(Art. 11 FinMIA)
1 An outsourcing situation in accordance with Article 11 paragraph 1 FinMIA is deemed to exist if the financial market infrastructure has commissioned a service provider to independently and permanently provide an essential service for the financial market infrastructure in accordance with Article 12.
2 The following aspects in particular are to be addressed in the agreement with the service provider:
- a.
- the service to be outsourced and the services of the service provider;
- b.
- the responsibilities and the reciprocal rights and duties, particularly the financial market infrastructure's rights of inspection, instruction and control;
- c.
- the security requirements that must be fulfilled by the service provider;
- d.
- the service provider's adherence to the financial market infrastructure's business confidentiality and, insofar as legally protected data is provided to the service provider, the service provider's adherence to professional confidentiality;
- e.
- the rights of inspection and access of the internal audit function, the external audit firm, FINMA and – in the case of systemically important financial market infrastructures – the Swiss National Bank (SNB).
3 The financial market infrastructure must exercise care in the selection, instruction and controlling of the service provider. It shall integrate the outsourced service into its internal control system and monitor the services rendered by the service provider on an ongoing basis.
4 Outsourcing to foreign countries requires appropriate technical and organisational measures to ensure the observance of professional confidentiality and data protection in accordance with Swiss law. Contracting parties of a financial market infrastructure whose data is to be sent to a service provider abroad must be informed about this.
5 The financial market infrastructure, its internal audit function, the external audit firm, FINMA and – in the case of systemically important financial market infrastructures – the SNB must be able to inspect and review the outsourced service.
6 Paragraphs 1 to 5 do not apply if a central securities depository outsources some of its services or activities to a technical platform that connects securities settlement systems by way of providing a public service. This kind of outsourcing must be governed by means of a dedicated regulatory and operational framework, which requires the approval of FINMA.