Chris Skinner's blog

Shaping the future of finance

Does the regulator think that banks are clouding the issues?

Chris Skinner Author Avatar
by

During the lockdown, banks moved rapidly to sign cloud contracts. Thing is they were signing with the likes of Amazon, Google and Microsoft, but these are all American firms. Where are the European ones?

I raised this issue two years ago, but it is now coming to a head as new rules require banks to know exactly what data is being stored where and how by their cloud service providers.

This was a concern for a while, but spring-boarded front and centre when Amazon Web Services had another failure late last year.

Amazon’s massive cloud-computing operation Wednesday suffered its third outage in a month, briefly shutting down a vast number of online services critical to everyday life and highlighting again the vulnerabilities of an increasingly interconnected Web.

The fact that banks are dependent on these third party services, whether American or not, is an exposure that could lead to bank failures if those services fail. This is what the Prudential Regulatory Authority (PRA) are focused upon, and it is all about the operational resilience of cloud service providers.

A particular concern is if one of the big cloud providers is hacked or subject to a cyberattack. The ripple effect cascades through the economy and can affect everything from Slack to Tinder to core banking services.

How do we protect ourselves against such things?

That’s why the PRA is introducing a stringent new regime where banks must prove their checks and balances with their cloud service provides for disaster recovery and operational resilience. The new rules come into effect on March 31 2022.

This is important, particularly as Amazon Web Services has struck high-profile deals with Barclays and HSBC, while Lloyds Banking Group has announced partnerships with both Google Cloud and Microsoft Azure. McKinsey has forecast that 40% to 90% of banks’ IT operations globally could move to the cloud within a decade, according to the FT.

Whatever your view, it sits firmly in my view in the risk management aspects of technology within a bank or FinTech. You have regulated processes, a promise of trust, security and stability, and an expectation of resilience and surety that can never be broken. However, the more banks use third party services, whether API or cloud services, the more banks need to assure that they have completed full due diligence on their third party providers.

More importantly, and this is what the PRA is trying to ensure, if there is a failure in the network, there needs to be blame. I’ve always struggled with this for a while. If a payment fails and it was taken by Stripe and sent via Braintree to be processed by a MasterCard from an account of ABC Bank, who is to blame for the failure?

We are moving to a world where Banking-as-a-Service (BaaS) is great, but the failure of one player in the ecosystem, even if just for minutes, might create a forensic process of reconstruction to work out who is to blame. The way in which it is moving though, is that the detectives who will have to lead such investigations are the banks who determined to use such external services with their sensitive customer data.

Beware and be aware. With great power comes great responsibility, and banks are being viewed as having the power. Therefore, if they use cloud services and such services fail, they also have the responsibility.

 

Chris Skinner Author Avatar

Chris M Skinner

Chris Skinner is best known as an independent commentator on the financial markets through his blog, TheFinanser.com, as author of the bestselling book Digital Bank, and Chair of the European networking forum the Financial Services Club. He has been voted one of the most influential people in banking by The Financial Brand (as well as one of the best blogs), a FinTech Titan (Next Bank), one of the Fintech Leaders you need to follow (City AM, Deluxe and Jax Finance), as well as one of the Top 40 most influential people in financial technology by the Wall Street Journal's Financial News. To learn more click here...

What is the future?

Learn more

Learn more about Chris

About Chris Skinner

The Past, Present And Future Of Banking, Finance And Technology

Fintech expert Chris Skinner: countries need digital transformation to remain competitive

Join me on Linkedin

Follow Me on X!

Hire Chris Skinner for dinners, workshops and more

Learn directly from from one of the most influential people in technology, gain insights from the world's most innovative companies, and build a global network.

Chris’s latest book

Chris Skinner’s ‘Digital For Good’ Book Launch Event – CFTE

Top 50 Global Thought Leaders and Influencers on FinTech 2023

Chris Skinner
Commentator, CEO of The Finanser and best-selling author at The Finanser

Thinkers360 Thought Leader

Contact Me

Global Awards

Lifetime Achievement Award

Global 100 - 2024 Winner

Chris Skinner - Financial Markets Advisor of the Year - The Finanser - UK 2023

Best Financial Markets Advisor of the Year 2023

30 Best Regtech Blogs and Websites 2023

Kids creating the future bank | TEDxAthens

Captain Cake and the Candy Crew

Captain Cake Winner of a Golden Mom’s Choice Award

TWO-TIME WINNER OF A MOM’S CHOICE GOLD AWARD!

Alex at the Financial Services

Gaping Void's Hugh MacLeod worked with the Finanser