2025-11-24

Added · Updated

Circular No. 03/EFI/2025, of November 19 – Cyber Risk Self-Assessment

The Bank of Mozambique mandates credit institutions and financial companies to conduct an annual cyber risk self-assessment and submit a completed report alongside a remediation plan detailing corrective measures, deadlines, and responsible parties by March 31. The directive establishes a standardized reporting model via the Banking Supervision Application portal, with fallback email procedures for operational disruptions, and requires institutions to evaluate intrinsic risk across organizational, technological, channel, product, and threat categories. Compliance is measured against a nine-domain framework covering governance, identification, protection, detection, response, awareness, testing, outsourcing, and learning, with responses categorized from fully compliant to non-compliant.

Banco de Mocambique logo

Mozambique

Banco de Mocambique

Scan of the document's first page
Share

Get BM alerts — same-day email on every new publication.

Read the rest free

Lineage: In force

Notice No. 2/GBM/2024, of 15 Ma…2024Notice No. 2/GBM/2024, of 15 March – Approves Cyber Risk Management and Resilience Guidelines (2024-03-15)GBM Notice No. 2 dated 2024-03-…GBM Notice No. 2 dated 2024-03-15Circular No. 03/EFI/2025, ofNovember 19 – Cyber Risk Self…2025-11-24 · this documentCircular No. 03/EFI/2025, of November 19 – Cyber Risk Self-Assessment (2025-11-24)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Banco de Mocambique — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from BM

We email you every new BM publication the day it's published.

Topics