Introducing Streamhouse: the open data architecture for AI | Learn More
Trust is foundational to how Confluent designs, operates, and governs its products. Confluent's Trust Principles shape everything from how Confluent Cloud is engineered to how it is monitored and audited. Each principle is backed by specific, independently verified controls. This commitment underpins a growing portfolio of global certifications and attestations, including SOC 2 Type II, ISO 27001, ISO 27701, and CSA STAR Level 2, that give customers continuous, third-party-verified evidence of Confluent's security posture, available on demand through the Confluent Trust Center. It's against this backdrop that Confluent continues to expand its compliance footprint in region-specific and sector-specific frameworks, with Outsourced Service Provider's Audit Report (OSPAR) as the latest addition.
Confluent Cloud has successfully achieved an OSPAR attestation. This milestone extends Confluent's existing portfolio of independently audited certifications and gives Singapore's financial institutions a verified, sector-specific assurance point built specifically for outsourced technology arrangements.
For financial institutions evaluating Confluent Cloud for real-time data streaming, this attestation is more than a compliance checkbox. It is independent confirmation that Confluent's governance, risk management, and technical controls meet the standards Singapore's financial sector expects from providers handling regulated, outsourced workloads.
OSPAR is a third-party assurance report issued by an authorized service auditor under the “Guidelines on Control Objectives and Procedures for Outsourced Service Providers” established by the Association of Banks in Singapore (ABS). It exists because Singapore's banking regulators expect financial institutions to maintain the same standard of oversight over outsourced technology providers as they do over their own internal systems.
Obtaining an OSPAR attestation is not a self-declared checklist. It requires engaging an auditor that meets ABS's qualification guidelines. These guidelines set the minimum, baseline controls that any outsourced service provider should have in place before serving Singapore's financial institutions. The latest version of the framework, OSPAR v2.0, is organized around three broad control groupings, together spanning a wide set of domains:
Entity-Level Controls, covering corporate governance, risk management frameworks, human resources security, and overall organizational compliance.
General IT Controls, covering logical security, physical security, change management, incident management, backup and disaster recovery, network and security management, security incident response, data security, cryptography, and software application development and management.
Service-Level Controls, covering business continuity management and the maintenance of records that financial institutions can rely on for their own due diligence.
Rather than each bank running a separate, bespoke audit of the same vendor, OSPAR gives Singapore's financial institutions a common, independently verified benchmark.
This matters for two reasons:
First, it aligns with MAS's outsourcing and technology risk expectations, so a bank's own risk team can point to OSPAR as recognized, sector-specific evidence rather than building a compliance case from scratch.
Second, it shortens due diligence. Instead of lengthy back-and-forth questionnaires ahead of every deal or renewal, a bank's procurement and risk teams can reference an attestation that was designed, from the outset, around what Singapore's financial sector needs to see.
Achieving the attestation is only useful if customers can actually put it to work in their own risk and procurement processes. Confluent's approach is to make that as straightforward as possible:
On-demand access through the Trust Center: The OSPAR report, alongside SOC 2 Type II, ISO 27001, ISO 27701, and CSA STAR, can be requested through Confluent's Trust Center.
Alignment to existing frameworks: Because OSPAR's control domains mirror much of what the MAS Technology Risk Management Guidelines and the MAS Outsourcing Guidelines already expect, customers can use the attestation to support multiple internal review processes rather than treating it as a standalone artifact.
Continuous relevance: As Confluent's governance and technical controls evolve, the attestation is maintained as part of the annual review cycle that governs Confluent's other certifications, so the evidence customers rely on stays current rather than becoming a point-in-time artifact.
OSPAR does not exist in isolation — it is one part of a broader, layered regulatory environment that Singapore has built around technology infrastructure and outsourcing. Bodies like the Monetary Authority of Singapore (MAS), the Cyber Security Agency of Singapore (CSA), and the Infocomm Media Development Authority (IMDA) each set expectations that extend beyond regulated enterprises to their technology vendors, including cloud service providers.
For any organization running an Apache Kafka® cluster or Apache Flink® pipeline that carries subscriber, transaction, or operational data, this layered regulatory environment is the baseline against which deployment decisions get evaluated. OSPAR is the piece of that landscape that is relevant to banks and other regulated financial institutions evaluating third-party vendors, but it sits alongside a wider set of frameworks spanning financial services, telecommunications, the public sector, and other CII sectors.
To help customers connect the dots between individual frameworks and the regulatory landscape they operate in, Confluent has published a dedicated white paper aligning Singapore's leading frameworks such as the MAS Technology Risk Management Guidelines, the MAS Outsourcing Guidelines, CCoP 2.0, and IM8 directly to the architecture and controls Confluent Cloud provides today.
We encourage teams navigating Singapore's regulatory requirements, whether in financial services, telecommunications, the public sector, or other CII-designated industries, to leverage the whitepaper as a working reference alongside the OSPAR attestation and our commitment to transparency through Confluent's Trust Center.
The OSPAR attestation reflects a broader principle behind how Confluent builds and operates Confluent Cloud: trust should be demonstrated through independently audited architecture, not asserted through policy alone. As Singapore's regulatory expectations continue to evolve, Confluent will continue to invest in the certifications, attestations, and documentation that let customers verify that commitment for themselves.
Visit the Confluent Trust Center to request the OSPAR report and access Confluent's full portfolio of certifications and the Singapore Trust white paper.
A guide to the Third-Party Risk Assessments available in the Confluent Trust Center and how customers can leverage the right one for their needs.
Learn how to migrate to Confluent Cloud in hours using Confluent’s open source Kafka Copy Paste tool. Get an in-depth introduction to the KCP tool and a walk-through of the four steps of migrating from MSK to Confluent Cloud using the tool.