USA Law and Practice Contributed by: Brock Dahl, Beth George, Timothy Howard and Megan Kayo, Freshfields
Contractual Requirements Although the prudential regulators have authority to supervise TSPs, financial institutions remain primarily responsible for ensuring that TSPs’ activities are con - ducted in a safe and sound manner and in compliance with applicable laws and regulations, and they face liability for breaches or violations by TSPs. As such, financial institutions are expected to have robust third- party risk management processes, including contract development and ongoing monitoring. As described in the TSP Booklet, contracts between financial institu - tions and TSPs should include the following: • the right to audit and conduct business continuity planning (BCP) testing; • measurable service-level agreements (SLAs) for services being provided; • default and termination provisions; • the need for data security and confidentiality to, at a minimum, adhere to US regulatory standards (for foreign-based service providers); • clear definitions of data ownership and handling expectations; • the ability to request information describing a TSP’s response to relevant regulations, supervisory guidance, or other notices from federal banking agencies; • incident response and notification responsibilities; and • the extension of contractual terms to subcontrac - tors. 3.3 Key Operational Resilience Obligations Financial institutions are required to maintain risk management systems that are proportional to the size and complexity of their organisation (known as “tailoring”). Given that risk management is institution- specific, regulators have not established any required processes and controls for cybersecurity risk. How - ever, the regulatory guidance and FFIEC manuals described in 3.1 Scope of Financial Sector Opera- tional Resilience Regulation provide standards and best practices to help institutions comply with regu - lators’ objectives. The Joint Statement, described in 3.1 Scope of Financial Sector Operational Resilience Regulation , summarises the elements of effective cybersecurity controls as:
• response and resilience capabilities – review, update and test incident response and business continuity plans; • authentication – protect against unauthorised access; and • system configuration – securely configure systems and services. Incident and Reporting Obligations The prudential regulators issued a rule, effective as of April 2022, requiring financial institutions to notify their primary regulator of any computer security incidents that constitute “notification incidents”. The final rule defines a “notification incident” as a computer secu - rity incident that the financial institution believes could “materially disrupt, degrade, or impair”: • “the ability of the banking organisation to carry out banking operations, activities, or processes, or deliver banking products and services to a material portion of its customer base, in the ordinary course of business”; • “any business line of a banking organisation, including associated operations, services, func - tions and support [where this] would result in a material loss of revenue, profit, or franchise value”; or • “operations of a banking organisation, including associated services, functions and support, as applicable – the failure or discontinuance of which would pose a threat to the financial stability of the United States”. Financial institutions must notify their primary regula - tor as soon as possible and no later than 36 hours after the financial institution determines that a notifica - tion incident has occurred. Each prudential regulator has designated its own points of contact for notifica - tions, available on each regulator’s website. 3.4 Operational Resilience Enforcement Enforcement of the laws and regulations described in 3.1 Scope of Financial Sector Operational Resilience Regulation begins with the supervisory and examina - tion authority of the prudential regulators. For financial institutions, cybersecurity risks are assessed during a full-scope, on-site examination as part of the finan - cial institution’s routine supervisory cycle or during
469 CHAMBERS.COM
Powered by FlippingBook