Build1 publisher2 min readPublished
Confluent Cloud gains an OSPAR attestation for Singapore bank outsourcing reviews
Confluent Cloud now holds an OSPAR attestation, adding Singapore's bank-sector audit to the four reports already in its Trust Center. Singapore banks vetting Confluent as an outsourced provider can start from one audit built on the banking association's own control baseline.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- OSPAR is a third-party assurance report, issued by an authorized auditor under the Association of Banks in Singapore's control guidelines for outsourced service providers.
- The current framework, OSPAR v2.0, sorts its baseline controls into three groups: entity-level, general IT, and service-level.
- Confluent says it will maintain the attestation on the same annual review cycle that governs its other certifications.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint A bank still owns oversight of Confluent Cloud, because Singapore's regulators expect outsourced providers to be overseen to the same standard as internal systems; the report is an input to that review.
- cost A bank's vendor review shrinks to reading one report against its own deployment, while Confluent takes on a yearly audit cycle to keep that report current.
- decision A Singapore bank comparing managed streaming vendors can ask for OSPAR up front, since a vendor without one leaves the bank to run its own audit of that vendor.
The idea behind OSPAR is sound. Without a shared report, each bank runs its own bespoke audit of the same vendor, according to Confluent's post [10]. With one, a single audit gives every bank the same evidence. The auditor has to meet the Association of Banks in Singapore's qualification guidelines, and the audit checks a set of baseline controls the association expects of any outsourced provider [5].
Confluent wrote that "this attestation is more than a compliance checkbox" [15]. For a procurement team, a checkbox that one document can tick is most of the value. The company says the report shortens due diligence by replacing the back-and-forth questionnaires that otherwise come before every deal or renewal [12]. It also says a bank's risk team can cite OSPAR as sector-specific evidence that matches MAS outsourcing and technology risk expectations [11].
The control catalogue is broad. The general IT group alone lists ten domains, among them change management, incident management, backup and disaster recovery, and cryptography [8][1]. The service-level group adds business continuity and the records a bank relies on for its own due diligence [9]. For a streaming service carrying a bank's transaction data, I'd expect the bank's architects to read the recovery and change management findings first.
Confluent's due-diligence saving is a claim about a typical buyer [12]. It applies to a particular bank only if the audit covered the Confluent Cloud services and regions that bank will run. The audit period also has to be recent enough for that bank's risk function to accept. The announcement does not name the auditor or the audit period, and it does not list which services and regions were in scope [17]. Banks have to request the report itself through Confluent's Trust Center [3].
Then there is the MAS mapping. "Much" is Confluent's own word for how far OSPAR's control domains overlap the MAS Technology Risk Management and Outsourcing Guidelines [13]. Controls outside that overlap stay on the bank's own review list.
What to watch
- The scope and audit period stated in the OSPAR report itself, once banks request it through the Trust Center.
- Whether Confluent renews the attestation on the annual cycle it describes.
- The next region- or sector-specific framework Confluent adds; it describes OSPAR as the latest in that series.