Rules for cloud outsourcing
2. Are there any rules that apply to cloud use by financial institutions (e.g., rules regarding outsourcing or the use of cloud services)?

Yes, a financial institution's use of a cloud service provider's services is likely to be directly subject to the following rules and guidelines specifically relating to outsourcing:

  1. The Monetary Authority of Singapore ("MAS") Guidelines on Outsourcing if the cloud use relates to outsourced services — financial institutions that are regulated by MAS are subject to these guidelines.
  2. The Association of Banks in Singapore Cloud Computing Implementation Guide 2.0 — this guide is a set of industry codes and best practices applicable to banks.
  3. The MAS Guidelines on Technology Risk Management — financial institutions that are regulated by MAS are subject to these guidelines.

There are also various other related rules/best practices on the use of technology or third parties more generally, such as the MAS Notice on Technology Risk Management, the MAS Notice on Cyber Hygiene, the Business Continuity Management Guidelines and the MAS Public Cloud Advisory. Financial institutions should be mindful of the obligations/best practices in these regulatory instruments and advisory notices, and ensure they can still be met even if operations/services are outsourced. MAS' August 2022 Information Paper on "Operational Risk Management — Management Of Outsourcing And Third-Party Arrangements" also provides further relevant guidance. 

Changes were made to the Banking Act in 2020 that contemplate MAS would issue revised outsourcing notices that would mandate banks' compliance with a range of requirements, including certain matters currently covered by the MAS Guidelines on Outsourcing, and more. At the time of writing, those notices have not yet been issued, so the contemplated changes are not in effect.

In December 2020, MAS issued a consultation paper on a proposed notice to banks on managing outsourced relevant services, which expressly includes public cloud services as relevant services. The proposals are still at the consultation stage.