Brazil’s National Monetary Council today issues CMN Resolution 4,893/2021, updating cyber security policy and cloud and data processing outsourcing requirements for Central Bank-supervised institutions.
Key points
- Institutions must have a board-approved cyber security policy.
- An incident response plan and incident information sharing are required.
- Contracting cloud and data processing services requires due diligence and prior notification to the Central Bank.
- Contracts must include rights of access and audit, with additional conditions for storage abroad.
UK cloud and technology providers serving Brazilian financial institutions should expect detailed due diligence, audit rights and data location requirements in contracts.
Source: CMN Resolution 4,893 (Banco Central do Brasil)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.