2020-06-16 | NBB_2020_23Added · Updated
This circular implements the European Banking Authority Guidelines on ICT and security risk management (EBA/GL/2019/04) into Belgian supervisory practice, applying from 30 June 2020. It mandates that credit institutions, stockbroking firms, payment institutions, electronic money institutions, and relevant holding companies establish sound ICT and security risk management arrangements in compliance with the Banking Law of 25 April 2014 and the Payment Services Law of 11 March 2018. The document replaces Circular NBB_2018_13 and requires adherence to specific provisions regarding governance, information security, ICT operations, and business continuity. It also clarifies that these requirements apply on a consolidated basis to Belgian parent credit institutions and holding companies.
Boulevard de Bedaimont 14-BE-1000 Brussels Phone +32 2 221 48 66 Company number: 0203. 201. 340 RPM (Trade Register) Bmssels www. nbb. be rtl BanqueNatipnaleBank DEBELCIQUE VAN BELGtE Eurosystem Circular Brussels, 16 June 2020 Reference: Contact person: Thomas Plomteux Phone +32 2 221 21 97 thomas. plomteux@nbb. be NBB 2020 23 European Banking Authority (EBA) Guidelines of 29 November 2019 on ICT1 and security risk management (EBA/GL/2019/04) . Credit institutions and stockbroking firms governed by Belgian law; . branches established in Belgium of credit institutions and stockbroking firms governed by the law of a non-EEA Member State; . payment institutions and electronic money institutions governed by Belgian law; . branches established in Belgium of payment institutions and electronic money institutions governed by the law of a non-EEA Member State2: . in the context of consolidated supervision, group supen/ision or supplementary conglomerate supervision, financial holding companies and mixed financial holding companies. Summarv/Obiectives This Circular implements the Guidelines of the European Banking Authority (hereinafter referred to as the "EBA") on ICT and security risk management (EBA/GL/2019/04)3 and applies from 30 June 2020. This Circular replaces Circular NBB_2018_13, which ceases to apply from that date. 1 Information and communication technology. 2 Assuming that the legal provision of which the content is specified here is made applicable to the branches concerned. 3 httDs://eba. euroDa. eu/requlation-and-policv/intemal-aovemance/Quidelines-on-ict-and-securitv-risk-management. NBB 2020 23 - 16062020 Circular - Page 1/3
m Dear Sir, Dear Madam,
m 2. Clarifications on the scope and implementation When referring to "financial institutions", the EBA Guidelines and this Circular apply to: . payment service providers (payment institutions, electronic money institutions and credit institutions) with respect to the provision of payment services; . credit institutions with respect to any of their activities other than payment services; . stockbroking firms with respect to any of their activities. Some provisions and clarifications in the Guidelines are aimed exclusively at payment service providers, credit institutions or "investment firms", For the scope of this Circular, "investment firms" should be read as stockbroking firms. This Circular applies from 30 June 2020 and replaces Circular NBB_2018_13, which is repealed from that date. The EBA Guidelines should be read and applied in conjunction with the provisions of the following Circulars: . Circular NBB_2019_19, which defines the general expectations regarding outsourcing for this scope; » Circular NBB_2015_32, which applies specifically to systemically important financial institutions; . Circular CBFA_2009_17, which includes additional provisions for offering financial services (excluding payment services) via the Internet (inter alia for credit institutions and stockbroking firms); . Circular PPB 2005/2, which includes additional provisions for business continuity management (inter alia for credit institutions and stockbroking firms); . Circular NBB_2019_09, which establishes the reporting on operational and security risks of payment services to be submitted by credit institutions and branches of credit institutions; . Circular NBB_2020_24, which establishes the reporting on operational and security risks of payment services to be submitted by payment institutions and electronic money institutions. A copy of this Circular will be sent to your institution's accredited statutory auditor(s). Yours faithfully, NBB 2020 23 - 16062020 Circular - Page 3/3