Related provisions for SYSC 13.8.8
1 - 20 of 24 items.
The high level requirement for appropriate systems and controls at SYSC 3.1.1 R applies at all times, including when a business continuity plan is invoked. However, the FCA1 recognises that, in an emergency, a firm may be unable to comply with a particular rule and the conditions for relief are outlined in GEN 1.3 (Emergency).
A firm should consider the likelihood and impact of a disruption to the continuity of its operations from unexpected events. This should include assessing the disruptions to which it is particularly susceptible (and the likely timescale of those disruptions) including through:(1) loss or failure of internal and external resources (such as people, systems and other assets);(2) the loss or corruption of its information; and(3) external events (such as vandalism, war and "acts
A firm should implement appropriate arrangements to maintain the continuity of its operations. A firm should act to reduce both the likelihood of a disruption (including by succession planning, systems resilience and dual processing); and the impact of a disruption (including by contingency arrangements and insurance).
A firm should document its strategy for maintaining continuity of its operations, and its plans for communicating and regularly testing the adequacy and effectiveness of this strategy. A firm should establish:(1) formal business continuity plans that outline arrangements to reduce the impact of a short, medium or long-term disruption, including:(a) resource requirements such as people, systems and other assets, and arrangements for obtaining these resources;(b) the recovery
21For a common platform firm:(1) the MiFID Org Regulation applies, as summarised in SYSC 1 Annex 1 3.2G, SYSC 1 Annex 1 3.2-AR and SYSC 1 Annex 1 3.2-BR; and (2) the rules and guidance apply as set out in the table below:SubjectApplicable rule or guidanceGeneral requirements SYSC 4.1.1R, SYSC 4.1.1CR, SYSC 4.1.2R, SYSC 4.1.2AARBusiness continuitySYSC 4.1.6R, SYSC 4.1.7R, SYSC 4.1.8GAudit committeeSYSC 4.1.11G, SYSC 4.1.13G, SYSC 4.1.14GPersons who effectively direct the businessSYSC
A CRR firm21 and a management company10 must establish, implement and maintain an adequate business continuity policy aimed at ensuring, in the case of an interruption to its systems and procedures, that any losses are limited, the preservation of essential data and functions, and the maintenance of its regulated activities, or, in the case of a management company, its collective portfolio management activities,10 or, where that is not possible, the timely recovery of such data
The matters dealt with in a business continuity policy should include:(1) resource requirements such as people, systems and other assets, and arrangements for obtaining these resources;(2) the recovery priorities for the firm's operations; (3) communication arrangements for internal and external concerned parties (including the FCA21, clients and the press);(4) escalation and invocation plans that outline the processes for implementing the business continuity plans, together with
16Arrangements to ensure P2P agreements facilitated by the firm continue to be managed and administered may include:(1) entering into an arrangement with another firm to take over the management and administration of P2P agreements if the operator ceases to operate the electronic system in relation to lending; or(2) holding sufficient collateral in a segregated account to cover the cost of management and administration while the loan book is wound down; or(3) entering into an
Before entering into, or significantly changing, an outsourcing arrangement, a firm should:(1) analyse how the arrangement will fit with its organisation and reporting structure; business strategy; overall risk profile; and ability to meet its regulatory obligations;(2) consider whether the agreements establishing the arrangement will allow it to monitor and control its operational risk exposure relating to the outsourcing;(3) conduct appropriate due diligence of the service
In negotiating its contract with a service provider, a firm should have regard to:(1) reporting or notification requirements it may wish to impose on the service provider;(2) whether sufficient access will be available to its internal auditors, external auditors or actuaries (see section 341 of the Act) and to the FCA2 (see SUP 2.3.5 R (Access to premises) and SUP 2.3.7 R (Suppliers under material outsourcing arrangements);(3) information ownership rights, confidentiality
A firm should ensure that it has appropriate contingency arrangements to allow business continuity in the event of a significant loss of services from the service provider. Particular issues to consider include a significant loss of resources at, or financial failure of, the service provider, and unexpected termination of the outsourcing arrangement.
The policy and procedures manual should cover all aspects of the credit union's operations, including matters such as:(1) cash handling and disbursements;(2) collection procedures;(3) lending, (see CREDS 7.1 to CREDS 7.2)5;(4) arrears management (see CREDS 7.2.9 G to CREDS 7.2.10 G);(5) provisioning5;(6) liquidity management5;(7) financial risk management5;(8) money laundering prevention (see SYSC 6.3);(9) internal audit (see CREDS 2.2.40 G to CREDS 2.2.50 G);(10) information
A credit union should put in place contingency arrangements to ensure that it could continue to operate and meet its regulatory requirements in the event of an unforeseen interruption that may otherwise prevent the credit union from operating normally (for example, if there was a complete failure of IT systems or if the premises were destroyed by fire).
A firm must:(1) have in place effective business continuity arrangements to deal with any failure of its trading systems; and(2) ensure that its systems are fully tested and properly monitored to ensure that it meets the requirements of (1) and of MAR 7A.3.2R. [Note: article 17(1) of MiFID and MiFID RTS 6 specifying the organisational requirements of investment firms engaged in algorithmic trading]
A firm must provide the following, at the FCA’s request, within 14 days from receipt of the request: (1) a description of the nature of its algorithmic trading strategies; (2) details of the trading parameters or limits to which the firm’s system is subject; (3) evidence that MAR 7A.3.2R (systems and controls) and MAR 7A.3.3R (business continuity and system tests) are met; (4) details of the testing of the firm’s systems; (5) the records in MAR 7A.3.8R(2) (accurate and time-sequenced
A firm should establish and maintain appropriate systems and controls for managing operational risks that can arise from inadequacies or failures in its processes and systems (and, as appropriate, the systems and processes of third party suppliers, agents and others). In doing so a firm should have regard to:(1) the importance and complexity of processes and systems used in the end-to-end operating cycle for products and activities (for example, the level of integration of systems);(2)
Regarding operational risk, matters of which the FCA1 would expect notice under Principle 11 include:(1) any significant operational exposures that a firm has identified;(2) the firm's invocation of a business continuity plan; and(3) any other significant change to a firm's organisation, infrastructure or business operating environment.
(1) 1The FCA expects to have an open, cooperative and constructive relationship with data reporting services providers to enable it to understand and evaluate data reporting services providers’ activities and their ability to meet the requirements in the DRS Regulations. As part of that relationship the FCA expects a data reporting services provider to provide it with information about any proposed restructuring, reorganisation or business expansion which could have a significant
The purpose of REC 3.16 is to ensure that the FCA1receives a copy of the UK recognised body's plans and arrangements for ensuring business continuity if there are major problems with its computer systems. The FCA1does not need to be notified of minor revisions to, or updating of, the documents containing a UK recognised body's business continuity plan (for example, changes to contact names or telephone numbers). [Note:MiFID RTS 7 requires that the operator of a trading venue assess
Schedule to the Recognition Requirements Regulations, paragraphs 3 – 3H4Paragraph 3 – Systems and controls4(1)The [UK RIE] must ensure that the systems and controls, including procedures and arrangements,4 used in the performance of its functions and the functions of the trading venues it operates are adequate, effective4 and appropriate for the scale and nature of its business.(2)Sub-paragraph (1) applies in particular to systems and controls concerning - (a)the transmission
Where MiFID RTS 7 does not apply to a UK RIE, the FCA may in addition have regard to the performance, capacity and reliability of its systems.4 The FCA3 may also have regard to the arrangements for maintaining, recording and enforcing technical and operational standards and specifications for information technology systems, including:3(1) the procedures for the evaluation and selection of information technology systems;(2) the arrangements for testing information technology systems
The FCA will adopt a pre-emptive approach which will be based on making forward-looking judgments about firms' business models, product strategy and how they run their businesses, to enable the FCA to identify and intervene earlier to prevent problems crystallising. The FCA's approach to supervising firms will contribute to its delivery against its objective to protect and enhance the integrity of the UK financial system (as set out in the Act). Where the FCA has responsibilities
The conditions referred to in ICOBS 8.4.4R (2)(d) and ICOBS 8.4.7R (1)(a)(ii) are that the tracing office is one which:(1) maintains a database which:(a) accurately and reliably stores information submitted to it by firms for the purposes of complying with these rules;(b) has systems which can adequately keep it up to date in the light of new information provided by firms;(c) has an effective search function which allows a person inputting data included on the database relating
An authorised fund manager carrying out due diligence for the purpose of the rules in this section should make enquiries or otherwise obtain information needed to enable him properly to consider:(1) whether the experience, expertise, qualifications and professional standing of the second scheme's investment manager is adequate for the type and complexity of the second scheme;(2) the adequacy of the regulatory, legal and accounting regimes applicable to the second scheme and its
A firm should establish and maintain appropriate systems and controls for the management of operational risks that can arise from employees. In doing so, a firm should have regard to:(1) its operational risk culture, and any variations in this or its human resource management practices, across its operations (including, for example, the extent to which the compliance culture is extended to in-house IT staff);(2) whether the way employees are remunerated exposes the firm to the
Business areas and management functionsExplanation(1) Payment servicesThis means:(1) payment services;(2) issuing and administering other means of payment (for example, cheques and bankers' drafts);(3) issuing electronic money; and(4) current accounts.(2) SettlementThis means clearing and settlement of any transactions described in rows (3) and (6) to (9) of this annex, in relation to the assets covered by (9).It also includes clearing and settlement of any transactions described
MAR 5.3A.1R applies in particular to systems and controls concerning:(1) the resilience of the firm’s trading systems;(2) its capacity to deal with peak order and message volumes;(3) the ability to ensure orderly trading under conditions of severe market stress;(4) the effectiveness of business continuity arrangements to ensure the continuity of the MTF’s services if there is any failure of its trading systems, including the testing of the MTF’s systems and controls;(5) the ability
A firm, other than a Solvency II firm,15 should have in place appropriate arrangements, having regard to the nature, scale and complexity of its business, to ensure that it can continue to function and meet its regulatory obligations in the event of unforeseen interruption. These arrangements should be regularly updated and tested to ensure their effectiveness. Solvency II firms are subject to the business continuity requirements in PRA Rulebook: Solvency II firms: Conditions
MAR 5A.5.1R applies in particular to systems and controls concerning: (1) the resilience of the firm’s trading systems;(2) its capacity to deal with peak order and message volumes;(3) the ability to ensure orderly trading under conditions of severe market stress;(4) the effectiveness of business continuity arrangements to ensure the continuity of the OTF’s services if there is any failure of its trading systems, including the testing of the OTF’s systems and controls;(5) the ability
(1) The FCA3 will consider reducing the amount of a penalty if a firm will suffer serious financial hardship as a result of having to pay the entire penalty. In deciding whether it is appropriate to reduce the penalty, the FCA3 will take into consideration the firm’s financial circumstances, including whether the penalty would render the firm insolvent or threaten the firm’s solvency. The FCA3 will also take into account its statutory objectives3, for example in situations where