AWRA OpsHub Search

When the Supervisor Asks About Every System

A regulated institution is expected to know every third party that holds its data and how. The core system gets that scrutiny already. The operations system that holds staff, supplier and asset records usually does not, until the supervisor asks.

SACCOs & Microfinance Washingtone Aura 7 min read

Brief

Supervisors of SACCOs, banks and insurers increasingly expect an institution to list every outside party holding its data and to describe how each one holds it. Your operations system is on that list. A dedicated instance lets you describe it in one line: our own instance, operated by the vendor, with no other organization on it.

The core banking system, the member register and the policy administration system get serious attention in any regulated institution. The system that runs procurement, stores, fixed assets, payroll and the general ledger behind them often does not. It still holds staff files, supplier bank details and the asset register, and when the supervisor asks for the third-party register it belongs on it.

What the supervisor is looking for

The detail differs between a SACCO regulator, a central bank and an insurance regulator, and between countries. The shape of the question rarely does. For each outside party that holds the institution’s data, they want to know:

The third-party questions

  • Which data the party holds, and why.
  • Where it is held, and whether any other organization shares the system.
  • How the institution would get its data back if the relationship ended.
  • How the institution oversees the party, and how often.
  • What happens to operations if the party fails.

The second question is the one where the hosting arrangement does the talking. On a shared service, the answer is a description of how organizations are separated. On a dedicated instance, it is a fact: one institution, its own database, its own encryption key, its own backups.

Why operations systems get missed

Because they are bought by the operations or finance team, not by IT risk, and because they do not hold member balances. But a supplier master with bank details is a fraud target, a payroll file is personal data on every employee, and an asset register is the evidence behind the balance sheet. A risk team that discovers the system during an inspection, rather than before it, has a harder conversation.

It does not hold member savings. It holds the payroll, the supplier bank details and the asset register, which is enough.

Record Why a supervisor cares
Supplier master and bank details Payment fraud starts with a changed account number.
Payroll and staff files Personal data on every employee, and a large recurring payment.
Fixed asset register Evidence for a balance-sheet line.
Procurement approvals Who authorised spend, and whether the limits were followed.

If you are preparing for an annual general meeting or an inspection, SACCO audit readiness covers the evidence side, and ten questions for any vendor gives you the vendor answers to put in the third-party register.

Before the next inspection

Is the operations system on our third-party register?

Have ready

An entry naming the vendor and the data.

From

Your risk team, with the vendor’s written answers.

Can we say who else is on it?

Have ready

“Nobody”, or a clear description of the separation.

From

The hosting arrangement you choose.

Can we get our data back?

Have ready

A described export and removal process.

From

The vendor, tested before you need it.

Who can change supplier bank details?

Have ready

Named roles, with an approval step.

From

Your own role setup and audit trail.

More we can add

For a regulated institution

Where a supervisor’s expectations go beyond the standard instance, these are the additions we build.

Region in the contract

Hosting set in the country or region your supervisor expects.

A trimmed provider list

Optional services switched off so the provider list matches your outsourcing register.

Your own domain

The system at an address on the institution’s own domain.

How it works: share the supervisor’s requirement, and we return a written scope and cost.

See the dedicated instance

The straight answer

What AWRA OpsHub does today

  • A dedicated instance used by one institution alone, with its own database, encryption key, storage and backups.
  • A Dedicated server tier, where the machine runs your instance and nothing else.
  • Role-based access and an audit trail over procurement, payroll, assets and the ledger.
  • An export of your records, followed by removal, when the relationship ends.

More we can add to your workspace

  • Hosting in a country or region your supervisor names, set in the contract.
  • A sub-processor list trimmed to your outsourcing register.
  • Your own domain in place of the awraops.com address.

Where we point you to a specialist

  • We do not run member savings, loans, deposits or claims. Those belong in your core banking or policy system; AWRA runs the operations around them.
  • We do not tell you whether an arrangement satisfies your supervisor. Your risk and compliance function makes that call, and we will put our answers in writing for it.

Each of these can be scoped into a dedicated-instance quote.

One line on the third-party register

Our own instance, operated by the vendor, no other organization on it. Available to set up now.

See the dedicated instance

Frequently asked questions

Does an ERP belong on a regulated institution’s third-party register?

Usually, yes. An operations system holds staff files, payroll, supplier bank details and the asset register, which supervisors expect an institution to account for.

Is AWRA a core banking or SACCO system?

No. AWRA runs procurement, stores, assets, HR, payroll and finance around the core system. Member savings, loans, deposits and claims belong in a core banking or policy system.

Does a dedicated instance make us compliant with our supervisor?

No system does that on its own. It lets you state that no other organization is on your operations system. Whether an arrangement satisfies your supervisor is for your risk and compliance function to decide.

Can the server be ours alone?

Yes. On the Dedicated server tier, the machine runs your instance and nothing else.

Share this article

LinkedIn X WhatsApp

Help Center

Need a quick answer while you read?

Run inventory, procurement, assets, sales, and field work with approved AWRA guidance for setup, migration, integrations, security, pricing, and support.

Search all approved AWRA public help articles.

Open Help Center