implementation and testing of business continuity plans;
3.3. the obligations of the service provider in the case of a transfer of the outsourced function to
another service provider or back to the institution, including the obligations regarding the treatment of data;
3.4. setting of an appropriate transition period, during which the service provider, after the
termination or cancellation of the outsourcing arrangement, would continue to provide the outsourced function to reduce the risk of disruptions; and
3.5. the obligation of the service provider to support the institution in the orderly transfer or
reintegration of the function in the event of the cancellation or termination of the outsourcing agreement.
4. The outsourcing agreement should specify whether or not sub-outsourcing of critical or important
functions, or material parts thereof, is permitted.
5. If sub-outsourcing of critical or important functions is permitted, institutions should determine
whether the part of the function to be sub-outsourced is, as such, critical or important (i.e., a material part of the critical or important function) and, if so, record it in the register.
6. Where an outsourcing agreement for critical or important functions includes the possibility of suboutsourcing, in addition to the content specified in paragraphs 2. and 3. of this Article, that
agreement must contain at least the following:
6.1. the obligation of the service provider to notify the institution of any planned sub-outsourcing,
or material changes thereof, within the period that would allow the institution to carry out a risk assessment of the proposed changes and, where necessary, to object in a timely manner to planned sub-outsourcing, or material changes thereof;
6.2. the right to cancel/terminate the agreement where the sub-outsourcing increases the risks for
the institution or where the service provider sub-outsources without notifying the institution and in other justified cases;
6.3. where the sub-outsourcing involves the processing of personal data, the obligation of the
service provider to obtain written authorization of the institution;
6.4. the obligation of the service provider to oversee those services that it has sub-contracted;
6.5. the conditions to be complied with in the case of sub-outsourcing;
6.6. the types of functions that may not be sub-outsourced;
6.7. the obligation of the service provider to request written approval of the institution for any
planned sub-outsourcing, or material changes thereof or the right to object to planned outsourcing; and
6.8. the obligation of the service provider to negotiate with the sub-contractor on access and audit
or on-site inspection rights in the manner laid down in Article 22, paragraph 1 of this Regulation.
7. Institutions may permit sub-outsourcing only where the sub-contractor undertakes to act in
compliance with applicable Law and regulatory requirements, comply with relevant contractual obligations and ensure to the institution and the CBK the same access and audit or onsite inspection rights as those granted by the service provider in accordance with Article 22 of this Regulation.
8. Institutions should ensure that the service provider appropriately oversees the sub-service
providers, in line with the policy defined by the institution. If the sub-outsourcing proposed could have material adverse effects on the outsourcing arrangement of a critical or important function or would lead to a material increase of risk, including where the conditions in paragraph 7 of this
Article would not be met, the institution should exercise its right to object to the sub-outsourcing,
if such a right was agreed, and/or terminate the contract.
Article 19
Security of data and systems
2.1. clear roles and responsibility for information security of the cloud service provider towards
the institution;
2.2. responsibilities for maintaining hardware and software components according to the
manufacturer’s requirements, testing and applying security patches;
2.3. the method of managing incidents so that the procedures and roles for solving incidents are
determined, as well as the method of reporting on the incident and its consequences for the institution;
2.4. secure authentication mechanism, and/or control of access to data and services using multifactor authentication;
2.5. procedures that ensure adequate encryption of data during data transmission, storage and
backup.
3. The institution intending to perform cloud outsourcing shall additionally take into account the
following when assessing the risk of such outsourcing:
3.1. cloud service implementation model (public, private, shared, hybrid, etc.);
3.2. type of cloud services (infrastructure as a service – IaaS, platform as a service – PaaS and
software as a service – SaaS, etc.);
3.3. the impact of data migration and resource implementation in the chosen type of cloud services;
3.4. network capacities for simple and secure data transfer (data portability);
3.5. data protection during cloud migration and storage.
4. When cloud outsourcing, the institution shall develop an adequate exit strategy in the event of
termination of the provision of these services, which additionally includes procedures governing the termination and re-establishment of cloud services or their transfer to another service provider or that institution, as well as detailed plans for the migration of data and/or resources of information systems depending on the type of cloud services.
5. The institution shall ensure that any contract on cloud outsourcing shall also contain provisions
governing the ownership of data, the method of accessing data and services, as well as the download of the institution’s data in a readable format after the termination of the provision of that service and their adequate deletion by the service provider.
Article 21
Sensitive Data Risk Management
1.3. have a documented data management strategy that addresses the range of risks, which can
arise in the context of outsourcing and take into account potential risks, in particular operational risk, including legal risk, ICT related risk, compliance and reputational risks, and potential control limits for performing outsourced activities.
1.4. when conducting risk assessments, to take into account the characteristics of confidential data,
integrity, availability and authentication of data and information required to deliver outsourced business or service functions.
2. Institutions under this Regulation, must ensure that any transmission of personal data, should be
carried out in accordance with applicable Law on the protection of personal data.
Article 22
Access and audit or on-site inspection rights
5.1. pooled audits organized jointly with other clients of the same service provider, and carried out
by the institution and these clients or by a third party appointed by them; and
5.2. third-party certifications and third-party or internal audit reports, made available by the
service provider.
6. For the outsourcing of critical or important functions, an institution shall assess whether thirdparty certifications and reports as referred to in paragraph 5, subparagraph 5.2 of this Article are
adequate and sufficient for the carrying out of appropriate audits and reviews of outsourcing arrangements and shall not rely solely on these reports over time.
7. Where the outsourcing arrangement carries a high level of technical complexity, for instance in the
case of cloud outsourcing, an institution shall verify:
7.1. whether the persons referred to in paragraph 5 of this Article who carry out the audit and/or
assessment have appropriate and relevant skills and knowledge to carry out relevant audits and/or assessments effectively; and
7.2. whether the staff of the institution reviewing certifications and/or reports by the persons
referred to in paragraph 5 of this Article have appropriate and relevant skills and knowledge to carry out relevant audits and/or reviews effectively.
Article 23
Termination rights
2.2. set an appropriate transition period, during which the service provider, after the termination
of the outsourcing arrangement, would continue to provide the outsourced function to reduce the risk of disruptions; and
2.3. include an obligation of the service provider to support the institution in the orderly transfer
of the function in the event of the termination of the outsourcing agreement.
Article 24
Oversight of outsourced functions
Article 25
Exit strategies
4.5. define the indicators to be used for the monitoring of the outsourcing arrangement with the
service provider, including indicators based on unacceptable service levels that should trigger the exit.
CHAPTER V
OBLIGATION FOR PRIOR APPROVALS
Article 26
Prior approvals of the outsourcing of a critical or important function
CHAPTER VI
TRANSITIONAL AND FINAL PROVISIONS
Article 27
Transitional period
Read the rest free
Source: Central Bank of the Republic of Kosovo — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CBK
CBK published 3 documents in the last 30 days. We email you each new one the day it's published.