Firms may outsource regulated and non-regulated activities to improve operational efficiency, access specialist expertise, or enhance business resilience. Where an arrangement is within the scope of the outsourcing policy, firms must comply with the applicable codes of practice and the seven core principles of the outsourcing policy, taking account of the supporting guidance. This thematic examination assessed whether firms had adequate systems and controls, including policies and procedures to meet those requirements.
To test this, we conducted a desk‑based review of firms’ policies, procedures and supporting documentation, followed by onsite examinations involving interviews with key persons, board members and staff. All eight firms received direct feedback, and where deficiencies were identified, they were required to submit formal remediation plans outlining how issues would be addressed.
Key findings
Overall, our thematic examination highlighted a generally acceptable level of compliance with the applicable obligations. This is a summary of the key findings under the following categories:
identification of activities caught by the outsourcing policy: instances of activities caught by the outsourcing policy but not notified to us
contingency plans: instances where contingency plans were inadequate or lacked evidence of periodic testing
policies and procedures: instances where reliance was placed on group outsourcing procedures with no tailoring to the specific requirements of the outsourcing policy
awareness of suspicious activity reporting (SAR) obligations: instances where firms could not evidence that SAR reporting obligations were communicated to the outsourced service providers
material change to outsourcing notification: instances where a material change to an outsourcing arrangement notification was not submitted to us