#PFS
02.12.21
When a company outsources the management of its IT environment to an external service provider, it does not relinquish all of its responsibilities.
This is particularly true for Professionals of the Financial Sector (PSFs), which remain responsible for protecting their data, ensuring business continuity, and managing the IT risks associated with outsourcing.
Investment firms, advisory companies, Family Offices, and domiciliation agents must therefore pay close attention to the selection of their IT service provider, as well as to the scope of services entrusted to them.
Which systems and tools may be managed by an external provider? What access rights will they have to company data? What monitoring mechanisms, performance indicators, and guarantees will be associated with the service? What happens at the end of the contract?
The purpose of a statement of requirements is to answer these questions. More than a simple list of technical needs, this document should translate the PSF’s operational and regulatory constraints into concrete requirements.
Serge Sauvage, Director of Services Dedicated to PSFs at Rcube Professional Services, our subsidiary dedicated to regulated professions, shares his advice and insights in this new article.
Defined by the Law of April 5, 1993 relating to the financial sector, the status of Professional of the Financial Sector (PSF) is supervised by the Luxembourg regulator.
On a daily basis, these organizations process personal and sensitive data relating to financial transactions, investments, and their clients’ identities.
In this context, a data breach, the compromise of data hosted by a PSF, or an information system outage can have significant consequences for both their business operations and their clients.
To address these risks, Luxembourg legislators have imposed strict requirements on PSFs regarding security, IT risk management, and business continuity. Since January 2025, the European DORA (Digital Operational Resilience Act) regulation has further strengthened this framework, particularly with regard to incident prevention, incident reporting, and oversight of technology service providers within the financial sector.
In Luxembourg, the Support PSF status designates service providers that are approved and supervised by the Luxembourg regulator, particularly for infrastructure and network management.
As Serge Sauvage explains: “While Support PSF approval is not mandatory for all professionals in the financial sector, it provides additional guarantees when outsourcing IT management. This is the case for Rcube Professional Services. Our organization, procedures, and risk management processes are audited to ensure compliance with the specific requirements of the financial sector.”
The rigor of the regulatory framework and the importance of data confidentiality make the preparation of a statement of requirements particularly challenging for PSFs.
This is why Rcube supports regulated professions in translating these requirements into operational criteria and in designing their IT outsourcing projects.
Rather than simply listing expected services, the statement of requirements should explain to the future provider how the company operates and uses its information systems.
The methodology recommended by our expert, Serge Sauvage, consists of three steps : identify business needs and usage patterns, analyze the risks to which the business is exposed and define the required technical solutions and expected service levels.
To provide a service that genuinely meets the PSF’s needs, the provider must understand its organization and operating model.
As Serge Sauvage explains : “A statement of requirements is used to describe how the company operates and the nature of its business. This has a significant impact on IT choices and internal organization.”
For example, companies operating in multiple countries or structured through subsidiaries may have their management teams and internal IT departments spread across different entities. Parts of the global information system may already be managed by other service providers.
This type of information enables a Support PSF such as Rcube to understand its role within the PSF’s organization and propose support that is both appropriate and compliant with its constraints.
In the event of a major IT incident, not all service interruptions will have the same impact on business operations. Losing access to contracts, client communication histories, or operational monitoring tools can quickly disrupt, or even halt, a PSF’s services.
Each business activity should therefore be reviewed by asking a simple question : “What can I do without, and for how long?”
This risk management approach makes it possible to prioritize actions and clearly define the scope entrusted to the IT provider.
Once this hierarchy of risks and needs has been established, the PSF can more easily identify the data, applications, and infrastructures to outsource, as well as the expected service levels.
As Serge Sauvage notes : “Identifying a need is one thing. Defining the expected outcome and how it will be measured is another.”
These commitments are formalized through Service Level Agreements (SLAs), which specify expected results, measurement indicators, and monitoring procedures.
Need an IT service provider ?
Once the requirements have been defined, the statement of requirements can be drafted to structure the future relationship between the PSF, its IT provider, and any other stakeholders involved in managing the information system.
A PSF may entrust the entire management of its information system to a primary provider or divide responsibilities among several specialists.
This approach reflects both organizational choices and risk management considerations. It enables the company to leverage complementary expertise or assign oversight responsibilities to another provider.
As Serge Sauvage explains : “We often see service packages divided into different work streams within statements of requirements. They are not necessarily intended to be awarded to a single provider. Sometimes the objective is to identify different areas of expertise.”
Each provider operates within its own area of expertise. “At Rcube, for example, we manage infrastructure, not business applications. The distinction is important,” adds Serge Sauvage.
Every service entrusted to the provider must be associated with an expected outcome and a method of verification. The statement of requirements therefore specifies availability targets, response times, recovery conditions, and request handling procedures.
As Serge Sauvage emphasizes: “Defining a requirement is only part of the job. You must also define the expected result and how it will be measured.” When it comes to business continuity, two indicators play a central role: RTO (Recovery Time Objective) and RPO (Recovery Point Objective).
Serge Sauvage summarizes their purpose: “The RTO answers the question: how long can I operate without a service? The RPO addresses another question: how much data can I afford to lose without jeopardizing the restart of my operations? It is expressed in hours and represents the volume of unrecoverable data. These are two essential criteria when selecting an IT maintenance service.”
These commitments are formalized within Service Level Agreements (SLAs).
Because PSFs are subject to strict regulatory obligations, they must maintain visibility and traceability over their provider’s activities.
As Serge Sauvage explains: “There are two aspects. Reporting focuses on expected results, while governance ensures monitoring of service quality and compliance obligations in the broader sense.”
The statement of requirements should therefore define the KPIs (Key Performance Indicators) that will be used to assess service quality through objective data, identify compliance gaps, and provide sufficient traceability in the event of an audit or regulatory review.
According to Serge Sauvage: “Service providers should naturally give their clients the means to verify that the work is being carried out in accordance with the statement of requirements.”
The PSF remains responsible for its data and information systems, even when management is outsourced. As Serge Sauvage reminds us : “Any organization operating within the financial sector remains responsible, at all times and in all circumstances, for compliance with the regulations that apply to it. Executive management retains responsibility. Final accountability cannot be transferred to a third party.”
This obligation requires the entire subcontracting chain to be formally documented. As an experienced Support PSF, Rcube assists its clients in this process. “We manage subcontractors, which means we are responsible for the entire chain. In some ways, we do much of the groundwork for our clients. However, they still retain the obligation to monitor us.”
This transparency also applies to data management. The statement of requirements must specify:
As Serge Sauvage points out : “Where is my data located? Data sovereignty and the ability to demonstrate that data does not leave a specific territory are of paramount importance for a PSF.”
Reversibility is essential to allow a PSF to change providers without disrupting business operations. As Serge Sauvage notes: “Contract termination is often overlooked. Regardless of the provider’s mandate, a PSF must be guaranteed the ability to end the service whenever it wishes, without risking lock-in situations or data loss.”
This requires ensuring that data can be transferred and new services deployed without compromising business continuity or disrupting day-to-day operations. Rcube recommends carefully considering the technical, financial, and scheduling aspects of contract termination from the outset.
Need advice from PSF? Contact us !
PSFs operate within an increasingly demanding regulatory environment, further intensified by the rise of cyberattacks. In this context, choosing an IT provider goes far beyond technical considerations.
As Serge Sauvage concludes: “Clients are not just looking for a service provider or storage space in a data center. They are looking for people who can support them on a daily basis.”
A subsidiary of the Rcarré Group and a Support PSF since 2014, Rcube Professional Services combines technical expertise with an in-depth understanding of the security, reporting, and governance requirements of the financial sector.
Are you preparing a tender process or an IT outsourcing project for a PSF? Contact us today !