2025-08-29

Regulation on Information Systems and Cyber Risk Management

The Central Bank of the Republic of Kosovo issued this regulation to establish minimum standards and procedures for information technology and cyber risk management across all licensed financial institutions. It mandates comprehensive governance structures, robust risk assessment frameworks, and strict controls for third-party providers, cloud computing, and artificial intelligence applications. Financial institutions must implement continuous monitoring, timely incident reporting, and operational resilience measures to ensure secure, reliable, and compliant critical financial operations.

Central Bank of the Republic of Kosovo logo

Kosovo

Central Bank of the Republic of Kosovo

Click to view full text