2023-09-17 | 31816Added · Updated
The Central Bank of Trinidad and Tobago amended its Cybersecurity Best Practices Guideline to require licensed and registered institutions to conduct annual self-assessments and submit them by March 31st of each year. The revisions clarify that the self-assessment must be signed by the Chief Executive Officer or a designated approved officer, such as the CISO or CCO, and include detailed action plans for material deficiencies. While the guideline remains compulsory for regulated entities, it explicitly excludes non-regulated institutions from reporting requirements and allows the frequency of independent third-party reviews to be determined by the institution based on its risk profile.