There is a sentence that turns up in every outsourcing discussion and that Brazilian regulation contradicts explicitly: "that is the supplier's responsibility now". Under CMN Resolution No. 4,893/2021, the institution that contracts data processing or cloud computing still answers for the service — what it outsources is the execution, not the accountability.
That changes what assessing a supplier means. It is not a procurement check before signing; it is a continuous control, with evidence, over a risk that has moved out of the house.
Before contracting
Article 12 requires governance procedures proportionate to the relevance of the service — and that phrase is the key to the whole rule. Not every supplier deserves the same rigour: what sets the depth of the assessment is what breaks if it stops.
Verifying the provider's capability, in the same article, comes with a concrete list. The institution has to confirm that the supplier ensures:
- Compliance with applicable legislation and the institution's access to its own data.
- Confidentiality, integrity and availability of the data and systems.
- The certifications required by the institution for the provision of the service.
- Access to independent audit reports and to monitoring information.
- Segregation of data between clients and adequate access controls.
Look at the third and fourth items. That is where ISO 27001 and SOC 2 come in, in practice — not as a decorative badge, but as the evidence the rule tells you to demand and keep. An ISO 27001 certificate proves that an audited management system exists; a SOC 2 Type II report proves that specific controls operated effectively over a period. They are different things, and it is worth knowing which one you are asking for.
The contract
Article 17 lists clauses that have to be written down. It is the part most often discovered late, once the contract has already been signed on the supplier's standard template:
- Countries and regions where the service may be provided and the data stored.
- Security measures for transmission and storage, and segregation of data.
- Transfer and deletion of the data on termination of the contract — the exit clause, almost always forgotten in the euphoria of signing.
- Access to information and certifications, and notice of subcontracting.
- Central Bank access to the data and information of the service.
The subcontracting clause deserves particular attention. Your supplier has suppliers, and inherited risk runs down the whole chain. Without contractual notice, you find out the fourth link exists on the day of the incident.
Notifying the Central Bank
Article 15 requires the contract to be reported to the Central Bank within ten days of contracting, giving the name of the contracted company, the services contracted and the locations where the data will be processed.
Ten days is calendar time, not project time. Whoever discovers this requirement after signing usually discovers along with it that they cannot answer the third question — in which locations the data will be processed — because it was never negotiated and is not in the contract.
Services provided abroad
Article 16 imposes additional conditions when the processing happens outside Brazil. The main one is the existence of an information-exchange agreement between the Central Bank and the supervisory authority of the country. Where the agreement exists, the locations and continuity alternatives must also be defined in advance. Where there is no agreement, contracting depends on a request for authorisation filed 60 days in advance.
That article is what turns an apparently technical choice — which provider region the workload runs in — into a regulatory decision with a deadline. It is worth settling in the architecture, before it becomes an authorisation request.
How this becomes a process, not paperwork
A supplier assessment that lives in a separate spreadsheet ages in weeks. What sustains the requirement over time is treating the third party as one more source of risk in the same register as internal risks — with an owner, acceptance criteria and periodic review, exactly like any other.
- Classify by relevance, not by contract size. The criterion is what stops if the supplier stops.
- Keep the evidence with an expiry date. Certificates and audit reports expire; the review has to be scheduled, not remembered.
- Link the supplier to the processes that depend on it. Without that link there is no way to answer which service stops when it goes down.
- Treat exit as part of the risk. Data portability and deletion are a control, not contractual bureaucracy.
CMN Resolution 5,274/2025, which updated the cybersecurity framework, loosened none of this — it reinforced the set. Organisations that already treated third parties rigorously had little to do; those that treated it as a procurement formality had work ahead.
Source consulted on 11 September 2026: CMN Resolution No. 4,893 of 26 February 2021, articles 12, 15, 16 and 17. This article is informational and does not constitute legal advice; consult the official text on the Central Bank website.