08.18.2021

Diversity of Cloud Computing Models Raises Challenges

08.18.2021
Diversity of Cloud Computing Models Raises Challenges

A diversity of cloud computing models is transforming how broker-dealers operate, with the potential to enhance agility, efficiency, resiliency and security within firms’ operations, while also highlighting the importance for firms to consider relevant regulatory factors for maintaining investor protection and market integrity, according to a new research report from FINRA.

The report, “Cloud Computing in the Securities Industry,” was issued by FINRA’s Office of Financial Innovation (OFI) following a review of nearly 40 broker-dealer firms, cloud service providers, industry analysts and technology consultants, to better understand the implications of cloud computing on the securities industry.

FINRA also requested comments on the report, including areas where guidance or modifications to FINRA rules may be desired to support cloud adoption while maintaining investor protection and market integrity. Comments are requested by Oct. 16, 2021.

“This report is intended to serve as a tool for our member firms and other industry stakeholders by providing information to help them learn from the experiences of others. In addition, it provides useful insights regarding the challenges and benefits associated with implementation of a cloud computing framework, from both an operational and regulatory perspective,” said Haimera Workie, Head of the Office of Financial Innovation and Senior Director at FINRA. “As broker-dealers are at various stages in their cloud computing journey—from full or partial integration, to pilot projects or not at all—many firms are seeking to explore how these technologies can be used to personalize customer experiences, analyze larger amounts of data faster and increase their competitiveness in areas of rapid innovation.”

During discussions with market participants, several common themes emerged:

  • The use of Software as a Service (SaaS) products was prevalent. Many firms, particularly smaller firms, used off-the-shelf SaaS cloud products for non-core business functions, such as email systems, customer relationship management, financial accounting and human resources operations.
  • Roll-outs of cloud infrastructure tended to be targeted, incremental and iterative. The majority of firms took a measured approach instead of launching a wholesale migration of the business to the cloud, acknowledging the need for project modifications, specialized skills and training, and measuring financial impact.
  • Firms focused heavily on governance, cloud security and training. Firms noted it was important to develop governance and cloud security policies and procedures to safeguard data and systems, often leveraging enhanced security protocols in the cloud environment.
  • Organization and cultural changes often accompanied cloud adoption. Optimizing cloud capabilities required changes in the way people work—ensuring greater responsiveness to business needs and enhanced time-to-market capabilities. Cloud adoption often coincided with firms’ reassessing their areas of technology expertise, frequently with existing staff being re-trained or acquiring new staff with cloud expertise.

“As adoption of the cloud continues to grow, firms are finding clear benefits, but also potential challenges,” Workie added. “We encourage broker-dealers to conduct their own assessments of the implications of cloud computing, based on their business models and related use cases, and share those learnings with us.”

Regulatory factors for those operating or migrating to the cloud to consider include:

  • Cybersecurity. Firms cite cybersecurity as a potential benefit to cloud computing, due to the many security features available in a cloud environment, but there are challenges in making sure their systems are appropriately configured for security on the cloud.
  • Data privacy. If a firm’s cloud adoption leads to changes in how it collects, stores, analyzes and shares sensitive customer data, firms may need to update their policies and procedures related to customer data privacy.
  • Outsourcing/vendor management. Outsourcing an activity or function to a cloud service provider or other cloud vendor does not relieve firms of their ultimate responsibility for compliance with all applicable securities laws, regulations and FINRA rules.
  • Business continuity. Firms are required to create, maintain, annually review and update written business continuity plans relating to an emergency or significant business disruption.
  • Recordkeeping. Firms should be aware of their recordkeeping obligations when assessing any recordkeeping products or services offered by their cloud providers.

Source: FINRA

It's been a month since we had our Women In Finance Awards in New York City at the Plaza! Take a look back tab some moments, and nominate for our upcoming awards in Mexico City and Singapore here: https://www.marketsmedia.com/category/events/

4

Citadel Securities told the SEC that trading tokenized equities should remain under existing market rules, a position that drew responses from various crypto industry groups. @ShannyBasar for @MarketsMedia:

SEC Commissioner Mark Uyeda argued that private assets belong in retirement plans, saying diversified alts can improve risk-adjusted returns and that the answer to optimal exposure “is not zero.” @ShannyBasar reporting for @MarketsMedia:

COO of the Year Award winner! 🏆
Discover how Jennifer Kaiser of Marex earned the 2025 Women in Finance COO of the Year recognition.

Load More

Related articles

  1. The ETF platform was introduced in 2023 with six strategies.

  2. Cybersecurity is Top of Mind for FinServ

    The statement is an interim step while the SEC continues to consider the issues.

  3. Expanding membership is an OCC priority for capital efficiency, risk reduction and operational simplicity.

  4. The technology harnesses data to provide faster, more customizable insights and distribution.

  5. The fund will focus on the small and mid-market.