FFIEC Issues Statement on Risk Management for Cloud Computing Services

(April 30, 2020) – The Federal Financial Institutions Examination Council (FFIEC) on behalf of its members today issued a statement to address the use of cloud computing services and security risk management principles in the financial services sector.

Security breaches involving cloud computing services highlight the importance of sound security controls and management’s understanding of the shared responsibilities between cloud service providers and their financial institution clients.  The statement does not contain new regulatory expectations, though it highlights that management should not assume that effective security and resilience controls exist simply because the technology systems are operating in a cloud computing environment.

The statement highlights examples of risk management practices for a financial institution’s safe and sound use of cloud computing services and safeguards to protect customers’ sensitive information from risks that pose potential consumer harm.  The statement also provides a list of government and industry resources and references to assist financial institutions using cloud computing services.

Additional information on general risk management and outsourcing practices is available in the FFIEC Information Technology Examination Handbook’s “Outsourcing Technology Services” booklet and other documents published by FFIEC members.

Agency Contact Phone
Federal Reserve Darren Gersh 202.452.2955
CFPB Marisol Garibay 202.435.7425
FDIC Julianne Fisher Breitbeil 202.898.6895
NCUA Ben Hardaway 703.518.6333
OCC Stephanie Collins 202.649.6870
SLC James Kurtzke 202.728.5733
IR Press

Share
Published by
IR Press

Recent Posts

READOUT: Assistant Secretary for International Finance Brent Neiman’s Travel to Mexico

MEXICO CITY - On September 19, Assistant Secretary for International Finance Brent Neiman visited Mexico…

1 day ago

READOUT: Fifth Meeting of the Economic Working Group Between the United States and the People’s Republic of China

BEIJING – The United States and the People’s Republic of China held the fifth meeting…

1 day ago

OCC Announces Enforcement Actions for September 2024

WASHINGTON—The Office of the Comptroller of the Currency (OCC) today released enforcement actions taken against…

2 days ago

Treasury Targets Key Actors in Sanctions Evasion Scheme to Support Russia and North Korea

DPRK and Russian Financial Entities Orchestrated Illicit Payment MechanismsWASHINGTON — Today, the Department of the…

2 days ago

OCC Reports Mortgage Performance for Second Quarter of 2024

WASHINGTON—The Office of the Comptroller of the Currency (OCC) reported on the performance of first-lien…

3 days ago