TAIWAN Law and Practice Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law
Cross-border outsourcing According to Article 17 of the Outsourcing Regula - tions, financial institutions, when outsourcing services outside of Taiwan, should follow certain requirements, including: • maintain a clear understanding of the service pro - vider’s data usage, processing and control meas - ures; • ensure that customer data is distinctly segregated from the service provider’s own data as well as that of other clients; • guarantee that customer data processed by the service provider remains accessible to both the financial institution and the FSC upon request; • conduct regular examinations and supervision of the service provider’s operations, either through external audits or internal review processes; and • in the event of a foreign financial regulator seeking information concerning Taiwanese customers from the service provider, notify the FSC and obtain its prior approval before any disclosure is made. Critical consumer information system outsourcing Pursuant to the Outsourcing Regulations, a financial institution must obtain prior approval from the FSC before outsourcing any critical consumer information system to a service provider located outside of Tai - wan. This approval is a prerequisite for engaging such service providers to perform outsourcing services. Additionally, the service providers engaged by finan - cial institutions are required to submit all documenta - tion requested by the FSC to facilitate the approval process. Criteria for critical consumer information system The FSC has issued explanatory guidance to clarify the application of the Outsourcing Regulations. This guidance outlines key factors that financial institutions should consider when assessing the criticality of an outsourcing arrangement, including but not limited to: • whether the outsourced function constitutes a core component of the institution’s business operations; • the potential impact of the outsourcing on the institution’s earnings, solvency, liquidity, funding capacity, capital adequacy and overall risk profile;
For instance, under the Regulations Governing Inter - nal Operating Systems and Procedures for the Out - sourcing of Financial Institution Operations (Outsourc - ing Regulations), the scope of permissible outsourcing is clearly defined and includes services related to: • the financial institution’s registered business activi - ties, as specified on its business licence; and • operations involving customer information, whether pertaining to individuals or legal entities. Permissible outsourced activities are limited to certain functions, including but not limited to: • data entry, processing and output within informa - tion systems; • the development, monitoring, control and mainte - nance of such systems; and • logistical support related to data processing. Furthermore, outsourcing arrangements must com - ply with specific regulatory requirements designed to ensure operational integrity and protect customer information. The key provisions governing these outsourcing activ - According to Article 10 of the Outsourcing Regula - tions, the financial institutions should implement out - sourcing contracts with the service providers, stating, among other things, that: • the FSC and the central bank may obtain relevant information or reports, conduct financial inspec - tions or order the provision of relevant information or reports within a specified period, with respect to the scope of the outsourcing matters; and • without the prior written consent of the financial institution, the service providers should not sub - contract the outsourced operations – the scope, restrictions and conditions of any subcontracting, if any, should be specified in the outsourcing con - tract as well. ities include the following. Contractual requirements
398 CHAMBERS.COM
Powered by FlippingBook