Google Cloud Platform Bends to Regulation at SLA Level
The company has taken a tailored approach to outsourcing contracts as increased scrutiny demands portability and audit rights from cloud service providers.
As financial regulators bring cloud providers under increasing scrutiny, Google Cloud Platform (GCP) is taking an industry-specific approach to service-level agreements, GCP’s vice president of engineering has said.
“Regulators care about what kinds of contracts these banks are signing,” Suzanne Frey said at the Google Next conference in London, in response to a question from WatersTechnology.
Frey said Google Cloud has taken a “multi-pronged” approach to its service-level agreements to make them relevant for each industry and, in the case of financial services, fit them to local regulations.
“We have tweaked our contracts to be very specific to industries and even in some cases the regions in which we are working,” she said.
In financial services regulations “there are some common denominators worldwide, and there are some specific rules in different jurisdictions. So, first and foremost, we have made changes there to align with the regulatory demands,” Frey said.
GCP has written audit rights into its contracts, for example. This reflects regulations such as the EU guidelines on outsourcing that were updated this year and demand that outsourcing contracts set out the rights of users to audit providers’ premises, including devices, systems and networks.
“We have been working with financial regulators in Europe and worldwide on engagement and audits to expose the full depth of our operations, how we handle information, how we handle business continuity, and the like. And then we are continuing to invest in various compliance regimes,” she said.
Another concern of regulators is portability—the ease with which data can be moved from one cloud provider to another. Logistically that is not a difficult task to undertake, but service providers don’t want to make it too easy for clients to be able to break contract and move to another provider. Regulators are trying to get cloud providers to ensure that their service-level agreements with users don’t hinder the portability of data.
Frey said she understands and respects concerns about portability, but noted that cloud providers are already prepared for outages and prior regulation.
“All the major cloud providers have invested in business continuity and in really, really strong, reinforced infrastructure worldwide. I understand where the pressure for these exit plans is coming from … but fundamentally all of us have to be compliant with GDPR [the EU’s General Data Protection Regulation] and ensure portability anyway.”
Frey said increasing numbers of financial users are starting to use Google Cloud. The tech giant entered the cloud business later than Amazon Web Services and Microsoft with its Azure business, and still has a market share in the single digits. However, research firm Canalys says GCP is the fastest-growing business of the three, up 90% year on year in 2019.
Most financial firms rely on at least one of these three providers for cloud services, and this so-called concentration risk is worrying governments and supervisory authorities. The EU outsourcing guidelines, for one, are partly intended to help regulators monitor the industry’s over-reliance on a small handful of service providers. The Bank of England has even said that certain aspects of cloud providers’ businesses could one day fall under direct supervision.
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@waterstechnology.com or view our subscription options here: http://subscriptions.waterstechnology.com/subscribe
You are currently unable to print this content. Please contact info@waterstechnology.com to find out more.
You are currently unable to copy this content. Please contact info@waterstechnology.com to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@waterstechnology.com
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@waterstechnology.com
More on Regulation
Off-channel messaging (and regulators) still a massive headache for banks
Waters Wrap: Anthony wonders why US regulators are waging a war using fines, while European regulators have chosen a less draconian path.
Banks fret over vendor contracts as Dora deadline looms
Thousands of vendor contracts will need repapering to comply with EU’s new digital resilience rules
Chevron’s absence leaves questions for elusive AI regulation in US
The US Supreme Court’s decision to overturn the Chevron deference presents unique considerations for potential AI rules.
Aussie asset managers struggle to meet ‘bank-like’ collateral, margin obligations
New margin and collateral requirements imposed by UMR and its regulator, Apra, are forcing buy-side firms to find tools to help.
The costly sanctions risks hiding in your supply chain
In an age of geopolitical instability and rising fines, financial firms need to dig deep into the securities they invest in and the issuing company’s network of suppliers and associates.
Industry associations say ECB cloud guidelines clash with EU’s Dora
Responses from industry participants on the European Central Bank’s guidelines are expected in the coming weeks.
Regulators recommend Figi over Cusip, Isin for reporting in FDTA proposal
Another contentious battle in the world of identifiers pits the Figi against Cusip and the Isin, with regulators including the Fed, the SEC, and the CFTC so far backing the Figi.
US Supreme Court clips SEC’s wings with recent rulings
The Supreme Court made a host of decisions at the start of July that spell trouble for regulators—including the SEC.