CHINA Law and Practice Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Daniel Wang, Fangda Partners
3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation Unlike the EU’s Digital Operational Resilience Act (DORA) or the USA’s Sound Practices to Strengthen Operational Resilience, China’s framework adopts a layered, sector-specific approach. Its regulatory scope is defined by a combination of general cybersecurity and data security laws and industry-specific rules, which together establish the overarching compliance requirements for regulated financial institutions. At the general level, cybersecurity and data security legislation applies to all financial institutions as net - work operators and data handlers. Because certain core financial systems may be designated as CIIs and their operators CIIOs, they are subject to enhanced obligations under the CIIO Regulation. These rules establish baseline requirements for risk monitoring, incident response, emergency handling and recovery capabilities. At the sectoral level, sectoral rules refine operational resilience obligations across multiple dimensions. In terms of the data security regulations, there are the Measures for the Data Security Management of Bank - ing and Insurance Institutions (“NFRA DSL”, in Chi - nese 银行保险机构数据安全管理办法 ) and the Measures for the Administration of Data Security in the Business Fields of the People’s Bank of China (“PBOC DSL”, in Chinese 中国人民银行业务领域数据安全管理办法 ) focus - ing on data security risk monitoring, disposal and lifecycle management. As for IT outsourcing supervi - sion, the Measures for the Supervision of Information Technology Outsourcing Risks of Banking and Insur - ance Institutions (“IT Outsourcing Risk Management Measures”, in Chinese 银行保险机构信息科技外包风险监管 办法 ) specifically regulate the information technology outsourcing risks of banking and insurance institu - tions, including subcontracting management and exit mechanisms. With respect to core business continu - ity, the Measures for the Administration of Emergency Response Financial Services of Banking and Insur - ance Institutions clarify requirements for emergency drills and disaster recovery support to ensure continu - ous financial services during incidents.
China’s operational resilience-related rules do not establish a standalone, compliance-based extrater - ritorial regime comparable to DORA. However, Arti - cle 77 of the CSL explicitly recognises extraterritorial jurisdiction where overseas entities engage in activi - ties that endanger China’s cybersecurity, thereby pro - ducing functional extraterritorial effects for relevant foreign service providers. 3.2 ICT Service Provider Contractual Requirements In the financial services sector, there is no special dis - tinction for those who provide information and com - munication technology (ICT) or other third-party IT services. They are collectively known as “information technology outsourcing”, which means that a banking or insurance institution engages service providers to conduct IT activities that would be otherwise under - taken by itself, including the entrusted processing of data. These outsourcings are subject to restrictions due to third-party risks associated with outsourcing. Under Article 37 and 38 of the CSL, where ICT and other third-party service providers supply network products or services to CIIOs, they are required to co- operate with the applicable national security review if such products or services are critical to the operation of the CII, and to comply with statutory confidentiality and data security obligations. These security review and confidentiality requirements should be clearly stipulated in the vendor contracts. In the financial services sector, according to Articles 6 and 7 of the IT Outsourcing Risk Management Meas - ures, banking and insurance institutions are required to establish an IT outsourcing governance structure and decision-making/approval procedures (at the board and senior management levels) to ensure effec - tive oversight and accountability. According to Article 21 of the IT Outsourcing Risk Management Meas - ures, IT outsourcing contracts are required to include clauses covering: scope of service, regulatory compli - ance, service continuity, audit and supervisory rights of financial institutions, cybersecurity and data pro - tection, incident reporting mechanisms, and dispute resolution, among others, and, to the extent a foreign vendor is engaged, the vendor contract should have Chinese law as governing law and Chinese dispute
81 CHAMBERS.COM
Powered by FlippingBook