advanced 1 min answer

A regulated institution must satisfy sector-specific rules on outsourcing to cloud providers. What does architecture need to demonstrate?

outsourcingcloud-regulationexitoversightfinancial
Show the full answer Hide the answer

What supervisors typically require

  • Effective oversight of the provider, meaning the institution can monitor and evidence the provider's performance rather than relying on assurance reports alone.
  • Access and audit rights, including for the supervisor, which must be contractually secured and practically exercisable.
  • A documented exit strategy that is credible — not a clause, but an assessed plan with a timeline and a destination.
  • Assessment of concentration risk, both the institution's dependence on one provider and the sector's.
  • Sub-outsourcing visibility, since the provider's own dependencies are part of the risk and are frequently unmapped.
  • Data location and access transparency, including which staff in which jurisdictions can reach the data.

What architecture must provide

  • Portability where it is credible. Managed services with proprietary interfaces make exit expensive, and the honest position is to accept the lock-in with an assessed cost rather than to claim a portability that has never been tested.
  • Evidence generated continuously — control operation, availability, incident history — rather than assembled for each review.
  • Data extraction capability, tested, since an exit plan that has never been exercised is an assumption.
  • Criticality-based tiering, so the strongest requirements apply to the services that genuinely matter and not uniformly.

The exit question honestly answered

Full portability is rarely economic and rarely real. A more defensible position is a tiered one: critical services designed for portability with the exit path exercised; everything else using managed capability with the exit cost quantified and accepted.

Claiming portability that has never been tested is worse than accepting lock-in with an assessment, because the first is a control that will fail when relied on and the second is a known risk with a number attached.