advanced
1 min answer
A regulated institution must satisfy sector-specific rules on outsourcing to cloud providers. What does architecture need to demonstrate?
Show the full answer Hide the answer
What supervisors typically require
- Effective oversight of the provider, meaning the institution can monitor and evidence the provider's performance rather than relying on assurance reports alone.
- Access and audit rights, including for the supervisor, which must be contractually secured and practically exercisable.
- A documented exit strategy that is credible — not a clause, but an assessed plan with a timeline and a destination.
- Assessment of concentration risk, both the institution's dependence on one provider and the sector's.
- Sub-outsourcing visibility, since the provider's own dependencies are part of the risk and are frequently unmapped.
- Data location and access transparency, including which staff in which jurisdictions can reach the data.
What architecture must provide
- Portability where it is credible. Managed services with proprietary interfaces make exit expensive, and the honest position is to accept the lock-in with an assessed cost rather than to claim a portability that has never been tested.
- Evidence generated continuously — control operation, availability, incident history — rather than assembled for each review.
- Data extraction capability, tested, since an exit plan that has never been exercised is an assumption.
- Criticality-based tiering, so the strongest requirements apply to the services that genuinely matter and not uniformly.
The exit question honestly answered
Full portability is rarely economic and rarely real. A more defensible position is a tiered one: critical services designed for portability with the exit path exercised; everything else using managed capability with the exit cost quantified and accepted.
Claiming portability that has never been tested is worse than accepting lock-in with an assessment, because the first is a control that will fail when relied on and the second is a known risk with a number attached.