2026-06-17
Added
The Banking Supervision Department amends Proper Conduct of Banking Business Directive No. 367 to align with Proper Conduct of Banking Business Directive No. 364, replacing references to repealed Directives 357 and 361. The term "acquirer" in Section 7 is replaced with "a payment service provider with prudential importance license holder, as defined in Section 36i of the Law, and its controlled entities." Section 27 is repealed as its provisions were previously removed, and the corresponding subsection heading is updated to "Online Account Designation and Monitoring." These amendments apply to banking corporations and payment services providers with prudential importance license holders and take effect on the date of publication.
Banking Supervision Department Technology, Innovation, and Cyber Division Banking Technology Unit June 17, 2026 Circular-C-06-2847 Attn: The banking corporations and payment services providers with prudential importance license holders Re: E-banking (Proper Conduct of Banking Business Directive No. 367) Introduction On November 18, 2024, the Banking Supervision Department published Proper Conduct of Banking Business Directive No. 364, titled “Management of Information Technology Risks, Information Security and Cyber Protection” (hereinafter: “Directive 364”). Pursuant to Circular 06 No. 2799, which accompanied the publication of the Directive, Directive 364 entered into force on May 18, 2026 and repealed, inter alia, Proper Conduct of Banking Business Directive No. 357, titled “Information Technology Management” (hereinafter: “Directive 357”), and Proper Conduct of Banking Business Directive No. 361, titled “Cyber Defense Management” (hereinafter: “Directive 361”). This circular includes the amendments required to Directive 367 following the entry into force of Directive 364. 2. The regulation was not accompanied by the publication of a Regulatory Impact Assessment (RIA) under the Principles of Regulation Law, 5782-2021 (hereinafter in this section: the “Law”), in accordance with Section 34(c)(2) of the Law, as the direct and indirect impacts expected to result from the regulation on the entities to which it applies, including compliance costs, are not material. The regulation will be subject to an ex post review pursuant to Section 36 of the Law, 10 years after its effective date. 3. Following consultation with the Advisory Committee on Banking Business Affairs and with the approval of the Governor, I have decided to amend Proper Conduct of Banking Business Directive No. 367, titled “E-banking Services.” Amendments to the Directive 4. Introduction Section 3 References to Directive 357 and Directive 361 have been replaced with a reference to Directive 364. No substantive changes have been made to the requirements set forth in this section.
More like this from BOI
We email you every new BOI publication the day it's published.