Policy Updates
Tanzania’s Draft Cloud Computing Guidelines for Financial Service Providers
By Veronica Shiroya
The Bank of Tanzania has released new Cloud Computing Guidelines for Financial Service Providers, setting out strict conditions for how banks and other regulated institutions can adopt cloud solutions. Issued under the Banking and Financial Institutions Act, 2006 and the National Payment Systems Act, 2015, the rules aim to balance innovation with cybersecurity, data protection and financial stability.
Mission-critical systems MUST stay in Tanzania
The guidelines draw a sharp line between mission-critical and non-mission-critical systems.
Mission-critical systems such as databases, applications, or processes essential to business survival must be hosted within Tanzania. Outsourcing these to foreign-based data centers or cloud providers is prohibited.
Non-mission-critical systems, which support auxiliary functions, may be hosted on the cloud but only with prior approval from the Bank.
The guidelines require that every cloud contract must be reviewed and approved by the Bank before implementation. Contracts must include clear Service Level Agreements, oversight and monitoring provisions, third-party audit rights and the Bank’s right to access data and reports at any time. They must also outline exit strategies in case of insolvency, disputes, or service failures and provide business continuity measures such as redundancy and backup systems. Financial institutions are also required to conduct annual reviews of their providers’ financial and operational stability to ensure ongoing compliance.
Financial service providers are obligated to establish a cloud computing policy, to be submitted to the Bank before implementation. The policy must designate internal oversight responsibilities, outline dispute resolution and data recovery mechanisms, ensure periodic due diligence on service providers and include contingency planning and clearly defined exit strategies. The goal is to ensure that financial institutions remain accountable for risk management even when outsourcing critical processes.
To enforce compliance, the Bank of Tanzania has introduced a series of sanctions ranging from civil monetary penalties to suspensions of cloud operations, credit facilities, lending and investment activities. In more severe cases, directors or officers responsible for non-compliance may face suspension or disqualification and institutions may ultimately risk license revocation.
Why it matters
The new framework underscores Tanzania’s effort to embrace cloud innovation without compromising financial stability or data sovereignty. By requiring mission-critical systems to remain local, the central bank signals a cautious but strategic approach to cloud adoption in the financial sector.