Ahorra un 25 % (o incluso más) en tus costes de Kafka | Acepta el reto del ahorro con Kafka de Confluent

Confluent Strengthens Trust for Singapore's Markets with OSPAR Attestation

Escrito por

Trust is foundational to how Confluent designs, operates, and governs its products. Confluent's Trust Principles shape everything from how Confluent Cloud is engineered to how it is monitored and audited. Each principle is backed by specific, independently verified controls. This commitment underpins a growing portfolio of global certifications and attestations, including SOC 2 Type II, ISO 27001, ISO 27701, and CSA STAR Level 2, that give customers continuous, third-party-verified evidence of Confluent's security posture, available on demand through the Confluent Trust Center. It's against this backdrop that Confluent continues to expand its compliance footprint in region-specific and sector-specific frameworks, with Outsourced Service Provider's Audit Report (OSPAR) as the latest addition.

A New Milestone in Confluent's Trust Journey

Confluent Cloud has successfully achieved an OSPAR attestation. This milestone extends Confluent's existing portfolio of independently audited certifications and gives Singapore's financial institutions a verified, sector-specific assurance point built specifically for outsourced technology arrangements.

For financial institutions evaluating Confluent Cloud for real-time data streaming, this attestation is more than a compliance checkbox. It is independent confirmation that Confluent's governance, risk management, and technical controls meet the standards Singapore's financial sector expects from providers handling regulated, outsourced workloads.

What Is OSPAR, and Why Does It Matter?

OSPAR is a third-party assurance report issued by an authorized service auditor under the “Guidelines on Control Objectives and Procedures for Outsourced Service Providers” established by the Association of Banks in Singapore (ABS). It exists because Singapore's banking regulators expect financial institutions to maintain the same standard of oversight over outsourced technology providers as they do over their own internal systems.

Obtaining an OSPAR attestation is not a self-declared checklist. It requires engaging an auditor that meets ABS's qualification guidelines. These guidelines set the minimum, baseline controls that any outsourced service provider should have in place before serving Singapore's financial institutions. The latest version of the framework, OSPAR v2.0, is organized around three broad control groupings, together spanning a wide set of domains:

  • Entity-Level Controls, covering corporate governance, risk management frameworks, human resources security, and overall organizational compliance.

  • General IT Controls, covering logical security, physical security, change management, incident management, backup and disaster recovery, network and security management, security incident response, data security, cryptography, and software application development and management.

  • Service-Level Controls, covering business continuity management and the maintenance of records that financial institutions can rely on for their own due diligence.

  • Rather than each bank running a separate, bespoke audit of the same vendor, OSPAR gives Singapore's financial institutions a common, independently verified benchmark.

This matters for two reasons:

  • First, it aligns with MAS's outsourcing and technology risk expectations, so a bank's own risk team can point to OSPAR as recognized, sector-specific evidence rather than building a compliance case from scratch. 

  • Second, it shortens due diligence. Instead of lengthy back-and-forth questionnaires ahead of every deal or renewal, a bank's procurement and risk teams can reference an attestation that was designed, from the outset, around what Singapore's financial sector needs to see.

How Confluent Helps Customers Leverage the OSPAR Attestation

Achieving the attestation is only useful if customers can actually put it to work in their own risk and procurement processes. Confluent's approach is to make that as straightforward as possible:

  • On-demand access through the Trust Center: The OSPAR report, alongside SOC 2 Type II, ISO 27001, ISO 27701, and CSA STAR, can be requested through Confluent's Trust Center.

  • Alignment to existing frameworks: Because OSPAR's control domains mirror much of what the MAS Technology Risk Management Guidelines and the MAS Outsourcing Guidelines already expect, customers can use the attestation to support multiple internal review processes rather than treating it as a standalone artifact.

  • Continuous relevance: As Confluent's governance and technical controls evolve, the attestation is maintained as part of the annual review cycle that governs Confluent's other certifications, so the evidence customers rely on stays current rather than becoming a point-in-time artifact.

Singapore's Regulatory Landscape: Why Context Matters

OSPAR does not exist in isolation — it is one part of a broader, layered regulatory environment that Singapore has built around technology infrastructure and outsourcing. Bodies like the Monetary Authority of Singapore (MAS), the Cyber Security Agency of Singapore (CSA), and the Infocomm Media Development Authority (IMDA) each set expectations that extend beyond regulated enterprises to their technology vendors, including cloud service providers.

For any organization running an Apache Kafka® cluster or Apache Flink® pipeline that carries subscriber, transaction, or operational data, this layered regulatory environment is the baseline against which deployment decisions get evaluated. OSPAR is the piece of that landscape that is relevant to banks and other regulated financial institutions evaluating third-party vendors, but it sits alongside a wider set of frameworks spanning financial services, telecommunications, the public sector, and other CII sectors.

To help customers connect the dots between individual frameworks and the regulatory landscape they operate in, Confluent has published a dedicated white paper aligning Singapore's leading frameworks such as the MAS Technology Risk Management Guidelines, the MAS Outsourcing Guidelines, CCoP 2.0, and IM8 directly to the architecture and controls Confluent Cloud provides today.

We encourage teams navigating Singapore's regulatory requirements, whether in financial services, telecommunications, the public sector, or other CII-designated industries, to leverage the whitepaper as a working reference alongside the OSPAR attestation and our commitment to transparency through Confluent's Trust Center.

Trust, Verified

The OSPAR attestation reflects a broader principle behind how Confluent builds and operates Confluent Cloud: trust should be demonstrated through independently audited architecture, not asserted through policy alone. As Singapore's regulatory expectations continue to evolve, Confluent will continue to invest in the certifications, attestations, and documentation that let customers verify that commitment for themselves.

Visit the Confluent Trust Center to request the OSPAR report and access Confluent's full portfolio of certifications and the Singapore Trust white paper.

  • Swati Manocha, APAC Regional Lead for the Office of the CISO at Confluent, drives trust and security initiatives. Her work spans customer trust engagements across strategic and regulated accounts, including security audits, security contract negotiations, and due diligence. By translating evolving regional regulatory requirements into practical programs and customer-focused assurance, Swati helps build confidence in trusted solutions.

  • Alicia Perez leads the Compliance team at Confluent. Her expertise spans customer trust and information security assurance, compliance frameworks (ISO 27001, SOC 2, PCI DSS), security policy development, vendor risk management, and security awareness training. Alicia is dedicated to helping Confluent achieve business goals while maintaining a strong security posture and meeting legal and regulatory obligations.

¿Te ha gustado esta publicación? Compártela ahora