Dieter REICHWEIN Directorate General Payment Systems and Market Infrastructure European Central Bank Market infrastructures‘ business continuity: Eurosystem.

Slides:



Advertisements
Similar presentations
Tips and Resources IASC Cluster/Sector Leadership Training
Advertisements

Armand Racine Consultant Chemicals Branch
The Benefits and Challenges of Implementation of Basel II in Europe José María Roldán | 27 Sept 2005.
Critical Infrastructure Protection Policy Priorities Sara Pinheiro European Commission DG Home Affairs.
Banking Union and the single supervisory mechanism (SSM) Meeting of the ad-hoc working party on the banking supervision mechanism, September 2012.
Table of contents 1 Manual of Operational Procedures (MOP) 2
The EU Recovery and Resolution framework Fátima Pires Financial Services Policy Division Directorate General Financial Stability Brussels, 2 October 2012.
Business Continuity and Disaster Recovery Planning.
1 The critical challenge facing banks and regulators under Basel II: improving risk management through implementation of Pillar 2 Simon Topping Hong Kong.
Data-Sharing and Governance Consultation ANALYSIS OF RESPONSES.
The quality framework of European statistics by the ESCB Quality Conference Vienna, 3 June 2014 Aurel Schubert 1) European Central Bank 1) This presentation.
Wales Accord on the Sharing of Personal Information (WASPI)
David Halldearn, ERGEG Conference on Implementing the 3 rd Package 11 th December 2008 Implementating the 3rd Package: An ERGEG Consultation paper.
Discussion Forum Bridge Consulting 9 November 2012.
Critical Role of ICT in Parliament Fulfill legislative, oversight, and representative responsibilities Achieve the goals of transparency, openness, accessibility,
OECD Guidelines on Insurer Governance
1 Framework Programme 7 Guide for Applicants
Financial Conglomerates, What are the Inherent Risks? 2006 CIAB Conference Port-of-Spain, Trinidad & Tobago November 16, 2006 Thordur Olafsson, CARTAC.
Principles of good practice Jana Kunická Community Philanthropy Initiative Coordinator European Foundation Centre.
EQARF Applying EQARF Framework and Guidelines to the Development and Testing of Eduplan.
Introduction In 1992, the Committee Of Sponsoring Organizations of the Treadway Commission (COSO) published Internal Control-Integrated Framework (1992.
GUIDELINES ON CRITERIA AND STANDARDS FOR PROGRAM ACCREDITATION (AREA 1, 2, 3 AND 8)
FUTURE OFFSHORE Update on the Consultation Nigel Peace Licensing & Consents Unit 27 March 2003.
Date (Arial 16pt) Title of the event – (Arial 28pt bold) Subtitle for event – (Arial 28pt) Implementation and policy overview Directors of General Insurance,
ESPON Seminar 15 November 2006 in Espoo, Finland Review of the ESPON 2006 and lessons learned for the ESPON 2013 Programme Thiemo W. Eser, ESPON Managing.
Towards a European network for digital preservation Ideas for a proposal Mariella Guercio, University of Urbino.
The ECB Statistical Quality Framework and Quality Assurance Procedures: An assessment in the light of the attempt to harmonise frameworks of international.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
Strategic Plan th October Management and Governance “GeSCI’s corporate structures and management arrangements were appropriate for.
The European Central Bank
1 Europe’s Monetary Union in practice José Manuel González-Páramo Member of the Executive Board and Governing Council of the European Central Bank 14th.
EU Funding opportunities : Rights, Equality and Citizenship Programme Justice Programme Jose Ortega European Commission DG Justice.
1 What model of governance for central bank’s operated systems? Denis BEAU Deputy Director Payment System and Market Infrastructure Directorate Banque.
International Relations Department Belgrade, September 28 TH, 2007 NBS PROJECT PROPOSALS.
Timely statistical information for monetary policy purposes
1 Financial market crisis and the relevance of European Statistics – the ECB perspective Caroline Willeke, Violetta Damia European Conference on Quality.
Summary of Local Seminars & Focus Groups 20/06/ Athens WP8 – TESTING II coordinated by IFI.
Indicators to Measure Progress and Performance IWRM Training Course for the Mekong July 20-31, 2009.
Proprietary Information of BearingPoint Inc. | Copyright 2005 BearingPoint Inc. All rights reserved. America’s First National Critical Infrastructure Exercise.
River Basin Management in Southern Africa Barbara Schreiner.
Microdata in ESCB banking statistics
Consultant Advance Research Team. Outline UNDERSTANDING M&E DATA NEEDS PEOPLE, PARTNERSHIP AND PLANNING 1.Organizational structures with HIV M&E functions.
The development of the market infrastructure for payment and securities handling Ramzi Hamadeh Group 2 Frankfurt am Main,
1. 2 TARGET2-Securities Washington, May 2007 Denis Beau Deputy Director Payment Systems and Market Infrastructure, Banque de France.
Development of System Operation Network Codes ACER Workshop 24 August 2011 Ole Jan Olesen, Convenor ENTSO-E Working Group on European Operational Standards.
Article 28(2) USD Introduction. The Problem Fraud and Misuse scale Evolving risks Impact on end users –Direct financial impact –Direct inconvenience Indirect.
© Copyright Allianz IIS Redefining the industry: Regulation, Risk & Global Strategy July 9, 2007 Berlin Helmut Perlet, Allianz SE The Emergence of Solvency.
19-20 October 2010 IT Directors’ Group meeting 1 Item 6 of the agenda ISA programme Pascal JACQUES Unit B2 - Methodology/Research Local Informatics Security.
Inter-American Development Bank BIMILACI 2007 QUALITY PROCUREMENT Third Party Review May 2007 Project Procurement Division.
Croatia: Result orientation within the process of preparation of programming documents V4+ Croatia and Slovenia Expert Level Conference Budapest,
Business Continuity Planning 101
AUDIT STAFF TRAINING WORKSHOP 13 TH – 14 TH NOVEMBER 2014, HILTON HOTEL NAIROBI AUDIT PLANNING 1.
TEMPUS INFORMATION DAY NEDAL JAYOUSI/Ph.d. NTO PALESITNE TEMPUS IV- FIFTH CALL FOR PROPOSALS.
Principles for Recovery and Resolution of a Financial Market Infrastructure ACSDA Senior Leadership Summit – November 16 & 17, 2015.
Crisis management related research at
Conduction of a simulation considering cascading effects
Pavel Racocha May, 2004 Dubrovnik, Croatia
Critical Infrastructure Protection Policy Priorities
PEFA 2016 Slides selected from the training materials of the PEFA secretariat.
America’s First National Critical Infrastructure Exercise
CAYMAN ISLANDS MONETARY AUTHORITY
Conduction of a simulation considering cascading effects
PEFA 2016 Slides selected from the training materials of the PEFA secretariat.
Hans Dufourmont Eurostat Unit E4 – Structural Funds
Plan your journey.
Neopay Practical Guides #2 PSD2 (Should I be worried?)
Commission proposal for a new LIFE Regulation CGBN meeting
Hans Dufourmont Eurostat Unit E4 – Structural Funds
Roles and Responsibilities
Operational Risk Management
Presentation transcript:

Dieter REICHWEIN Directorate General Payment Systems and Market Infrastructure European Central Bank Market infrastructures‘ business continuity: Eurosystem roles and activities The sixth international payment system conference, Budapest, 14 November 2007

I.Introduction II.Standard setting III.Fostering co-operation and information sharing IV.Leading by example in the design of own systems V.Simulation exercises Outline

1. Introduction Market infrastructures‘ business continuity: Eurosystem roles and activities

1. Introduction What is business continuity? Guaranteeing the continued operation of all core business activities in the event of sustained and severe disruptions Dealing with unexpected and unpredictable events Process that requires permanent review and improvement Possible trade-off between costs of business arrangements of individual players and the expected benefits

1. Introduction Why is business continuity of market infrastructures crucial? The smooth functioning of market infrastructures is crucial for the functioning of the entire financial system, including –The implementation of the monetary policy of the central bank –Financial stability Through network effects and the backbone function of major infrastructures, shocks can be transmitted –From infrastructures to participants (and vice versa) –Between different market segments (e.g. payments and securities)

1. Introduction Why has the importance of business continuity increased? Changed operational conditions –Move towards real-time processing –Increased operational complexity (interdependencies within and between market segments and geographical regions) New types of threats (e.g. terrorist attacks) Shortcomings of existing BC plans – continuous learning curve –Too narrow scope of scenarios considered –Lack of consideration of dependence on third-party service providers –Lack of compatibility of individual plans

1. Introduction Euro area specificities in the field of business continuity Complex and consolidating market infrastructure –Role of investment cycles –Bigger infrastructures may have the possibility to invest more in business continuity (e.g. TARGET1 vs. TARGET2) Up until now strong national dimension of existing policies, practices and plans

1. Introduction Reasons for Eurosystem involvement in business continuity Statutory responsibilities Existing externalities (individual costs vs. benefit for society) Co-ordination needs due to system interdependencies and European / global dimension of the issue Eurosystem objective in the field of business continuity Ensure the existence of adequate and co-ordinated business continuity strategies and plans of the various actors (central banks, market infrastructures, critical participants and third- party service providers)

Eurosystem measures / activities Ensure that existing standards and policies adequately reflect new threats and requirements Fostering co-operation and information sharing Leading by example Preparing and co-ordinating simulation exercises 1. Introduction

1I. Standard setting Market infrastructures‘ business continuity: Eurosystem roles and activities

1I. Standard-setting Euro area objectives Develop policies and standards, as far as possible in co-operation with the market (through round tables, public consultation etc.), that ensure an adequate level of infrastructure protection Consistent enforcement at national levels (also to ensure a level playing-field for market infrastructures across Europe) Situation in different fields Payment systems: BC Oversight Expectations for SIPS, June 2006 SWIFT: G10 High-level Expectations, June 2007 Securities settlement systems: ESCB/CESR not yet finalised

1I. Standard-setting Business Continuity Oversight Expectations for SIPS (I) Aimed at establishing a common framework in the euro area for the implementation of Core Principle VII that adequately reflects new threats and requirements in the field of business continuity Implementation of the Expectations: –SIPS: by mid 2009 –Critical participants: by mid 2010 Eurosystem to review implementation progress

Four main elements: 1.Definition of BC objectives and strategies –To be reviewed and approved at board level –Identification of critical functions (including outsourced functions) –Recovery and resumption of critical functions within the same settlement day („good practice“: within 2 hours; settlement of a limited number of critical payments should be possible at any time) Business Continuity Oversight Expectations for SIPS (II) 1I. Standard-setting

2.Developing business continuity plans –Ensure continuity of the service in a variety of plausible scenarios including major disasters, outages or disruptions covering a wide area –Consider scenarios where the primary site, critical functions and/or staff remain unavailable for more than a day –Ensure a different risk profile of and an appropriate geographic separation between the primary and the secondary site –Identify external dependencies and highlight any remaining single points of failure –Critical participants should also have a second processing site and same recovery time objectives as SIPS 1I. Standard-setting

3.Communication and crisis management –Clear procedures to respond to a crisis event –Establishment of a multi-discipline and multi-skilled Crisis Management Team (CMT) responsible for maintaining the crisis management plan (CMP) 4.Testing and regular updating business continuity plans –Update plans at least every 12 months –Good practice: participation in industry-wide testing 1I. Standard-setting

–Reliability and resilience High level expectations for SWIFT, June 2007: 1I. Standard-setting SWIFT is expected to: (i) to ensure that its critical services are available, reliable and resilient by implementing appropriate policies and procedures, and devoting sufficient resources, and that (ii) business continuity management and disaster recovery plans support the timely resumption of its critical services in the event of an outage. –Technology planning –Communication with users Developed by G10 SWIFT Co-operative Oversight Group Primary focus on operational risk The five high level expectations cover: –Risk identification and management –Information security

Currently no harmonised standards in the EU available due to blocking of the ESCB/CESR work that tried to adapt the existing CPSS/IOSCO Standards to the EU environment However, following initiatives of the ECB and the European Commission and discussion at the level of ECOFIN, the work is now being resumed with the objective to further clarify the scope, legal basis and content of the standards Proposal on the way forward to be made in spring 2008 Situation in the field of securities settlement 1I. Standard-setting

Public authorities to take the lead in setting standards, but preferably in co-operation with the market Lack of knowledge in the market on existing standards and initiatives at national, euro area, EU and global levels Existing standards show significant differences in terms of: –General approach (high-level vs. checklist; compulsary vs. “good practice” etc.) –Scope, structure and level of detail –Terminology and definitions (e.g. critical participant) Issue of multi-country players Some general experience / feedback from the market 1I. Standard-setting

III. Fostering co-operation and information sharing Market infrastructures‘ business continuity: Eurosystem roles and activities

Ensure availability of all relevant (static) information to all parties concerned through the development of an effective information sharing network Ensure effective crisis communication between public authorities and with the market participants Cover all relevant market segments and geographical levels (euro area / EU; global) Eurosystem objectives III. Fostering co-operation and information sharing

First step: compilation of the relevant information: –Collate existing standards, guidelines, best practices etc. at national, EU and G10 level; including conducting a consistency check of terminology (list of critical terms) and content of the standards, not with the aim of harmonising but to explain national peculiarities –Identify critical market infrastructures, service-providers / utilities and participants, including in particular those operating in various countries –Collate business continuity related contact groups etc. Information dissemination approach: „need to know“ - basis Development of an information sharing network (I) III. Fostering co-operation and information sharing

Development of a public BC domain on the websites of the ECB and the NCBs - for making non-confidential information on BC available to all relevant stakeholders, e.g.: –Explanation of the role of the Eurosystem/ESCB in BC –National, EU and G10 standards and initiatives –Glossary of major BC terms –Links to the relevant BC public domains of the other NCBs/ECB Use of a restricted BC domain - for sharing information of more confidential nature among central banks / public authorities Development of an information sharing network (II) III. Fostering co-operation and information sharing

Need to define procedures and mechanisms ensuring clear and accurate information flows, both internally and externally  Who communicates with whom, in which situation, on what and using which communication channels? Feedback from market participants at ECB conference on BC, September 2006: –At national level, market players generally know the contact points at their national authorities –Most infromation will flow via the existing national structures –Public authorities to take care of cross-market and cross-country communication Ensuring effective crisis communication (I) III. Fostering co-operation and information sharing

Crisis communication cascade at Eurosystem / ESCB level  Each central bank acts as contact point for other central banks as far as contacts with both other national authorities and with market infrastructures for which they act as (lead) overseer are concerned Similar communication network at G10 level Memorandum of Understanding for information sharing between overseers and banking supervisors Ensuring effective crisis communication (II) III. Fostering co-operation and information sharing

1V. Leading by example in the design of own systems Market infrastructures‘ business continuity: Eurosystem roles and activities

Development of TARGET2: significant improvement inter alia in business continuity terms due to new design concept Two regions / four sites Recovery and resumption objective –2 hours for regional desaster –< 1 hour for other scenarios Minimum service level through independent Contigency Module Requirements for (critical) participants regarding system security and business continuity IV. Leading by example

V. Simulation exercises Market infrastructures‘ business continuity: Eurosystem roles and activities

V. Simulation exercises Activities at the level of individual infrastructures The BC Oversight Expectations for SIPS require regular testing of BC plans, inter alia to: –Validate the effectiveness of the BC strategy –Verify that arrangements are viable in practice –Ensure continued readiness –Familiarise staff with the operation of the plan and their responsibilities –Evaluate co-ordination needs with external service providers

V. Simulation exercises Activities at national levels in the EU (I) In 2006 – 2007, cross-system simulation exercises have been conducted in various EU countries Exercises have been organised by –BC working groups, including the central banks, other public authorities and major market players –The national central bank –Other public authorities

V. Simulation exercises Activities at national levels in the EU (II) Stated objectives of the exercises were, inter alia, to: –Test the national crisis communication infrastructure –Optimise individual participants crisis management and BC organisation –Test the interoperability of individual BC plans –Test the availability of decision-makers and ensure their awareness of their roles –Check availability of secondary site Frequency of tests depends on what is going to be tested Ideas in various countries to increase complexity, frequency and/or number of involved players etc. in future exercises

V. Simulation exercises Activities at European level (I) No simulation exercises involving market participants have been conducted so far However, Eurosystem has started work on preparing such an exercise with the objectives of e.g.: –Checking the interoperability of BC plans on a wider scale –Better understanding existing interdependencies across infrastructures and market segments To be based on current set up of existing BC arrangements and organisational and communication structures

V. Simulation exercises Activities at European level (II) Possible start with a rather simple exercise and gradual widening of the scenarios to be considered in terms of Impacted or failed parties Type of failure(s) (premeses, staff, IT, utility service) Time, duration and geographical reach Discussions started at Eurosystem level; subsequently market players to be involved First exercise involving market players possibly in 2008/2009 Significant time for planning and preparation needed Priorisation of the tests needs to consider national initiatives as well as major ESCB projects and events (e.g. TARGET2)