2020-01-01
The Central Bank of Montenegro issued this Decision to mandate specific security measures for operational and information system risks related to payment services. It requires payment service providers to establish robust governance structures, implement comprehensive risk management strategies, and enforce strict controls over logical and physical security, including access management and third-party service oversight. The regulation further obliges providers to maintain detailed internal acts, conduct regular audits, and ensure business continuity through defined development strategies and incident response procedures.