Industry · Banking
DevOps for Banking — secure multi-cloud platforms
Managed DevOps for banks and digital banking programmes: hardened multi-cloud, audit evidence, peak reliability, and 15-min CRITICAL SLA across Europe, GCC, and Morocco.
Challenges we solve
- Regulated workloads and audit cycles
- Hybrid core + cloud estates
- Strict change and access controls
- Shortage of senior platform engineers
Outcomes
What is different about running Banking infrastructure
The constraints below are specific to this sector — they are why a generic platform engagement tends to miss.
What regulates the infrastructure
Applying since 17 January 2025. Binds infrastructure directly: a maintained register of information on all ICT third-party arrangements submitted annually through the national competent authority, prescribed contractual terms covering access, audit, subcontracting, data location and documented exit, major ICT incident notification within four hours of classifying an incident as major (and no later than 24 hours from becoming aware), an intermediate report at 72 hours and a final report within one month, and threat-led penetration testing for entities in scope. It also establishes EU-level oversight of ICT providers designated as critical.
Published 31 March 2021. Not binding in itself, but it is the template most prudential supervisors have adopted: identify critical operations, set explicit tolerances for disruption to each, map the people, processes, technology and third parties those operations depend on, and test against severe-but-plausible scenarios. It also requires that third parties demonstrate an equivalent or higher standard of operational resilience, which pushes the obligation down the supply chain.
CSCF v2026 comprises 32 controls of which 26 are mandatory and 6 advisory, up from 25 mandatory in v2025 because control 2.4 (back-office data flow security, covering the flows between the general IT environment and the SWIFT secure zone) moved from advisory to mandatory in this cycle. Users must undergo an independent assessment against at least the mandatory controls and submit an annual KYC-SA attestation; the v2026 attestation window runs from July to December 2026. The framework prescribes an isolated secure zone with separately administered access, which is an architectural mandate rather than a policy one. The exact mandatory/advisory split should be read from the published CSCF v2026 document.
Euro-area credit institutions have had to receive instant euro credit transfers since 9 January 2025 and to send them since 9 October 2025, processed within ten seconds and available 24/7/365, with a free verification-of-payee service. This eliminates the overnight and weekend quiet period that core banking maintenance historically depended on.
Issued 19 May 2022 and prepared in consultation with the DGSSI (national information systems security authority) and the CNDP (data protection authority). It sets the minimum conditions Moroccan credit institutions must meet before outsourcing to cloud, covering supervisory notification, provider security requirements and data protection. Directive No. 3/W/2016 remains the underlying information-systems security directive for the sector.
What actually goes wrong here
- Overnight batch overrun in the core banking system. Interest accrual, transaction posting, standing orders and statement generation run inside a fixed window; if the batch does not complete, the next business day opens with wrong balances and unexecuted instructions, and the error compounds into subsequent cycles rather than clearing itself.
- Missed settlement cut-offs. Large-value payment systems close at a fixed time; a payment that misses the window does not simply arrive late — it leaves an unsettled position overnight, creating liquidity and counterparty exposure and, at scale, a reportable incident.
- The vanishing maintenance window. Continuous instant-payment obligations mean the weekend change window that core banking upgrades were built around no longer exists in the euro area, so changes to shared components must be made live against a service that is contractually obliged to answer in ten seconds.
- Third-party and sector concentration. Many institutions depend on the same core banking vendor, card processor or cloud region, so one supplier failure becomes a simultaneous multi-bank event that no single bank's recovery plan can absorb — the specific risk DORA's critical ICT third-party provider oversight was created to address.
- Card switch and ATM network outages. Because these are the most publicly visible part of a bank, an interruption produces immediate reputational and, in cash-reliant markets, social consequences well out of proportion to the transaction volume affected.
- Risk-data aggregation failures at reporting deadlines. Prudential returns require assembling consistent data across legacy systems on a hard submission date; a broken feed is not a delayed report but a supervisory breach, and the reconciliation work has no slack in the calendar.
- Breach of the SWIFT secure zone boundary. Attacks on the payment-messaging path target the back-office systems feeding it rather than SWIFT itself, which is why the framework's controls concentrate on isolating and monitoring those flows.
How demand behaves
Largely calendar-driven and predictable. Retail volumes concentrate on salary payment dates, month-end and the days before public holidays; wholesale payment traffic bunches ahead of the daily RTGS cut-off each afternoon; prudential and financial reporting workloads spike at month, quarter and year end. Instant payment obligations have flattened the historical overnight trough, because the rails must run continuously even when branch and corporate activity is at zero.
Data you will be holding
Account balances, transaction histories, payment message content and AML/KYC identity records. Banking secrecy statutes in many jurisdictions restrict disclosure and cross-border transfer independently of data protection law, so a lawful GDPR-style transfer can still be a secrecy breach. AML rules generally require records be retained for years after the customer relationship ends, which puts retention obligations in direct tension with erasure rights and constrains how backups and archives can be designed.
Architecture this pushes you toward
A vendor or mainframe core with a batch cycle, fronted by channel and API layers that must stay answerable while the core is closed for cut-over. SWIFT connectivity sits in an isolated secure zone with separately administered credentials and controlled data flows from the back office. Regulatory expectations push toward documented and tested exit plans for each ICT provider, warm secondary sites, and the ability to evidence recovery to a supervisor — the burden is proving resilience, not only having it.
Availability expectation
Retail channels and payment rails are typically targeted at 99.9% or better, and euro-area instant payment obligations make continuous operation a legal requirement rather than an SLA. Supervisors increasingly express the expectation as an impact tolerance — the maximum tolerable disruption to a named critical operation — rather than as an availability percentage, so the operative number differs per operation and per institution.
In Morocco
Bank Al-Maghrib licenses and supervises credit institutions under Law 103-12 and has been shifting supervisory attention toward non-financial risk, with cybersecurity treated as a priority alongside tighter oversight of critical service providers. Directive 4/W/2022 (19 May 2022) sets the minimum rules for cloud outsourcing by credit institutions and Directive 3/W/2016 covers information systems security. Banks are treated as organisations of vital importance under the national information-systems security framework overseen by the DGSSI, which in practice drives strong expectations around domestic hosting and prior engagement with the regulator before outsourcing; the precise localisation obligation should be read from the directive text rather than from secondary reporting.
Banking au Maroc — contexte local
Les banques marocaines modernisent leur socle IT tout en restant soumises à la supervision de Bank Al-Maghrib et à des exigences strictes de continuité d'activité et de souveraineté des données.
Contraintes spécifiques au Maroc
- Plans de continuité et de reprise (PCA/PRA) auditables
- Migration progressive vers le cloud sans rupture du core banking
- Cloisonnement et chiffrement des données clients
Cadre réglementaire & conformité
Related
FAQ
Does CloudLink specialise in Banking?
Yes. We apply multi-cloud DevOps patterns proven in Banking environments — with a 15-minute CRITICAL SLA and coverage across Morocco, the Middle East, and Europe.
Can you combine managed ops and staffing?
Yes — retainers for platform ownership plus 48-hour staffing shortlists when you need surge capacity.
How do we start?
Book a demo at /demo or run a free audit at /audit. Pricing is transparent at /pricing.
