2020-06-16 | NBB_2020_23Added · Updated
This circular implements the European Banking Authority Guidelines on ICT and security risk management (EBA/GL/2019/04) into Belgian supervisory practice, applying from 30 June 2020. It mandates that credit institutions, stockbroking firms, payment institutions, electronic money institutions, and relevant holding companies establish sound ICT and security risk management arrangements in compliance with the Banking Law of 25 April 2014 and the Payment Services Law of 11 March 2018. The document replaces Circular NBB_2018_13 and requires adherence to specific provisions regarding governance, information security, ICT operations, and business continuity. It also clarifies that these requirements apply on a consolidated basis to Belgian parent credit institutions and holding companies.