Don’t do SECURITY. Do business SECURELY.

Brazil’s Central Bank updates cyber security and cloud rules

CMN Resolution 4,893 sets cyber security policy and cloud outsourcing requirements for Brazilian financial institutions.

Brazil’s National Monetary Council today issues CMN Resolution 4,893/2021, updating cyber security policy and cloud and data processing outsourcing requirements for Central Bank-supervised institutions.

Key points

  • Institutions must have a board-approved cyber security policy.
  • An incident response plan and incident information sharing are required.
  • Contracting cloud and data processing services requires due diligence and prior notification to the Central Bank.
  • Contracts must include rights of access and audit, with additional conditions for storage abroad.

UK cloud and technology providers serving Brazilian financial institutions should expect detailed due diligence, audit rights and data location requirements in contracts.

Source: CMN Resolution 4,893 (Banco Central do Brasil)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights