Mapping
FFIEC Risk Management for Outsourcing Technology Services
Google Cloud Platform Mapping
This document is designed to help financial institutions (“ institutions”) within the Federal Financial Institutions Examination Council’s (“ FFIEC”) mandate to consider the Outsourcing Technology Services Booklet (the “ FFIEC Outsourcing Booklet") in the context of Google Cloud Platform (“ GCP”) and the Google Cloud Financial Services Contract.
We focus on the Due Diligence and Contract Issues sections of the FFIEC Outsourcing Booklet. For each paragraph of these sections, we provide commentary to help you understand how you can address the FFIEC Outsourcing Booklet using the Google Cloud services and the Google Cloud Financial Services Contract.
- Existence and corporate history;
- Qualifications, backgrounds, and reputations of company principals, including criminal background checks where appropriate;
Company principals
Information about Google Cloud’s leadership team is available on our Media Resources page.
Background checks
Google conducts background checks on our employees where legally permissible to provide a safe environment for our customers and employees.
- Other companies using similar services from the provider that may be contacted for reference;
- Financial status, including reviews of audited financial statements;
- Strategy and reputation;
Information about Google Cloud’s strategies is available on Alphabet’s Investor Relations page.
Reputation
Google Cloud has been named as a leader in several reports by third party industry analysts. You can read these on our Analyst Reports page.
- Service delivery capability, status, and effectiveness;
- Technology and systems architecture;
Information about Google Cloud’s technology and systems architecture is available on our Choosing Google Cloud page.
- Internal controls environment, security history, and audit coverage;
Google recognizes that institutions need to review our internal controls as part of their risk assessment. To assist, Google undergoes several independent third-party audits on at least an annual basis to provide independent verification of our operations and internal controls. Google commits to comply with the following key international standards during the term of our contract with you:
- Legal and regulatory compliance including any complaints, litigation, or regulatory actions;
- Reliance on and success in dealing with third party service providers;
- Insurance coverage; and
- Ability to meet disaster recovery and business continuity requirements.
After selecting a service provider, management should negotiate a contract that meets their requirements. The RFP and the service provider's response can be used as inputs to this process. The contract is the legally binding document that defines all aspects of the servicing relationship. A written contract should be present in all servicing relationships. This includes instances where the service provider is affiliated with the institution. When contracting with an affiliate, the institution should ensure the costs and quality of services provided are commensurate with those of a nonaffiliated provider. The contract is the single most important control in the outsourcing process. Because of the importance of the contract, management should:
- Verify the accuracy of the description of the outsourcing relationship in the contract;
- Ensure the contract is clearly written and contains sufficient detail to define the rights and responsibilities of each party comprehensively; and
- Engage legal counsel early in the process to help prepare and review the proposed contract.
- Descriptions of required activities, timeframes for their implementation, and assignment of responsibilities. Implementation provisions should take into consideration other existing systems or interrelated systems to be developed by different service providers (e.g., an Internet banking system being integrated with existing core applications or systems customization);
Activities
The GCP services are described on our services summary page.
Integration
There are a number of ways to integrate our services with your systems.
- Cloud console allows you to find and check the health of all your Google Cloud resources in one place, including virtual machines, network settings, and data storage.
- Cloud APIs allow you to access Google Cloud products from your code and automate your workflows by using your preferred programming language.
- Obligations of, and services to be performed by, the service provider including software support and maintenance, training of employees, or customer service;
Google will provide the Services described on our services summary page in accordance with the Google Cloud Platform Service Level Agreements .
The support services are described on our technical support services guidelines page.
Google provides documentation to explain how institutions and their employees can use our services. If an institution would like more guided training, Google also provides a variety of courses and certifications .
Services
Technical Support
- Obligations of the financial institution;
- Refer to your Google Cloud Financial Services Contract.
- The contracting parties' rights in modifying existing services performed under the contract; and
Google continuously updates the services to enable our customers to take advantage of the most up-to-date technology. Given the one-to-many nature of our service, updates apply to all customers at the same time.
Google will not make updates that materially reduce the functionality, performance, availability or security of the Services.
If Google needs to discontinue a service without replacing it, you will receive at least 12 months’ advance notice. Google will continue to provide support and product and security updates during this period.
- Guidelines for adding new or different services and for contract re-negotiation.
New services
Google is continuously introducing new services to offer our customers the latest features and functionality. New services are added to the services summary page when they are available and each customer can choose whether or not to use them under their existing contract.
Contract re-negotiation
As services and technology change, Google may update certain terms at URLs that apply to all our customers. Any updates must meet strict criteria. For example, they must not result in a material degradation of the overall security of the services or have a material adverse impact on your existing rights. Beyond these limited updates, any contract changes must be made in writing and signed by both parties.
Updates to Services and Terms
Changes to Terms; Amendments
The security and privacy of information when using a cloud service consists of two key elements:
Google’s infrastructure
Google manages the security of our infrastructure. This is the security of the hardware, software, networking and facilities that support the Services.
Given the one-to-many nature of our service, Google provides the same robust security for all our customers.
Google provides detailed information to customers about our security practices so that customers can understand them and consider them as part of their own risk analysis.
More information is available at:
- Our infrastructure security page
- Our security whitepaper
- Our cloud-native security whitepaper
- Our infrastructure security design overview page
- Our security resources page
Your data and applications in the cloud
You define the security of your data and applications in the cloud. This refers to the security measures that you choose to implement and operate when you use the Services.
(a) Security by default
Although we want to offer you as much choice as possible when it comes to your data, the security of your data is of paramount importance to Google and we take the following proactive steps to assist you:
- Encryption at rest. Google encrypts customer data stored at rest by default, with no additional action required from you. More information is available at: https://cloud.google.com/security/encryption/default-encryption .
- Encryption in transit. Google encrypts and authenticates all data in transit at one or more network layers when data moves outside physical boundaries not controlled by Google or on behalf of Google. More information is available at https://cloud.google.com/security/encryption-in-transit .
(b) Security products
In addition to the other tools and practices available to you outside Google, you can choose to use tools provided by Google to enhance and monitor the security of your data. Information on Google’s security products is available on our Cloud Security Products page.
(c) Security resources
Google also publishes guidance on:
Use of your information
Google commits to only access or use your data to provide the Services ordered by you and will not use it for any other Google products, services, or advertising.
Privacy and Non-Public Personal Information
Google will comply with privacy laws and regulations applicable to it in the provision of the Services.
Security breaches
Google will notify you of data incidents promptly and without undue delay. More information on Google’s data incident response process is available in our Data incident response whitepaper .
Data Security; Security Measures ( Data Processing and Security Terms )
Protection of Customer Data
Processing of Data; Roles and Regulatory Compliance ( Data Processing and Security Terms )
Data Incidents ( Data Processing and Security Terms )
- Service provider internal controls;
Google undergoes several independent third-party audits on at least an annual basis to provide independent verification of the effectiveness of our internal controls. To give you visibility of the effectiveness of our internal controls throughout our relationship, Google commits to maintain certifications / reports for the following key international standards during the term of our contract with you:
- Compliance with applicable regulatory requirements;
- Record maintenance requirements for the service provider;
- Access to the records by the institution;
- Notification requirements and approval rights for any material changes to services, systems, controls, key project personnel, and service locations;
Services
Refer to row 25 on changes to the services.
Personnel
Customers can operate the services independently without action by Google personnel. Although Google personnel manage and maintain the hardware, software, networking and facilities that support the Services, given the one-to-many nature of the services, there are no Google personnel dedicated to delivering the services to an individual customer.
Locations
To provide you with a fast, reliable, robust and resilient service, Google may store and process your data where Google or its subprocessors maintain facilities.
- Learn more about the location of Google’s facilities and where individual GCP services can be deployed.
- Learn more about the location of Google’s subprocessors’ facilities .
Google provides the same contractual commitments and technical and organizational measures for your data regardless of the country / region where it is located. In particular:
- The same robust security measures apply to all Google facilities, regardless of country / region.
- Google makes the same commitments about all its subprocessors, regardless of country / region.
Google provides you with choices about where to store your data - including a choice to store your data in the United States. Once you choose where to store your data, Google will not store it outside your chosen region(s).
You can also choose to use tools provided by Google to enforce data location requirements. For more information, see our Data residency, operational transparency, and privacy on Google Cloud Whitepaper .
Data Transfers ( Data Processing and Security Terms )
Data Security; Subprocessors ( Data Processing and Security Terms )
Data Location ( Service Specific Terms )
- Setting and monitoring parameters for financial functions including payments processing or extensions of credit on behalf of the institution; and
- Insurance coverage maintained by the service provider.
Audit reports
Refer to row 10 for more information on the audit reports that Google provides. Google commits to maintain these reports throughout the term of our contract with you. The reports are produced on at least an annual basis after an audit by an independent third-party.
You can review Google’s current certifications and audit reports at any time.
- Google’s ISO certificationsare available here .
- Google’s SOC reportsand PCI Attestation of Compliance (AOC)are available via your Google Cloud account representative.
Institutions may provide these materials to their regulatory agencies.
Inspection
Google recognizes that institutions must be able to audit our services effectively. Google grants audit rights to institutions and their independent auditors, including to inspect Google’s processing facilities and operating practices. The institution is best placed to decide what audit frequency is right for their organization. Our contract does not limit institutions to a fixed number of audits.
Certifications and Audit Reports;
Enabling Customer Compliance
Performance reports
You can monitor Google’s performance of the Services (including the SLAs) on a regular basis using the functionality of the Services.
For example:
- The Status Dashboard provides status information on the Services.
- Google Cloud Operations is an integrated monitoring, logging, and diagnostics hosted solution that helps you gain insight into your applications that run on GCP.
- Access Transparency is a feature that enables you to review logs of actions taken by Google personnel regarding your data. Log entries include: the affected resource, the time of action, the reason for the action (e.g. the case number associated with the support request); and data about who is acting on data (e.g. the Google personnel’s location)
Financial reports
Google provides billing tools that customers can use to obtain reports on their usage of the Services and associated costs. More information is available on our Cloud Billing documentation page and the Export Cloud Billing data to BigQuery page.
Audit and security reports
Refer to row 10.
Business resumption testing reports
Refer to row 40.
Significant developments
Google will make information about developments that materially impact Google’s ability to perform the Services in accordance with the SLAs available to you. More information is available on our Incidents & the Google Cloud dashboard .
Ongoing Performance Monitoring
Significant Developments
Google will implement a disaster recovery and business contingency plan for our services, review and test it at least annually and ensure it remains current with industry standards. Institutions can review our plan and testing results.
In addition, information about how customers can use our Services in their own disaster recovery and business contingency planning is available in our Disaster Recovery Planning Guide .
Google recognizes that institutions need to consider the risks associated with subcontracting. We also want to provide you and all our customers with the most reliable, robust and resilient service that we can. In some cases there may be clear benefits to working with other trusted organizations e.g. to provide 24/7 support.
Accountability
Google requires our subcontractors to meet the same high standards that we do. In particular, Google requires our subcontractors to comply with our contract with you. Google will remain responsible for the performance of all subcontracted obligations.
Information and changes
To enable institutions to retain oversight of any subcontracting and provide choices about the services institutions use, Google will:
- provide information about our subcontractors (including their function and location);
- provide advance notice of changes to our subcontractors; and
- give institutions the ability to terminate if they have concerns about a new subcontractor.
Refer to your Google Cloud Financial Services Contract.
Audit
Google is committed to supporting institutions with audits or examinations of our services. As this support is not included in our usual publicly listed service fees, Google may charge an additional fee in connection with an audit or examination. Google will provide further details of any fee in advance of the activity when the scope of the activity is known.
Data
You retain all intellectual property rights in your data, the data you derive from your data using our services and your applications. Refer to row 28 for Google’s commitment about the use and protection of your data.
Trademarks, logos etc
Google will not use your brand features without your prior approval.
Intellectual Property
Marketing and Publicity
Termination
Institutions can elect to terminate our contract for convenience with advance notice, including if Google increases the fees or if necessary to comply with law.
In addition, institutions may terminate our contract with advance notice for Google’s material breach after a cure period, for change in control or for Google’s insolvency.
Transfer
Google recognizes that institutions need sufficient time to exit our services (including to transfer services to another service provider). To help institutions achieve this, upon request, Google will continue to provide the services for 12 months beyond the expiry or termination of the contract.
Google will enable you to access and export your data throughout the duration of our contract and during the post-termination transition term. You can export your data from the Services in a number of industry standard formats. For example:
- Google Kubernetes Engine is a managed, production-ready environment that allows portability across different clouds as well as on premises environments.
- Migrate to Containers allows you to move and convert workloads directly into containers in Google Kubernetes Engine.
- You can export/import an entire VM image in the form of a .tar archive. Find more information on images and storage options on our Compute Engine Documentation page.
Assignment
Refer to your Google Cloud Financial Services Contract.
Subcontracting
Refer to row 41 on subcontracting.
Google LLC is the provider of the services for US-based institutions. Google LLC is organized under the laws of the State of Delaware, USA.
Refer to your Google Cloud Financial Services Contract for more information about the governing law and jurisdiction that applies to our contract.
Compliance
Google will comply with all laws, regulations and binding regulatory guidance applicable to it in the provision of the Services.
Access by regulatory agencies
Google grants access and information rights to institutions’ regulatory agencies and their appointees.
Representations and Warranties
Regulator Information, Audit and Access

