News
Print Article

JFSC 2025 Outsourcing Examination Feedback – Key findings and what firms need to do

30/07/2026

The Jersey Financial Services Commission (JFSC) has published feedback from its 2025 thematic examination programme on outsourcing. The examination assessed how firms complied with

  • Legal and regulatory requirements under the applicable Codes of Practice and
  • The seven core principles of the Outsourcing Policy (OSP).

Speed read   

  • The JFSC's 2025 thematic examination of outsourcing arrangements found a generally acceptable level of compliance across the eight firms reviewed. Still, findings were identified in five of the eight examinations, with all but one of those minor.
  • The issues that did arise cluster around five areas: failure to identify and notify in-scope outsourcing activity, inadequate or untested contingency plans, group policies not tailored to Jersey-specific requirements, gaps in evidencing SAR-reporting awareness among service providers and missed notifications of material changes to outsourcing arrangements.
  • None of these point to a systemic problem — but each is a control gap the JFSC has now flagged publicly, which raises the bar for what it will expect firms to demonstrate next time.

What firms should do now?

  • Map your outsourcing population.
    • Confirm every arrangement in scope of the Outsourcing Policy has been identified and, where required, notified — cloud and cyber security services are an area the JFSC specifically called out as commonly missed.
  • Stress-test contingency plans.
    • Don't just hold a plan — evidence that it's been reviewed and, where appropriate, tested, and that group-level plans have been tailored to the Jersey business rather than inherited wholesale.
  • Localise group policies and procedures.
    • Where outsourcing policies sit at group level, confirm they've been adapted to meet OSP-specific requirements, not just adopted as-is.
  • Check SAR-reporting lines with service providers.
    • Confirm — and be able to evidence, e.g. via training records or SLA clauses — that outsourced providers know how and when to escalate suspicion of ML/TF/PF to your MLRO or deputy MLRO.
  • Review your notification triggers.
    • Make sure termination or other material changes to outsourcing arrangements are captured by your procedures and notified to the JFSC as they happen, not retrospectively.

Firms should treat this as a self-assessment prompt rather than a compliance formality:

  • The JFSC has said explicitly that in future engagements it may ask firms to demonstrate the steps taken in response to this feedback, and that it may revisit the theme in future supervisory work.

Long read  

The Jersey Financial Services Commission (JFSC) has published feedback from its 2025 thematic examination programme on outsourcing. The examination assessed how firms complied with legal and regulatory requirements under the applicable Codes of Practice and the seven core principles of the Outsourcing Policy (OSP).

The feedback paper provides:

  • An overview of the examination and key findings
  • Statistics on the findings
  • An overview of outsourcing obligations
  • A table with detailed findings and examples of best practice
  • Key questions to help firms assess their own systems and controls

Examination approach

  • The JFSC conducted desk-based reviews of policies, procedures and supporting documentation, followed by on-site examinations involving interviews with key persons, board members and staff.
  • All eight firms examined received direct feedback. Where deficiencies were identified, firms were required to submit formal remediation plans.

Overall finding

  • The examinations found a generally acceptable level of compliance.
  • Findings were identified in five of the eight examinations, and all but one of those findings were minor.

Key findings (summary of the main categories where issues were identified)

  • Identification of activities caught by the outsourcing policy — instances of activities caught by the OSP but not notified to the JFSC.
  • Contingency plans — instances where contingency plans were inadequate or lacked evidence of periodic testing.
  • Policies and procedures — instances where reliance was placed on group outsourcing procedures with no tailoring to the specific requirements of the OSP.
  • Awareness of suspicious activity reporting (SAR) obligations — instances where firms could not evidence that SAR reporting obligations had been communicated to outsourced service providers.
  • Material changes to outsourcing notification — instances where a material change to an outsourcing arrangement (including termination) was not notified to the JFSC.

What the feedback paper also covers

  • It restates the seven core principles of the OSP (responsibility/accountability, fit and proper service providers, outsourcing agreements, ongoing capacity and resources, contingency plans, notification/no-objection requirements, and preservation of the JFSC's regulatory powers).
  • It distinguishes obligations for registered persons (under sector Codes) and supervised persons (particularly in respect of AML/CFT/CPF-related outsourcing). It includes examples of practices observed that worked well (e.g. assessment checklists, centralised registers of outsourced arrangements, tailored contingency plans, periodic testing, and clear contractual SAR reporting clauses).

Key questions the JFSC encourages firms to ask themselves

  1. Have you identified all outsourced activity within the scope of the outsourcing policy?
  2. Can you demonstrate that you remain responsible and accountable for outsourced activity (including sub-outsourcing) and have appropriate oversight arrangements?
  3. Have you satisfied yourself that appropriate due diligence has been conducted and maintained, and that service providers continue to be fit and proper, adequately resourced, and compliant with applicable regulatory and AML/CFT/CPF requirements?
  4. Can you evidence that outsourcing arrangements are supported by appropriate contractual agreements documented before services commence, and that notification and no-objection requirements have been met where applicable?
  5. Have you established proportionate contingency and exit arrangements, and tested them where appropriate?

Next steps for firms

The JFSC encourages all supervised persons to:

  • Review the full feedback paper
  • Assess their own systems and controls against the findings and good-practice examples
  • Identify and implement any necessary enhancements (proportionate to the nature, scale, complexity and risks of their outsourced activities)
  • Ensure any remediation is sustainable and considers broader implications

In future engagements, the JFSC may ask firms to demonstrate the steps taken in response to this (and other) feedback. The theme may be revisited in future supervisory work.

Read the official material.

(Source material is the JFSC's own published feedback. Firms should read the full paper for the detailed findings table, statistics, and complete examples of good practice.)

JERSEY JFSC SAR/STR

The Team

Meet the team of industry experts behind Comsure

Find out more

Latest News

Keep up to date with the very latest news from Comsure

Find out more

Gallery

View our latest imagery from our news and work

Find out more

Contact

Think we can help you and your business? Chat to us today

Get In Touch

News Disclaimer

As well as owning and publishing Comsure's copyrighted works, Comsure wishes to use the copyright-protected works of others. To do so, Comsure is applying for exemptions in the UK copyright law. There are certain very specific situations where Comsure is permitted to do so without seeking permission from the owner. These exemptions are in the copyright sections of the Copyright, Designs and Patents Act 1988 (as amended)[www.gov.UK/government/publications/copyright-acts-and-related-laws]. Many situations allow for Comsure to apply for exemptions. These include 1] Non-commercial research and private study, 2] Criticism, review and reporting of current events, 3] the copying of works in any medium as long as the use is to illustrate a point. 4] no posting is for commercial purposes [payment]. (for a full list of exemptions, please read here www.gov.uk/guidance/exceptions-to-copyright]. Concerning the exceptions, Comsure will acknowledge the work of the source author by providing a link to the source material. Comsure claims no ownership of non-Comsure content. The non-Comsure articles posted on the Comsure website are deemed important, relevant, and newsworthy to a Comsure audience (e.g. regulated financial services and professional firms [DNFSBs]). Comsure does not wish to take any credit for the publication, and the publication can be read in full in its original form if you click the articles link that always accompanies the news item. Also, Comsure does not seek any payment for highlighting these important articles. If you want any article removed, Comsure will automatically do so on a reasonable request if you email info@comsuregroup.com.