Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

SFC Rules for Outsourced Electronic Storage of Regulatory Records

Updated 6 min read
Key takeaway

Outsourcing electronic storage does not transfer a licensed corporation’s regulatory responsibility.

More key points
  • If regulatory records are kept exclusively with an external electronic data storage provider, the SFC framework requires specific access, availability, control, and approval arrangements so the firm and regulator can retrieve records when needed.
On this page16 sections
  1. Exclusive external storage has added conditions
  2. Due diligence and ongoing oversight
  3. Exam distinction: provider service versus regulated duty
  4. Practical control checklist
  5. Exclusive storage triggers a specific approval framework
  6. Know what counts as an external provider
  7. Approval and senior accountability
  8. Access, production and data integrity
  9. Due diligence and ongoing vendor oversight
  10. Cybersecurity and business continuity
  11. Exclusive and non-exclusive storage
  12. Exit and migration
  13. Exam checklist
  14. Identify what is being stored and who controls it
  15. Meet approval and access conditions before migration
  16. Key takeaway

A licensed corporation may use a cloud or other external electronic data storage provider, but the regulator still expects the firm to control and produce its records. Outsourcing changes where records sit; it does not outsource the firm’s accountability for complete, retrievable, and secure regulatory records.

Exclusive external storage has added conditions

The SFC’s guidance distinguishes records stored at the corporation’s premises with a duplicate set from records kept exclusively with an external provider. Exclusive storage triggers specific requirements, including seeking SFC approval under the applicable arrangement and ensuring the records remain readily accessible to the corporation and the SFC. The firm must be able to retrieve records promptly for supervision, investigation, or inspection, including when provider systems or connectivity are disrupted.

Due diligence and ongoing oversight

Before engaging a provider, a firm should assess data location, access rights, security, resilience, subcontracting, incident response, business continuity, and the provider’s ability to support regulatory access. Contracts should preserve the firm’s and regulator’s rights to access and obtain records. The firm should test retrieval, monitor service performance, and maintain exit and migration plans rather than relying on a provider’s assurances alone.

Exam distinction: provider service versus regulated duty

The storage company is not a substitute for the licensed corporation’s recordkeeping control. A firm cannot excuse a missing file by saying it is the cloud provider’s responsibility. The relevant control question is whether the firm retains effective access, integrity, confidentiality, retention, and regulatory cooperation throughout the outsourcing relationship.

Practical control checklist

  • Determine whether the arrangement is exclusive external storage or uses a duplicate on-premises set.
  • Obtain any approval required for the chosen arrangement before relying on it.
  • Contract for regulator access, export, continuity, incident notice, and subcontractor transparency.
  • Test retrieval and document retention and deletion controls.
  • Maintain a workable exit plan if the provider fails or the relationship ends.

Exclusive storage triggers a specific approval framework

An SFC-licensed corporation that keeps regulatory records exclusively with an external electronic data storage provider, without a duplicate set at the corporation’s premises, must follow the SFC’s specific approval and undertaking requirements. The framework is intended to ensure the records remain authentic, complete, reliable and promptly accessible to the SFC. “Cloud” is not an exemption from recordkeeping rules.

Know what counts as an external provider

An EDSP can include public or private cloud storage, data-centre servers, virtual storage and technology services where records generated in using the service are stored by the provider or a further storage provider. The legal analysis turns on where the regulatory records are held and who controls them, not the marketing label of the IT service. Map all primary and backup storage locations.

Approval and senior accountability

The SFC framework requires advance approval for exclusive external storage arrangements and assigns responsibility to a Manager-In-Charge with authority and general knowledge of how regulatory records are stored. The MIC should be able to secure the SFC’s effective access on demand and without undue delay. Assigning the role to an employee who cannot direct the group, provider or system will not achieve the purpose.

Access, production and data integrity

The firm should ensure it can retrieve records in an intelligible format, search them by client, transaction and date, and produce them promptly in proceedings or inspections. Protect authenticity and integrity through access controls, versioning, encryption, audit logs, retention controls and tested restoration. Maintain data in a form that can establish who created or changed a record and when.

Due diligence and ongoing vendor oversight

Assess the provider’s security, availability, resilience, subcontractors, data location, incident notification, continuity and exit capabilities. Contracts should permit regulatory access, audit, export and cooperation with the SFC. Monitor service performance and material changes; a provider’s certification does not prove that the firm’s own record retrieval and access controls work.

Cybersecurity and business continuity

Maintain backups, recovery procedures, key management and access arrangements that remain effective during a provider outage or cyber incident. If records are encrypted, ensure the firm controls the keys and can provide access to the SFC when lawfully required. Test restoration and regulator-request scenarios, including provider failure and staff turnover.

Exclusive and non-exclusive storage

The approval requirement described by the SFC is specific to records kept exclusively with an EDSP; firms may maintain duplicate copies at their own premises. However, using an EDSP in either arrangement still requires management of cybersecurity and operational risk, and outsourcing does not transfer the firm’s recordkeeping responsibilities. Check the current circular and FAQs for the exact terms.

Exit and migration

Before changing providers, confirm records can be exported with metadata and audit trails, validate samples after migration, and retain access to the old system until completeness is confirmed. The firm should prevent deletion before statutory retention expires and ensure that a new arrangement has the required approvals before it becomes the exclusive repository.

Exam checklist

Determine where regulatory records are stored and whether the arrangement is exclusive. Apply SFC approval and MIC requirements if applicable; ensure timely regulatory access, integrity, retrieval, cybersecurity, continuity and vendor oversight. State clearly that outsourcing records storage does not outsource the licensed corporation’s regulatory responsibility.

Identify what is being stored and who controls it

Start with a record inventory: which books and records are required by Hong Kong law or SFC rules, where each copy is held, which vendor and subcontractors can access it, and who can retrieve or delete it. Cloud labels such as “backup,” “archive” or “disaster recovery” do not determine whether the arrangement is regulatory-record storage. Consider the actual data, system architecture and operational access.

The licensed corporation should document the data flow, encryption and key management, user access, retention, backup, deletion, incident reporting and exit arrangements. It should know whether records are replicated across jurisdictions and be able to identify the applicable regulatory and privacy constraints.

Meet approval and access conditions before migration

Where a firm uses an external electronic data storage provider to exclusively keep regulatory records, the SFC’s framework requires prior approval and specified undertakings and controls. The firm should not migrate first and seek approval after the operational dependency is established. It should provide the regulator with the required provider and data details and ensure the relevant responsible individuals understand their obligations.

The system must allow the corporation and SFC to access records promptly and effectively, including during a vendor outage, dispute or termination. A contractual promise is insufficient if credentials, encryption keys, export tools or staff knowledge are unavailable in practice. Test retrieval of representative records before the service goes live.

Key takeaway

A cloud provider may hold records, but the licensed corporation remains accountable. Pay special attention to the SFC approval and access conditions for exclusive external storage.

Common questions

Does using a cloud provider shift the recordkeeping obligation away from the licensed corporation?

No. The firm remains responsible for regulatory compliance and must be able to access and produce the records.

Why does exclusive external storage receive special attention?

Where no duplicate records are kept at the firm’s premises, the SFC requires a framework that preserves regulator access and retrieval, including approval where applicable.