Information Governance and Compliance

People

An offer of employment is extended contingent upon successful review and completion of employment, education verification, and criminal background check. After the offer is accepted, pre-employment screenings are initiated through a third-party background vendor. Contractors are subject to the screening provisions in their contracts.

All new employees or contractors with Finastra’s network access must complete mandatory Compliance training which includes Code of Conduct, Information Security, physical security, privacy and risk within the first 60 days of employment. Annually, all employees and contractors must complete Compliance training. To complete the training you must pass the test. Failure to complete training results in management escalation and remediation.

Additionally, developers and those with privileged access must take role-based training to assure that they understand their responsibilities and the company expectations. Training for developers also includes Secure coding practices.

Risk Assesments

Any developer that wishes to create a FusionCreator application available on FusionFabric.cloud has to undergo a risk and compliance assessment where standard checks in relation to compliance with sanctions, anti-bribery and anti-corruption laws are conducted. Additionally, we request their insurance, financial, policies and any other documentation.

Following the approval of the developer, each application must go through a thorough a security review to ensure that the client data is properly protected and that the appropriate Secure Software Development standards have been met.

Data Management Program

Finastra’s Enterprise Data Management & Governance team is responsible for addressing enterprise risk concerns, maintaining Finastra’s regulatory compliance and supporting the corporate application rationalization program. The team achieves the aforementioned responsibilities by focusing on maintaining data quality, developing overall data architecture strategies, implementing data management best practices, data provisioning, and data integration to ensure data is well-managed as an enterprise asset.

The Program has been developed and is maintained in collaboration with IT Architecture and Practices, Global Risk, Privacy, IT Compliance, InfoSec, Product and Data Security (PDS), Legal, and other relevant Finastra teams. Data Management & Governance team and stakeholders identify where Finastra’s Program stands today; what our requirements are for delivering an Enterprise Data Management and Governance Program; what the future state looks like and how we will get there. Finastra Enterprise Data Management & Governance team’s Data Management & Governance is enterprise in scope, encompassing Finastra products (including FusionFabric.cloud), managed services and corporate applications.