AI Briefing
KO

Financial Cloud Guide A to Z Part 2 – R&D Network Exceptions and the Network Separation Improvement Roadmap

·2026.07.23 12:23

Key point

Following the 2024 Network Separation Improvement Roadmap, this guide walks financial companies step by step through safely implementing R&D networks using an AWS multi-account architecture.

Details

The network separation regulation enforced in 2013 was a cornerstone of financial security, but it made it practically impossible for developers to use external open source or cloud AI services. The 'Network Separation Improvement Roadmap for the Financial Sector' announced by the Financial Services Commission in August 2024 permits logical network separation for R&D networks and opens the way for generative AI and SaaS adoption.

A R&D network is a development system network configured independently from the internal business network, data center, and external network for the research and development of financial services. The major changes since the improvement roadmap are as follows.

  • Logical network separation allowed: Relaxation of the existing physical separation requirement
  • Internal deployment of source code allowed: R&D outputs can be brought into the internal network
  • Use of pseudonymized information allowed: Pseudonymized data can be used for R&D purposes
  • Remote work for IT developers allowed: Remote access permitted under security controls

In the AWS environment, a multi-account + AWS Control Tower configuration is recommended. By adding an R&D OU to an existing Organization and separating a dedicated account for the R&D network, network, IAM, and cost boundaries are naturally formed. This is a way of satisfying the regulatory requirement of an 'independently configured development system network' through an AWS multi-account strategy.

Building an R&D network must go through a 4-step process: ① determining the scope of use → ② conducting a self-risk assessment → ③ applying information security controls → ④ deliberation and resolution by the Information Security Committee.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.