Use by Banks of Cloud Computing: An Empirical Study

97 Pages Posted: 20 Oct 2016 Last revised: 2 Nov 2016

See all articles by W. Kuan Hon

W. Kuan Hon

Imperial College London

Christopher Millard

Queen Mary University of London, School of Law - Centre for Commercial Law Studies

Date Written: October 20, 2016

Abstract

This paper explores the extent to which public cloud computing is in fact being used in practice by banks operating in the EU, including global banks. It is based primarily on anonymised interviews with banks, cloud providers, advisers, and financial services regulators. This paper describes how banks are using cloud computing and their key drivers (such as time to market), as well as real and perceived barriers (such as misconceptions about cloud, and financial services regulation), including cultural and technical/commercial as well as legal/regulatory aspects. It summarises how banks and regulators have approached the cloud, as well as how cloud providers have approached the banking sector.

Specific consideration is given to barriers arising from banking regulatory rules on outsourcing, critical or material, and the contentious issue of contractual audit rights for regulators. The paper also analyses legal and practical issues such as risk assessments, security, business continuity including exit plans, concentration risk and bank resolution, continuing regulatory oversight, banking secrecy laws, barriers under data protection law including personal data export restrictions, problems arising from layered service models where SaaS services are built on another provider’s IaaS/PaaS service, and commonly-negotiated contractual provisions regarding termination, service changes and liability.

The paper concludes that, while some barriers are internal and some external, cloud is still misunderstood, and further educational efforts are needed to ensure regulatory approaches and guidance are sufficiently cloud-aware to strike the appropriate balance between risk management and efficiency/innovation across the European Economic Area.

Keywords: cloud computing, banks, financial services regulation, banking regulation, data protection, cloud use, EU, European Union, cloud providers, MIFID

JEL Classification: F30, F65, G15, G21, G28, K12, K22, K23, J33, L50, L85, M15, N20, N24, O16, O32, O33

Suggested Citation

Hon, W. Kuan and Millard, Christopher, Use by Banks of Cloud Computing: An Empirical Study (October 20, 2016). Queen Mary School of Law Legal Studies Research Paper No. 245/2016, Available at SSRN: https://ssrn.com/abstract=2856431

W. Kuan Hon (Contact Author)

Imperial College London ( email )

South Kensington Campus
Exhibition Road
London, Greater London SW7 2AZ
United Kingdom

Christopher Millard

Queen Mary University of London, School of Law - Centre for Commercial Law Studies ( email )

67-69 Lincoln's Inn Fields
London, EC2A 3JB
United Kingdom

HOME PAGE: http://www.law.qmul.ac.uk/staff/millard.html

Do you have negative results from your research you’d like to share?

Paper statistics

Downloads
1,834
Abstract Views
4,900
Rank
17,240
PlumX Metrics