View a markdown version of this page

FSIOPS3: Have you assessed your specific workload against regulatory needs? - Financial Services Industry Lens

FSIOPS3: Have you assessed your specific workload against regulatory needs?

Financial services institutions must be aware of all applicable regulatory and compliance obligations for their use of cloud services, and they should take appropriate steps to meet those obligations.

FSIOPS03-BP01 Implement a process for the review of applicable compliance and regulatory requirements for your workload

Financial services institutions must be aware of all applicable regulatory and compliance obligations for their use of the cloud, and they should take appropriate steps to meet those obligations. As part of your strategy, review your migration plan and control frameworks with the relevant internal stakeholders responsible for compliance to identify any compliance requirements, including legal and regulatory requirements that apply to your use of the cloud. Note that designing a workload to meet specific technical requirements may only be one aspect of compliance, so it's important to conduct a comprehensive regulatory and compliance review. This process must include both initial design and planning, as well as pre-production readiness activities.

Prescriptive guidance

Use the AWS Compliance Center to learn about key cloud-related regulatory requirements that impact your use of the cloud, and the regulations that apply within your geography. Design a process to monitor evolving changes to compliance and regulatory obligations. Use AWS Config Conformance Packs and AWS Audit Manager to continually evaluate your compliance to applicable regulatory frameworks. If appropriate, review the AWS Sub-Processors list and sign up to be notified of changes. Use AWS Artifact to gather compliance reports that apply to your workload and geography.