Financial Services Authority building
The FSA aims to "pierce the corporate veil" at retail banks
R E L A T E D   C O N T E N T
ADVERTISEMENT

FSA threatens executives with fines

Senior management to be held accountable for security lapses at banks

Tom Young, Computing 09 Oct 2008
ADVERTISEMENT

Board-level executives found responsible for information security lapses in retail banks are to be personally fined as part of a new drive to “pierce the corporate veil”.

The Financial Services Authority (FSA) is concerned that corporate fines are not incentive enough for banks to take adequate measures to protect customers’ information and wants to drive best practice by ensuring executives personally oversee security programmes.

The move is a key part of ensuring security compliance, according to Bill Sillett, manager of the retail department at the FSA.

“Protecting personal data is essential to reduce the level of financial crime,” he said. “This is a big shift in how we operate. There will be more fines for senior individuals in the future.”

The FSA regulates banks’ compliance with the Data Protection Act and the Financial Services and Markets Act, both of which contain legal obligations for banks to safeguard customers’ financial information.

The regulator is concerned that banks place too much emphasis on IT security as part of a cost-benefit risk analysis.

“With some large firms even if we fine them £20m it won’t have much of an impact ­ we hope targeting senior management will help solve that problem,” said Sillett.

The FSA has not yet levied any major fines on individuals, but will commit more resources to doing so in such cases in the future.

Sillett said the level of senior management to be targeted will depend on the case, but the FSA wants to avoid executives palming off overall security responsibilities onto the IT department.

Chief executives, compliance officers and board-level IT directors could all be held responsible.

The obligation of senior management for data protection issues is not a completely novel idea, according to Stewart Room, barrister with law firm Field Fisher Waterhouse.

“Directors and senior management are liable if a firm doesn’t comply with an enforcement notice from the Information Commissioner’s Office,” he said. “Regulators need to make sure they inflict real pain to ensure compliance.”

Tags: Security, Banking, Fsa, Management

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
EXCEPTIONAL .NET (ASP / VB / C#) DEVELOPER – SURREY HEDGE FUND My client is a CASH RICH leading Microsoft Technology focused Hedge Fund currently experiencing unrivalled success – they need to bring on fresh ... more >
| JAM Recruitment
Position: Software Developer – Modelling / Simulations Salary: £27-37,000 Location: Luton, Bedford, Milton Keynes Apply to: a.ross@jamrecruitment.co.uk This is an excellent chance to join one of the UK’s leading Defence businesses operating at the forefront ... more >
| JAM Recruitment
Position: Software Engineer – C/C++/GUI/UML Salary: £30-40,000 Location: Leicester Apply to: a.ross@jamjobs.co.uk This is a fabulous opportunity to join a globally recognised organisation working as part of a team taking innovative and cutting edge solutions ... more >
| JAM Recruitment
Position: Embedded Software / Systems Engineer Salary: £25-40,000 Location: Barrow, Cumbria, Carlisle, Lake District Apply to: a.ross@jamrecruitment.co.uk (inc salary expectations, availability and notice period) This is an exciting opportunity to join one of the UKs ... more >
More job opportunities