The guidance in FCG 2.2.1G on governance in relation to financial crime also applies to data security.
Firms should be alert to the financial crime risks associated with holding customer data and have written data security policies and procedures which are proportionate, accurate, up to date and relevant to the day-to-day work of staff.
Self-assessment questions:
- • How is responsibility for data security apportioned?
- • Has the firm ever lost customer data? If so, what remedial actions did it take? Did it contact customers? Did it review its systems?
- • How does the firm monitor that suppliers of outsourced services treat customer data appropriately?
• Are data security standards set in outsourcing agreements, with suppliers’ performance subject to monitoring?
Examples of good practice Examples of poor practice • There is a clear figurehead championing the issue of data security. • The firm does not contact customers after their data is lost or compromised. • Work, including by internal audit and compliance, is coordinated across the firm, with compliance, audit, HR, security and IT all playing a role. • Data security is treated as an IT or privacy issue, without also recognising the financial crime risk. • A firm’s plans to respond to data loss incidents are clear and include notifying customers affected by data loss and offering advice to those customers about protective measures. • A ‘blame culture’ discourages staff from reporting data losses. • A firm monitors accounts following a data loss to spot unusual transactions. • The firm is unsure how its third parties, such as suppliers, protect customer data. • The firm looks at outsourcers’ data security practices before doing business, and monitors compliance.
