Superannuation funds contemplating utilising cloud-based information technologies solutions may care to think again, following a tough assessment of cloud-based arrangements by the Australian Prudential Regulation Authority (APRA).
This week APRA released an information paper in which it urged regulated entities to take a cautious approach to the adoption of a cloud-based approach, at this stage.
Importantly, the information paper states, "In light of weaknesses in arrangements observed by APRA, it is not readily evident that risk management and mitigation techniques for public cloud arrangements have reached a level of maturity commensurate with usages having an extreme impact if disrupted".
"Extreme impacts can be financial and/or reputational, potentially threatening the ongoing ability of the APRA-regulated entity to meet its obligations," the APRA information paper said.
Further, it said the APRA stance "aligns with the position of other international financial regulators who also question the appropriateness of transitioning systems of record to a public cloud environment".
The APRA discussion paper concludes on the note that "the use of shared computing services represents a significant change to the way technology is employed. While shared computing services may bring benefits, such as economies of scale, they also bring associated risks".
It said the use of shared computing services by APRA-regulated entities expected to continually evolve, along with the maturity of the risk management and mitigation techniques applied and, for this reason, APRA encourages "ongoing dialogue to ensure prudent practices are in place and risks are adequately mitigated when regulated entities seek the advantages that shared computing services can realise".
A major super fund has defended its use of private markets in a submission to ASIC, asserting that appropriate governance and information-sharing practices are present in both public and private markets.
A member body representing some prominent wealth managers is concerned super funds’ dominance is sidelining small companies in capital markets.
Earlier this month, several Australian superannuation funds fell victim to credential stuffing attacks, which saw a small number of members lose more than $500,000.
Small- to medium-sized funds have become collateral damage in an "imperfect" model for super industry levies, a financial institution has said.