Operational Resilience Framework for Futures Commission Merchants, Swap Dealers, and Major Swap Participants
New collection (Request for a new OMB Control Number)
No
Regular
Comment filed on proposed rule
03/12/2024
01/24/2024
OMB files this comment in accordance with 5 CFR 1320.11(c). This OMB action is not an approval to conduct or sponsor an information collection under the Paperwork Reduction Act of 1995. This action has no effect on any current approvals. If OMB has assigned this ICR a new OMB Control Number, the OMB Control Number will not appear in the active inventory. For future submissions of this information collection, reference the OMB Control Number provided. Resubmit when proposed rule is finalized.
table that charts list comparision
Inventory as of this Action
Requested
Previously Approved
36 Months From Approved
0
0
0
0
0
0
0
0
0
Proposed regulations 1.13 and 23.603 require FCMs, SDs, and MSPs (collectively, covered entities) to establish, document, implement, and maintain an Operational Resilience Framework (ORF), which shall, at a minimum, include an information and technology security program, a third-party relationship program, and a business continuity and disaster recovery (BCDR) plan. All such programs and plan must be supported by written policies and procedures. In addition, the proposed regulations impose the following reporting, recordkeeping, and disclosure obligations: (1) on an annual basis, written approval of each component program or plan of the ORF and of risk appetite and risk tolerance limits, or in the case of covered entities relying on a consolidated program or plan, written attestation; (2) on an annual basis, documenting review and testing of the ORF; (3) as applicable, notifying the Commission of certain âincidents,â as defined in the proposed rule; (4) as applicable, notifying the Commission upon activation of the BCDR plan; (5) as applicable, notifying customers or counterparties of certain âincidents,â as defined in the proposed rule; and (6) providing emergency contact information to the Commission in connection with the information and technology security program and the BCDR plan.
It is necessary to ensure that SDs and MSPs establish, document, implement, and maintain an ORF that is reasonably designed to monitor and manage operational risks related to information and technology security, third-party service providers, and emergencies or other significant disruptions to the continuity of normal business activities as an SD or MSP. The collection of information is also necessary to accomplish the purposes of the Act under CEA 8a(5), specifically those related to FCMsâ various statutory requirements required under the Act.
The Commission will use the information collected to exercise its regulatory oversight obligations to address systemic risk and protect customer assets. Specifically, the Commission will use the information collected to evaluate and oversee covered entitiesâ implementation of the ORF required under the proposed rule. The information collected will also inform the Commission of whether it should take any action regarding lack of compliance with the proposed rule. Covered entitiesâ counterparties and customers will receive information collected that may be used to assess the potential impact of an incident on its information, assets, or positions and to take any necessary action. The information collected is intended to protect counterparties and customers, as well as ensure market integrity and soundness.
This is a new collection of information associated with proposed regulations establishing an operational resilience framework for FCMs, SDs, and MSPs. As described in Attachment A, the Commission estimates that, if adopted, the information collections associated with the proposed regulations would entail an estimated 84,240 burden hours along with $8,424,000 in associated labor costs.
On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control number;
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.