Stay in the know
We’ll send you the latest insights and briefings tailored to your needs
Having initially delayed its planned consultation exercise to allow the financial services sector to focus on responding to Covid-19, the International Organization of Securities Commissions (IOSCO) subsequently found the pandemic a catalyst to proceed. Therefore, at the end of May, IOSCO launched its consultation on proposed updates to the 2005 Outsourcing Principles for Market Intermediaries and the 2009 Outsourcing Principles for Markets; feedback on the proposed new Outsourcing Principles (OPs) is requested on or before 1 October 2020. The decision to proceed reflects the acknowledgement that outsourcing is a key element for consideration when assessing operational resilience across the sector.
This article gives a high level summary of the consultation, with a link to our briefing that focuses in more detail on: the scope of application; IOSCO’s definition of outsourcing; intragroup arrangements; concentration risk; and access and audit rights. To provide additional context to IOSCO’s proposals, the associated briefing also catalogues relevant proposals and initiatives which are running concurrent to the consultation exercise.
In common with some regional and national authorities among its membership, IOSCO has found that much has changed since its original efforts to define universal principles for outsourcing, not least the move towards use of cloud and the increased speed of markets. However, like many regulators in its membership, IOSCO holds to two principles:
While cloud has been a factor driving regulators to revisit their existing guidelines, it clearly has not prompted a fundamental rethink on whether firms’ responsibilities for compliance should be modified – much as some may have hoped this would be the case.
Increased and increasing reliance on third party providers is drawing greater regulatory focus as supervisors look to ensure the operational resilience of regulated entities – a condition that is unlikely to change anytime soon, particularly in light of the lessons being learnt under Covid-19. In this consultation, IOSCO explains that, ‘operational resilience refers to the ability of regulated entities, other firms such as service providers, and the financial market as a whole to prevent, respond to, recover, and learn from operational disruptions.’
The OPs commence with a set of ‘fundamental precepts’ covering issues such as the definition of outsourcing, the assessment of materiality and criticality, their application to affiliates, the treatment of sub-contracting and outsourcing on a cross-border basis.
IOSCO then sets out seven principles which explain the expectations for regulated entities that outsource tasks, along with guidance for implementation. The principles are:
Our briefing examines the IOSCO proposals in more detail. We focus in particular on aspects of outsourcing regulations and guidance which have proved challenging in a range of jurisdictions, including: intragroup arrangements; concentration risk; and access and audit rights. We also consider the scope of application of the OPs and IOSCO’s definition of outsourcing. The briefing concludes with our catalogue of concurrent and forthcoming consultations and initiatives.
The contents of this publication are for reference purposes only and may not be current as at the date of accessing this publication. They do not constitute legal advice and should not be relied upon as such. Specific legal advice about your specific circumstances should always be sought separately before taking any action based on this publication.
© Herbert Smith Freehills 2025
We’ll send you the latest insights and briefings tailored to your needs