2019-01-21

Added · Updated

Circular on Amendments to Instructions on IT Governance and Management (No. 65/2016)

The Central Bank amends the IT Governance and Management Instructions (No. 65/2016) to align with the COBIT 2019 framework, replacing specific Annex matrices and definitions with COBIT 2019 goals and objectives. Licensed banks must ensure that activities related to high-priority focus areas, such as cyber security and risk management, reach a maturity level of at least 3 by the end of 2019. The amendments also permit foreign bank branches to merge IT Governance Committee tasks with existing committees and allow the IT Governance Committee to adopt auditor reports provided the Board of Directors is informed.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view thumbnail

10/6/984 15/5/1440 AH 21/1/2019 AD

Circular to Licensed Banks

In light of feedback regarding completion reports, requests, and inquiries received by the Central Bank concerning the implementation of the IT Governance and Management Instructions and their accompanying guidelines, No. (65/2016) dated 25/10/2016 (the Instructions), and referring to Article (3/w) thereof, and keeping pace with developments and updates to the proposed international frameworks in this regard, specifically the Reference Framework (COBIT 2019) issued by the Information Systems Audit and Control Association (ISACA) at the end of 2018, the following amendments have been decided for the aforementioned Instructions:

First: The following definition is added to Article (2) (Definitions): Auditor: The person (natural or legal) or the competent authority responsible for examining the Bank's operations based on information technology, in accordance with the requirements of the Instructions in this regard and agreed upon by the Bank's management to achieve those requirements for a period of not less than 3 consecutive years and not more than 6 consecutive years.

Second: Foreign bank branches are permitted to incorporate the tasks of the IT Governance Committee into the tasks of the IT Steering Committee or into the tasks of a local committee formed to act in place of the aforementioned Governance Committee.

Third: The IT Governance Committee or the committee acting in its place is permitted to adopt the reports of the internal and external auditors, provided that the Board of Directors is informed of those reports.

Fourth: The (Enterprise Goals) contained in the (COBIT 2019) framework replace the Enterprise Goals Matrix contained in Annex (1) of the Instructions.

Fifth: The (Alignment Goals) contained in the (COBIT 2019) framework replace the Information and Technology Goals Matrix accompanying it in Annex (2) of the Instructions.

Sixth: The (Governance and Management Objectives) contained in the (COBIT 2019) framework replace the IT Governance Processes contained in Annex (3) of the Instructions, and are terminologically named and replaced as "Governance and Management Objectives" wherever mentioned in the Instructions.

Seventh: The IT Governance Committee, in addition to its tasks stipulated in the Instructions, is responsible for adopting the importance and priority ranking of the objectives mentioned in Sixth, and their linkage to the objectives mentioned in Fourth and Fifth above, as well as their linkage to the remaining six Enablers (or Components) mentioned in the Instructions. This is based on a qualitative and/or quantitative study prepared for this purpose at least annually, taking into account the (Design Factors) contained in (COBIT 2019 – Design Guide).

Eighth: The objectives mentioned in Sixth above and the remaining six Enabler components related to activities concerning cyber security, risk management, data privacy and protection, compliance, monitoring, auditing, and strategic alignment are considered (Focus Areas) of highest importance and priority.

Ninth: The maturity level (Capability Level) of activities related to the objectives mentioned in Sixth above and the remaining six Enablers (or Components) associated with them and mentioned in the Instructions must be directly proportional to the degree of importance and priority according to the results of the study referred to in Seventh above. The maturity level (Capability Level) for activities related to objectives of highest importance and priority must not be less than Level (3) (Fully Achieved) according to the maturity scale in the (COBIT 2019) framework by the end of the current year 2019 at the latest. Up to (26%) of the objectives mentioned in Sixth above may be considered within Management Objectives (not exceeding 9 objectives at most out of 35 objectives) as having lower or negligible importance and priority, depending on the results of the study referred to in Seventh above.

Tenth: It is optional for the Bank to target reaching maturity levels higher than Level (3) (Fully Achieved) according to the (COBIT 2019) framework. In the event that higher maturity levels are achieved, the Central Bank will view this positively when reviewing related requests submitted by banks.

Eleventh: The text of Article (3/h) of the Instructions is repealed.

Twelfth: The amendments made are reversed, and the updating and publication of the IT Governance and Management Guide continue in accordance with Articles (4 and 5) of the Instructions.

Thirteenth: Continue providing us with the completion report in accordance with Article (3/t) of the Instructions until the completion of all items of the Instructions.

Please accept our highest respect and appreciation,

The Governor Dr. Ziad Fariz