AWS Cloud regulatory compliance framework for a BFS client to meet EBA (European Banking Authority) requirement

Ramesh Selvaraj
2 min readOct 19, 2021

--

Below is my experience in defining a framework for Cloud regulatory compliance (including EBA — European Banking Authority) for a financial service customer in Europe.

Financial Customers in Europe have below regulatory requirement:

  1. Materiality Assessment
  2. Adequately inform supervisors
  3. Access and audit rights
  4. Right of access
  5. Security
  6. Location of data and processing
  7. Supply-Chain outsourcing
  8. Contingency plans / Exit strategy

Below is a traceability matrix that maps Regulatory requirement, security and compliance framework and AWS services that helps for compliance.

Traceability Matrix for EBA requirement with AWS services

Below is the detailed approach on how at each phase, regulatory compliance can be met in AWS cloud transformation projects using AWS services and other 3rd party products.

Below are the support activities that may be required by client to meet EBA regulatory and compliance:

Below is the approach to be followed during well architected review, cloud exit strategy and 3rd party product evaluation.

Below are list of AWS services that help in meeting EBA requirement at various phases.

Below is the execution methodology

Below is the high level framework to meet regulatory and compliance requirement.

Compliance, regulatory and security
Framework for AWS projects

By following above framework and guidelines, AWS projects can meet EBA regulatory compliance requirements.

--

--

Ramesh Selvaraj
Ramesh Selvaraj

Written by Ramesh Selvaraj

Enterprise Cloud Architect, Sr. Director (Cloud), AWS 5x Certified, Virtusa, London

No responses yet