IBM Cloud for Financial Services and Promontory Advisory Services provide a holistic and practical approach to an increasingly complex cloud environment.

Data fuels today’s global economy, and like any appreciating asset, whether tangible or virtual, data requires strong privacy and security protections.

While companies and government agencies are steadily migrating sensitive workloads to cloud environments, the heavily regulated financial sector has been less willing to lift and shift their data to a public cloud [1]. According to an IBM commissioned report, financial institutions are only running 9% of their storage, disaster recovery and data archiving applications in the cloud. This hesitancy is due in part to the heavily-regulated nature of financial services, the global growth of privacy and data protection regulations (e.g., European Union’s General Data Protection Regulation (GDPR) and the California Consumer Protection Act (CCPA)) and restrictions in cross-border data transfers.

This first article in our “Privacy and Security in the Cloud” series provides a high-level overview of how the combination of IBM Cloud for Financial Services and Promontory’s advisory services can help clients address their privacy, security, and data protection obligations.

IBM Cloud for Financial Services

The IBM Cloud for Financial Services operates on the IBM public cloud and provides a custom-made, secure environment for financial institutions and their partners to process critical and sensitive workloads. This financial services-centric cloud is designed to enable financial institutions, their independent software vendors (ISVs), Software as a Service (SaaS) providers and IBM Cloud to transact and operate securely and confidently.

Built with-and-for the financial sector

Initially developed with Bank of America, the IBM Cloud for Financial Services has since onboarded other global financial institutions — such as BNP Paribas, Luminor Bank and MUFG —  and is now backed by more than 120 ecosystem partners. This includes SAP, EY, Tata Consultancy Services, ISVs and several SaaS providers that continue to contribute to a secure, compliant and auditable public cloud environment for financial institutions with critical workloads.

“Being able to bring the independent software vendors, software-as-a-service providers and fintechs into an ecosystem with a proactive security and compliance context is really what we’re all about. That will enable a flourishing of adoption of innovation.”Hillery Hunter, VP & CTO, IBM Cloud

Driving cloud compliance: IBM Cloud Framework for Financial Services

The heart of the IBM Cloud for Financial Services is the IBM Cloud Framework for Financial Services (Framework for Financial Services).

The Framework for Financial Services is comprised of a standard set of controls, architectures and deployment patterns informed by global regulatory requirements for cybersecurity, data security, data privacy and risk management. This also includes ongoing governance by IBM Financial Services Cloud Council and Promontory to ensure currency with new and changed regulations. The Framework for Financial Services currently applies base controls — aligned to the National Institute of Standards and Technology’s (NIST) Special Publication 800-53,Security and Privacy Controls for Information Systems and Organizations [2] — with specific IBM Financial Services guidance providing a common control approach to IBM Cloud services, IBM software and third-party ISV and SaaS providers.

IBM Financial Services Cloud Council

To further inform and influence the IBM Cloud Framework, IBM established the Financial Services Cloud Council (Council), a group of senior executives from global and regional financial institutions leading a focused effort to reduce the risk of cloud consumption across this highly regulated sector. IBM and Promontory work with the Council to help drive an innovative new construct for public cloud centered in cloud privacy and security, enabling cloud adoption for critical workloads.

The Promontory advantage

Promontory helps organizations successfully embark upon and execute large-scale business and technology transformations. Our teams of former industry practitioners, executives and regulators advise clients on key risk, compliance, privacy and operational resilience program elements and regulatory requirements. No matter where a client is in their cloud journey, our teams can assist throughout every stage — from upfront strategic design, through migration and development, to ongoing management.

Promontory’s privacy, risk management and regulatory services

To fully benefit from a cloud transformation, institutions also need a sound target operating model to address future technology, privacy and compliance risks, as well as evolving regulatory and business requirements. Promontory’s services are tailored to the specific size, complexity and needs of a client. Services can be delivered as standalone work efforts or executed as a comprehensive, end-to-end solution.

With offices across the U.S., Europe and Asia, Promontory helps firms integrate technology into their privacy risk management frameworks and develop privacy control frameworks to support compliance with local, national and regional privacy requirements.

Promontory advises organizations on how best to meet their privacy requirements through creating or conducting the following:

  • Accountability and governance frameworks
  • Privacy compliance assessments
  • Privacy risk assessments
  • Incident reporting process
  • Data localization strategies
  • Cross-border data transfer strategies
  • Third-party risk management assessments.

Promontory also helps clients to adopt a privacy-by-design (PbD) [3] approach that embeds privacy controls into services, systems and applications at the design stage to avoid compliance gaps and delays. PbD helps ensure that personal data in the cloud is used only for the purposes disclosed to end users.

Promontory’s Cloud Privacy Control Deployment: Bringing order to privacy regulations

The world of global privacy regulations is complex, with a torrent of varying obligations carrying financial and reputational consequences for non-compliance.

Promontory’s Cloud Privacy Control (CPC) Deployment provides a comprehensive and pragmatic approach to privacy compliance in simple and complex private, public and hybrid cloud environments. Designed to align regulatory requirements, industry standards and business needs, the CPC provides a solid baseline for effectively and efficiently managing privacy in the cloud.

Promontory also offers managed privacy services to assist privacy program operations. Scalable and flexible on-demand privacy operations help firms manage day-to-day privacy operations, clear backlogs, address unpredictable volumes of work and reduce costs.

IBM and Promontory provide a full-service cloud experience

IBM Cloud’s security and privacy services — in combination with Promontory’s regulatory advisory services — provide clients with a holistic and practical approach to an increasingly complex cloud environment.

Learn more about the IBM Cloud for Financial Services.

Watch out for our next blog: “Get a Good Night’s Sleep in the Cloud: The Security and Privacy Benefits of IBM and Promontory Services”


[1] Angus Loten, IBM, Bank of America Team Up on Public Cloud Aimed at Banks, Wall Street Journal, November 6, 2019

[2] National Institute of Standards and Technology’s (NIST), Special Publication 800-53, “Security and Privacy Controls for Information Systems and Organizations.”

[3] See also, “IBM Security and Privacy by Design (SPbD@IBM).”


More from Cloud

IBM Cloud VMware as a Service introduces multitenant as a new, cost-efficient consumption model

4 min read - Businesses often struggle with ongoing operational needs like monitoring, patching and maintenance of their VMware infrastructure or the added concerns over capacity management. At the same time, cost efficiency and control are very important. Not all workloads have identical needs and different business applications have variable requirements. For example, production applications and regulated workloads may require strong isolation, but development/testing, training environments, disaster recovery sites or other applications may have lower availability requirements or they can be ephemeral in nature,…

IBM accelerates enterprise AI for clients with new capabilities on IBM Z

5 min read - Today, we are excited to unveil a new suite of AI offerings for IBM Z that are designed to help clients improve business outcomes by speeding the implementation of enterprise AI on IBM Z across a wide variety of use cases and industries. We are bringing artificial intelligence (AI) to emerging use cases that our clients (like Swiss insurance provider La Mobilière) have begun exploring, such as enhancing the accuracy of insurance policy recommendations, increasing the accuracy and timeliness of…

IBM NS1 Connect: How IBM is delivering network connectivity with premium DNS offerings

4 min read - For most enterprises, how their users access applications and data is an essential part of doing business, and how they service those application and data responses has a direct correlation to revenue generation.    According to We Are Social’s Digital 2023 Global Overview Report, there are 5.19 billion people around the world using the internet in 2023. There’s an imperative need for businesses to trust their networks to deliver meaningful content to address customer needs.  So how responsive is the…

IBM Cloud Databases for MongoDB (Enterprise Edition): Changes to backup functionality

< 1 min read - We are announcing that IBM Cloud Databases for MongoDB (Enterprise Edition) will no longer support the creation of On Demand backups beginning on March 1, 2024. On Demand backups are being replaced by the recently deployed Point in Time Recovery (PITR) capabilities in the Enterprise Edition of our popular fully managed MongoDB service. With PITR, you can restore a copy of your database to any point in the past seven days. This gives you granular access to the past state…