KNF

Rules for providing information and supervision under outsourcing contracts

Pursuant to Art. 6a-6d and art. 111b of the Act of August 29, 1997 - Banking Law (Journal of Laws of 2002, No. 72, item 665, as amended), BackOffice Outsourcing Sp. z o.o. undertakes, under agreements concluded with banks and financial institutions, to ensure full transparency and cooperation in order to enable effective supervision over the implementation of the entrusted activities.

In particular, the Company undertakes to:

 

  1. Providing banks, financial institutions, the Bank's statutory auditors and the Polish Financial Supervision Authority (KNF) with the following documents and information:
  • current registration and formal and legal documents, including extracts from the National Court Register, administrative decisions, licenses, permits, certificates and other documents confirming the legality and status of BackOffice Outsourcing business activity, as well as compliance with the scope of outsourcing services performed;
  • financial statements for contractual and pre-contractual periods, together with auditor's opinions and reports, if a statutory or voluntary audit has been carried out, and management reports or quarterly balance sheets, if available;
  • business continuity plans (BCPs) and procedures to ensure the uninterrupted provision of outsourcing services in the event of extraordinary events, crises or technical failures, together with emergency scenario test reports and BCP periodic review documentation;
  • information security descriptions and procedures– including implemented rules consistent with ISO 27001, ISO 22301 and ISO 9001 standards – relating to incident management, access control, personal data protection and physical and logical security policy;
  • audit results– both external (e.g. carried out by certification bodies or the contracting authority) and internal, covering the functioning of control systems, compliance with regulatory requirements and the effectiveness of the implemented supervision mechanisms;
  • operational and executive documentation related to the implementation of the subject of the contract, including descriptions of operational processes, instructions, schedules, activity registers and internal procedures regarding outsourcing;

 

  1. Allowing an audit to be carried out by the Bank, a financial institution, the Bank's statutory auditor or the Polish Financial Supervision Authority, in the scope of:
  • on-site inspections in locations where the subject of the outsourcing agreement is performed, including access to operating rooms, equipment, paper and electronic documentation and IT systems;
  • information processing security verification, both technically (including network security, access control and backups) and organisationally (including roles and permissions, separation of duties and compliance with the security policy);
  • personnel interviews who perform the activities covered by the agreement, including explanations of how services are delivered, how unusual situations are handled, how control mechanisms operate and how procedures are followed.

 

  1. Immediately inform Banks, financial institutions or the Polish Financial Supervision Authority about:
  • any facts or risks, which may or may potentially have a significant negative impact on the implementation of the subject of the contract - including in particular:
    • IT system failures, service interruptions, data breach incidents,
    • detection of violations of legal provisions, internal regulations or contractual conditions,
    • cases of loss of data integrity, loss of service availability, exposure to external attack,
    • insolvency, restructuring or financial situations affecting the ability to continue to provide services;
  • actions of subcontractors or third parties, that affect the services covered by the agreement, including changes in legal status, discontinuation of a subcontractor's services, transfers of data outside the EEA or material changes in the way services are provided.

 

  1. Additional obligations regarding supervision and transparency of cooperation with Banks and the Polish Financial Supervision Authority:
  • providing a dedicated point of contact within the Company's organisational structure to handle supervisory and inspection requests (Compliance Officer, Internal Control Department, Data Protection Officer),
  • maintaining archival documentation regarding the implementation of contracts for a period of at least 5 years from their termination, available at the request of the supervisory authority or bank,
  • taking corrective and corrective actions based on post-audit recommendations and submitting implementation reports to the appropriate supervisory bodies.

 

BackOffice Outsourcing Sp. z o.o. treats information obligations and cooperation with the supervisory authorities as the foundation of trust in relations with the financial sector. Transparency, timeliness and completeness of the information provided are the basis of responsible outsourcing that complies with the Banking Law and the KNF's regulatory good practices.

 

Customer service

Let’s talk about your business correspondence

BackOffice Outsourcing

Verify our company

Check BackOffice Outsourcing’s current credentials on the official services.

BackOffice Outsourcing

Quality, security and business continuity

We work in line with recognised ISO standards that structure our processes and information-security practices.

9001:2015Quality management
22301:2020Business continuity
27001:2023Information security
27002:2023Information security controls