Regulators cracking down on outsourcers | ZDNet
Summary
In the United Kingdom the Financial Services Authority is clear that the ultimate responsibility for a control failure remains with the client not the outsourcer. In late August, sensitive information on criminals was lost by a Home Office contractor--and this weekend it has emerged data on 5,000 staff also has gone missing, resulting in embarrassment and front page headlines in both cases. And the recent introduction of MiFID (Markets in Financial Instruments Directive) has also raised the bar, making it clear that client firms are not only ultimately responsible for the services delivered by their outsourcer, but are also responsible for ensuring on an ongoing basis they have the right people, processes and controls in place to provide effective management and monitoring of the supplier. These high impact incidents seriously harm the reputation of the core firm, even when the root cause occurred within an associate, subsidiary, third party or outsourced provider. The implications of the recent cases of companies failing to comply with the FSAs strict IT security regulations should raise the level of concern for those firms going down the outsourcing route.