Featured Product

    EBA Publishes Guidelines on ICT and Security Risk Management

    November 28, 2019

    EBA published the final guidelines on the mitigation and management of information and communication technology (ICT) and security risks for banks in EU. The guidelines set out expectations on the way in which all financial institutions should manage their internal and external ICT and security risks. The guidelines provide financial institutions with a better understanding of supervisory expectations for the management of these risks, covering sound internal governance, information security requirements, ICT operations, project and change management, and business continuity management. The guidelines, which apply to credit institutions, investment firms, and payment service providers, enter into force on June 30, 2020.

    These guidelines respond to the EC's FinTech Action plan request for EBA to develop guidelines on ICT risk management and mitigation requirements in the financial sector in EU. The guidelines:

    • Focus on the management and mitigation of ICT and security risks by establishing sound internal governance and an internal control framework that sets clear responsibilities for the staff of financial institutions, including for the management bodies
    • Require financial institutions to maintain up-to-date inventories of their business functions, supporting processes and information assets and to classify them in terms of criticality, based on the confidentiality, integrity, and availability of data
    • Remind financial institutions to ensure the effectiveness of the risk-mitigating measures, as defined by their risk management framework, when outsourcing or using third-party providers
    • Specify high-level principles on how ICT operations should be managed, including requirements to improve, when possible, the efficiency of ICT operations; implement logging and monitoring procedures for critical ICT operations; maintain an up-to-date inventory of their ICT assets; monitor and manage the life cycle of ICT assets; and implement backup plans and recovery procedures
    • Specify expectations on business continuity management and developing response and recovery plans, including testing, and their consequent updating based on the test results
    • Cover the management of relationship of payment service providers with payment service users to ensure that users are made aware of the security risks linked to the payment services and are provided with the tools to disable specific payment functionalities and monitor payment transactions

    In implementing these guidelines, financial institutions should refer to the existing standards and leading best practices. These guidelines intend to be technology and methodology agnostic. The implementation of these guidelines should be done in accordance with the principle of proportionality, taking into account the scale and complexity of operations, the nature of the activity engaged in, the types of services provided, and the corresponding ICT and security risks related to the processes and services of financial institutions. These guidelines complement, and should be read in conjunction with, the supervisory assessment to the applicable institutions in EBA guidelines on ICT risk assessment under the Supervisory Review and Evaluation Process (EBA/GL/2017/05) and other relevant guidelines such as EBA guidelines on outsourcing arrangements (EBA/GL/2019/02). 

     

    Related Links

    Effective Date: June 30, 2020

    Keywords: Europe, EU, Banking, CRD, PSD 2, ICT Risk, Cyber Risk, Proportionality, Operational Risk, Outsourcing Arrangements, Third-Party Arrangements, Fintech, EBA

    Featured Experts
    Related Articles
    News

    EBA Proposes Guidelines for Establishing Intermediate Parent Entities

    EBA issued a consultation paper on the guidelines on monitoring of the threshold and other procedural aspects of the establishment of intermediate EU parent undertakings, or IPUs, as laid down in the Capital Requirements Directive.

    January 15, 2021 WebPage Regulatory News
    News

    EC Adopts Financial Reporting Changes Arising from Benchmark Reforms

    EC published Regulation 2021/25 that addresses amendments related to the financial reporting consequences of replacement of the existing interest rate benchmarks with alternative reference rates.

    January 14, 2021 WebPage Regulatory News
    News

    BIS Bulletin Examines Key Elements of Policy Response to Cyber Risk

    BIS published a bulletin, or a note, that examines the cyber threat landscape in the context of the pandemic and discusses policies to reduce risks to financial stability.

    January 14, 2021 WebPage Regulatory News
    News

    HMT Updates List of Post-Brexit Equivalence Decisions in UK

    HM Treasury, also known as HMT, has updated the table containing the list of the equivalence decisions that came into effect in UK at the end of the transition period of its withdrawal from EU.

    January 14, 2021 WebPage Regulatory News
    News

    EBA Issues Erratum for Technical Package on Reporting Framework 3.0

    EBA published an erratum for technical package on phase 1 of the reporting framework 3.0.

    January 14, 2021 WebPage Regulatory News
    News

    APRA Publishes FAQ on Measurement of Credit Risk Weighted Assets

    APRA updated a frequently asked question (FAQ), for authorized deposit-taking institutions, on the measurement of credit risk weighted assets.

    January 14, 2021 WebPage Regulatory News
    News

    EBA Publishes Risk Dashboard for Third Quarter of 2020

    EBA published the quarterly risk dashboard, along with the results of the Risk Assessment Questionnaire survey among 60 banks and 15 market analysts.

    January 13, 2021 WebPage Regulatory News
    News

    ECB Analysis Shows Privacy as Biggest Concern in Use of Digital Euro

    ECB concluded the public consultation on the introduction of a digital euro in EU.

    January 13, 2021 WebPage Regulatory News
    News

    ECB Analysis Shows Privacy as Biggest Concern in Use of Digital Euro

    ECB concluded the public consultation on the introduction of a digital euro in EU.

    January 13, 2021 WebPage Regulatory News
    News

    ECB Finalizes Guide on Supervisory Approach to Bank Consolidation

    ECB published a guide that sets out the supervisory approach to consolidation in the banking sector.

    January 12, 2021 WebPage Regulatory News
    RESULTS 1 - 10 OF 6432