2024-09-16
Added · Updated
The Banco de Portugal establishes supervisory expectations for credit institutions regarding the suitability of board members and key ICT, security, and risk management personnel. It mandates that executive members responsible for ICT and risk management possess at least three years of relevant professional experience and appropriate academic qualifications. Institutions must ensure collective board competence in ICT risks, maintain independent second-line defense functions, and implement continuous training programs, with performance indicators potentially linked to variable remuneration. These requirements apply to credit institutions, excluding specific agricultural credit entities, and are enforced through ongoing supervisory assessments.