AMF and ICT risk: what a Quebec financial institution shows
The AMF expects security hygiene that prevents a major incident and limits its effects. A provincial licence decides: a federal institution follows OSFI.
The Guideline on Information and Communications Technology Risk Management was published in February 2020. The AMF expects an institution to take it up by 27 February 2021. It applies to the institutions the AMF supervises, including insurers, deposit institutions and trust companies. A federally regulated bank or insurer follows OSFI, not this guideline.
For the AMF, ICT risk is the business risk tied to the use, ownership, operation and adoption of technology. It includes availability and continuity, security including cybersecurity, change, data integrity and outsourcing.
A taxonomy of your own
The institution keeps a taxonomy that is its own, forward-looking, and aggregated across the organization. Three strategic risks belong in it: technology governance, technology positioning and technology execution. Categories to consider include information security, crisis management, outsourcing and cloud, continuity, projects, change, ICT operations, ethics, human resources and intellectual property.
Who is named
- A person responsible for the systems and technologies that support the institution's objectives, often the technology or information lead.
- A second-line person for information security, often the chief information security officer. That function does not perform internal audit and is separate from ICT operations.
- A second-line person for data.
- Senior-management owners for information assets and ICT risks.
The board receives updates on recovery and continuity tests, and it knows when a breach or a security incident is escalated to it. An information security policy covers confidentiality, integrity and availability, including information handled by an outside party. ICT security training reaches staff and suppliers who access the assets.
What the risk file contains
1. The assets
A periodic inventory of information assets, data, people, systems and premises, including those entrusted to a third party. Classification at least by availability, integrity and confidentiality.
2. The register
An ICT risk register, a risk and control matrix, and follow-up of the measures. The register is updated on a forward-looking basis.
3. Incidents and recovery
An incident process with recovery objectives. Impact analyses on critical processes. Tests of the plans. Replacement of hardware and software before the vendor ends support. A strategy for legacy systems that support critical operations.
4. The notice
Prompt notice to internal and external parties, including the AMF, when an operational incident disrupts, slows or interrupts a critical activity.
Internal audit reviews the design and effectiveness of security controls, including those maintained by outside parties. Quebec's private-sector privacy act and the Act to establish a legal framework for information technology still apply beside this guideline.
The expectations are read in light of the institution's nature, size, complexity and risk profile. The full text is the one the AMF published in February 2020.
The ICT register and the evidence in one place
CapRISK holds the taxonomy, the assets and the follow-up. CapAUDIT reviews the controls. CapTRISK tracks suppliers.
