2021-03-17 | 4/POJK.05/2021Added
Financial Services Authority Regulation No. 4/POJK.05/2021 mandates Non-Bank Financial Service Institutions (LJKNB) to implement effective information technology risk management, including active oversight by the Board of Directors and Board of Commissioners, adequate policies and procedures, and internal control systems. Institutions with total assets exceeding IDR 1 trillion must establish an IT Steering Committee. The regulation requires LJKNBs to maintain disaster recovery plans, ensure information security, and conduct regular internal audits of IT operations.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA
COPY
FINANCIAL SERVICES AUTHORITY REGULATION
REPUBLIC OF INDONESIA
NUMBER 4 /POJK.05/2021
CONCERNING
THE IMPLEMENTATION OF RISK MANAGEMENT IN THE USE OF INFORMATION TECHNOLOGY BY NON-BANK FINANCIAL SERVICE INSTITUTIONS BY THE GRACE OF GOD THE ALMIGHTY THE COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY,
Considering:
a. that in order to implement the regulatory and supervisory duties in the non-bank financial service institution sector as referred to in Article 8 and Article 9 of Law Number 21 of 2011 concerning the Financial Services Authority, the Financial Services Authority has the authority to establish regulations governing non-bank financial service institutions; b. that the utilization of information technology can increase the effectiveness and efficiency of operational activities and the quality of service provided by non-bank financial service institutions to consumers, but at the same time can increase risks for non-bank financial service institutions, so that the implementation of information technology risk management is necessary;
c. that for the integration of regulations regarding information technology risk management applicable to non-bank financial service institutions, it is necessary to establish regulations regarding information technology risk management;
d. that based on the considerations as referred to in letters a, b, and c, it is necessary to establish a Financial Services Authority Regulation concerning the Implementation of Risk Management in the Use of Information Technology by Non-Bank Financial Service Institutions;
Recalling:
DECIDING:
Establishing: FINANCIAL SERVICES AUTHORITY REGULATION CONCERNING THE IMPLEMENTATION OF RISK MANAGEMENT IN THE USE OF INFORMATION TECHNOLOGY BY NON-BANK FINANCIAL SERVICE INSTITUTIONS.
CHAPTER I
GENERAL PROVISIONS
Article 1
In this Financial Services Authority Regulation, the following terms are defined as:
Non-Bank Financial Service Institution, hereinafter referred to as LJKNB, is an institution that carries out activities in the insurance sector, pension funds, financing institutions, and other financial service institutions.
Information Technology is a technique to collect, prepare, store, process, announce, analyze, and/or disseminate information.
Electronic Financial Service is a service for consumers to obtain information, communicate, and conduct financial transactions through electronic media.
Information Technology-Based Transaction Processing is an activity consisting of adding, changing, deleting, and/or authorizing data carried out on application systems used to process transactions.
Electronic System is a series of electronic devices and procedures that function to prepare, collect, process, analyze, store, display, announce, send, and/or disseminate electronic information.
Data Center is a facility used to place Electronic Systems and related components for the purpose of placement, storage, and data processing.
Disaster Recovery Center is a facility used to restore data or information and important functions of Electronic Systems that are disrupted or damaged due to disasters caused by nature or humans.
Database is a comprehensive set of data arranged systematically, accessible by users according to their respective authorities and managed by the Database Administrator.
Disaster Recovery Plan is a document containing plans and steps to replace and/or restore access to data, hardware, and software required, so that LJKNB can carry out critical business operational activities after disruptions and/or disasters.
Board of Directors is a corporate organ authorized and fully responsible for the management of the corporation for the interests of the corporation, in accordance with the purpose and objectives of the corporation and representing the corporation, both inside and outside of court, in accordance with the articles of association for LJKNB in the form of a limited liability company or equivalent to the Board of Directors for LJKNB in the form of a cooperative, joint venture, pension fund, Indonesian Export Financing Institution, social security implementing body, or limited partnership.
Board of Commissioners is a corporate organ tasked with carrying out general and/or specific supervision in accordance with the articles of association and providing advice to the Board of Directors for LJKNB in the form of a limited liability company or equivalent to the Board of Commissioners for LJKNB in the form of a cooperative, joint venture, pension fund, Indonesian Export Financing Institution, social security implementing body, or limited partnership.
Article 2
LJKNB as referred to in Article 1 number 1 includes:
a. insurance companies, consisting of:
CHAPTER II
SCOPE OF INFORMATION TECHNOLOGY RISK MANAGEMENT
Article 3
(1) LJKNB is required to implement risk management effectively in the use of Information Technology.
(2) The implementation of risk management as referred to in paragraph (1) covers at least:
a. active supervision by the Board of Directors and Board of Commissioners; b. adequacy of policies and procedures for the use of Information Technology;
c. adequacy of processes for identifying, measuring, controlling, and monitoring the risks of using Information Technology; and
d. internal control systems over the use of Information Technology.
(3) The implementation of risk management as referred to in paragraph (1) is carried out in an integrated manner in every stage of the use of Information Technology from the planning, procurement, development, operation, maintenance stages until the cessation and deletion of Information Technology resources. (4) The implementation of risk management in the use of Information Technology for financial institution pension funds can be combined with the implementation of risk management in the use of Information Technology by the founder.
Article 4
The implementation of risk management in the use of Information Technology as referred to in Article 3 must be adjusted to the objectives, business policies, size, and complexity of the LJKNB's business.
CHAPTER III
ACTIVE SUPERVISION BY THE BOARD OF DIRECTORS AND BOARD OF COMMISSIONERS
Article 5
LJKNB is required to establish clear authorities and responsibilities of the Board of Directors, Board of Commissioners, and officials at every level of position related to the use of Information Technology.
Article 6
The authorities and responsibilities of the Board of Directors as referred to in Article 5 cover at least:
a. establishing plans for the development of Information Technology and LJKNB policies related to the use of Information Technology; b. establishing policies and procedures related to the implementation of Information Technology that are adequate and communicating them effectively, both to the implementing work units and users of Information Technology;
c. ensuring:
Article 7
The authorities and responsibilities of the Board of Commissioners as referred to in Article 5 cover at least:
a. evaluating, directing, and monitoring plans for the development of Information Technology and LJKNB policies related to the use of Information Technology; and b. evaluating the accountability of the Board of Directors regarding the implementation of risk management in the use of Information Technology.
Article 8
(1) LJKNB having total assets of more than IDR 1,000,000,000,000.00 (one trillion rupiah) is required to have an Information Technology Steering Committee.
(2) The Information Technology Steering Committee as referred to in paragraph (1) is responsible for providing recommendations to the Board of Directors regarding at least:
a. plans for the development of Information Technology that are in line with LJKNB's business activities; b. the formulation of Information Technology policies and procedures;
c. the conformity of approved Information Technology projects with the plans for the development of Information Technology;
d. the conformity of the implementation of Information Technology projects with the approved Information Technology projects; e. the conformity of Information Technology with the needs of management information systems and the needs of LJKNB's business activities; f. the effectiveness of risk mitigation over LJKNB's investments in the Information Technology sector so that LJKNB's investments in the Information Technology sector contribute to the achievement of LJKNB's business objectives; g. monitoring of Information Technology performance and efforts to improve Information Technology performance; h. efforts to resolve various Information Technology-related problems that cannot be resolved effectively, efficiently, and on time by the work units of users and implementers of Information Technology; and
i. the adequacy and allocation of Information Technology resources owned by LJKNB.
(3) The Information Technology Steering Committee as referred to in paragraph (1) consists of at least:
a. a director who oversees the work unit implementing Information Technology; b. a director or official who oversees the risk management function;
c. the highest official who oversees the work unit implementing Information Technology; and
d. the highest official who oversees the work unit using Information Technology.
(4) The calculation of total assets as referred to in paragraph (1) uses information on total assets contained in the latest periodic reports submitted to the Financial Services Authority in accordance with the provisions of Financial Services Authority regulations regarding monthly reports and/or the conduct of business of each LJKNB at the time of the implementation of this Financial Services Authority Regulation for the respective LJKNB. (5) In the event of a decrease in assets, LJKNB remains required to fulfill the provisions as referred to in paragraph (1).
CHAPTER IV
ADEQUACY OF POLICIES AND PROCEDURES FOR THE USE OF INFORMATION TECHNOLOGY
Article 9
(1) LJKNB is required to have policies and procedures for the use of Information Technology as referred to in Article 3 paragraph (2) letter b.
(2) LJKNB is required to apply the policies and procedures for the use of Information Technology as referred to in paragraph (1) consistently and continuously.
(3) Policies and procedures for the use of Information Technology contain at least aspects of:
a. management; b. development and procurement;
c. Information Technology operations;
d. communication networks; e. information security; f. Disaster Recovery Plans; g. the use of Information Technology service providers; and h. Electronic Financial Services, for LJKNB that provide Electronic Financial Services. (4) LJKNB is required to establish risk limits that can be tolerated to ensure that aspects related to Information Technology as referred to in paragraph (3) can run optimally. (5) LJKNB is required to conduct periodic reviews and updates of the policies and procedures as referred to in paragraph (2). (6) LJKNB is required to establish the review and update period for the policies and procedures as referred to in paragraph (5) in written policies.
Article 10
(1) LJKNB is required to submit plans for the development of Information Technology that support LJKNB's business activity plans to the Financial Services Authority. (2) Plans for the development of Information Technology as referred to in paragraph (1) are part of the policies and management plans in LJKNB's business plans. (3) The obligation to submit plans for the development of Information Technology as referred to in paragraph (1) only applies to LJKNB required to submit business plans to the Financial Services Authority.
CHAPTER V
ADEQUACY OF PROCESSES FOR IDENTIFICATION, MEASUREMENT, CONTROL, AND MONITORING OF RISKS IN THE USE OF INFORMATION TECHNOLOGY
Article 11
(1) LJKNB is required to have policies and procedures in conducting processes for the identification, measurement, control, and monitoring of risks in the use of Information Technology as referred to in Article 3 paragraph (2) letter c. (2) LJKNB is required to conduct identification, measurement, control, and monitoring of risks in the use of Information Technology in accordance with the policies and procedures as referred to in paragraph (1). (3) The processes for identification, measurement, control, and monitoring of risks in the use of Information Technology as referred to in paragraph (2) are conducted at least on aspects related to Information Technology as referred to in Article 9 paragraph (3). (4) In the event that LJKNB uses Information Technology service providers, LJKNB is required to ensure that Information Technology service providers implement risk management as regulated in this Financial Services Authority Regulation.
Article 12
(1) In conducting Information Technology development, LJKNB is required to take control steps to produce systems that support:
a. the achievement of LJKNB's objectives; and b. the maintenance of data confidentiality and integrity.
(2) Control steps as referred to in paragraph (1) cover at least:
a. establishing and applying consistent methodologies and procedures for the development and procurement of Information Technology; b. applying project management in the development and procurement of systems;
c. conducting adequate testing in the development and procurement of a system, including joint testing with user work units, to ensure the accuracy and functionality of the system according to user needs and the compatibility of one system with another;
d. documenting the development, procurement, and maintenance of Information Technology systems; e. having Information Technology system change management; f. ensuring that LJKNB's Information Technology systems are able to display information completely; and g. ensuring the creation of written agreements for software in the event that the software affects the continuity of LJKNB's operations and is created by third parties.
Article 13
LJKNB is required to ensure the continuity and stability of Information Technology operations and mitigate risks that could potentially disrupt LJKNB's operational activities.
Article 14
LJKNB is required to provide communication networks that meet the principles of confidentiality, integrity, and availability.
Article 15
For LJKNB that have sharia business units or sharia units, they are required to have systems that can generate separate reports for sharia business unit or sharia unit activities.
Article 16
(1) LJKNB is required to have a Disaster Recovery Plan.
(2) LJKNB is required to ensure that the Disaster Recovery Plan as referred to in paragraph (1) can be implemented effectively so that LJKNB's operational continuity continues during disasters and/or disruptions to the Information Technology facilities used by LJKNB. (3) LJKNB is required to conduct tests on the Disaster Recovery Plan as referred to in paragraph (1) on all core applications and critical infrastructure according to the results of impact analysis periodically by involving Information Technology user work units. (4) LJKNB is required to conduct reviews of the Disaster Recovery Plan as referred to in paragraph (1) periodically. (5) LJKNB is required to establish the testing period as referred to in paragraph (3) and review period as referred to in paragraph (4) in written policies.
Article 17
LJKNB is required to ensure that information security is implemented effectively by considering at least:
a. information security aimed at ensuring that managed information maintains confidentiality, integrity, and availability effectively and efficiently by considering regulatory provisions; b. information security conducted on technological aspects, human resources, and processes in the use of Information Technology;
c. information security applied based on the results of risk assessments on the information owned by LJKNB; and
d. the availability of incident management management in Information security.
CHAPTER VI
INTERNAL CONTROL SYSTEMS OVER THE USE OF INFORMATION TECHNOLOGY
Article 18
(1) LJKNB is required to implement internal control systems as referred to in Article 3 paragraph (2) letter d effectively on all aspects of the use of Information Technology. (2) Internal control systems as referred to in paragraph (1) contain at least:
a. management supervision; b. risk identification and assessment;
c. control activities and segregation of functions;
d. information systems, accounting systems, and communication systems; and e. monitoring activities and correction of deviations carried out by:
Article 19
(1) LJKNB is required to ensure the availability of audit trails for all Information Technology implementation activities for the purposes of supervision, law enforcement, dispute resolution, verification, testing, and other examinations in the implementation of the internal audit function as referred to in Article 18 paragraph (4) letter b. (2) The implementation of the internal audit function as referred to in Article 18 paragraph (4) letter b can be carried out by external auditors or LJKNB group internal auditors. (3) LJKNB is required to conduct periodic internal audits on all aspects in the implementation and use of Information Technology according to the results of Information Technology risk analysis, priorities, and needs. (4) LJKNB is required to establish the implementation period for internal audits as referred to in paragraph (3) in written policies.
Article 20
(1) LJKNB is required to have internal audit guidelines for the use of Information Technology implemented by LJKNB itself and/or by Information Technology service providers. (2) LJKNB is required to conduct periodic reviews of the internal audit function in the use of Information Technology. (3) LJKNB is required to establish the review period as referred to in paragraph (2) in written policies.
CHAPTER VII
IMPLEMENTATION OF INFORMATION TECHNOLOGY BY LJKNB AND/OR INFORMATION TECHNOLOGY SERVICE PROVIDERS
First Section
General Provisions
Article 21
(1) The implementation of Information Technology by LJKNB can be done independently and/or using Information Technology service providers.
(2) In the event that the implementation of LJKNB's Information Technology is carried out by Information Technology service providers as referred to in paragraph (1), LJKNB is required to:
a. be responsible for the implementation of risk management; b. have a work unit implementing Information Technology;
c. supervise the implementation of LJKNB activities carried out by Information Technology service providers;
d. selecting the Information Technology service provider based on cost-benefit analysis by involving the Information Technology organizer work unit; e. monitoring and evaluating the reliability of the Information Technology service provider periodically regarding performance, provider reputation, and continuity of service provision; f. providing access to internal auditors, external auditors, group internal auditors of Nonbank Financial Service Institutions (LJKNB), and/or the Financial Services Authority (OJK) to obtain data and information whenever needed; g. providing access to the Financial Services Authority to the Database in a timely manner, both for current data and for past data; and h. ensuring that the Information Technology service provider:
(7) In the event that the plan to use Information Technology service providers causes or is indicated to cause difficulties in supervision conducted by the Financial Services Authority, the Financial Services Authority may reject the plan to use Information Technology service providers submitted by LJKNB. (8) In the event that the use of Information Technology service providers causes or is indicated to cause difficulties in supervision conducted by the Financial Services Authority, the Financial Services Authority may request LJKNB to take corrective actions. (9) LJKNB must submit an action plan for corrective actions as referred to in paragraph (8) at the latest 20 (twenty) working days from the date of the request letter from the Financial Services Authority. (10) In the implementation of the action plan as referred to in paragraph (9), the Financial Services Authority provides a maximum period of 6 (six) months to LJKNB to take corrective actions. (11) If after the period as referred to in paragraph (9) LJKNB is unable to take corrective actions, the Financial Services Authority may order LJKNB to terminate cooperation with the Information Technology service provider before the contract period ends.
Article 22
(1) LJKNB having total assets up to Rp500,000,000,000.00 (five hundred billion rupiah) must conduct periodic data backup of activities processed using Information Technology. (2) LJKNB having total assets more than Rp500,000,000,000.00 (five hundred billion rupiah) up to Rp1,000,000,000,000.00 (one trillion rupiah) must:
a. have a Data Center; and b. conduct periodic data backup of activities processed using Information Technology.
(3) LJKNB must determine the data backup period for activities processed using Information Technology as referred to in paragraph (1) and paragraph (2) in written policy. (4) LJKNB:
a. having total assets more than Rp1,000,000,000,000.00 (one trillion rupiah); and/or b. whose majority of business organization is conducted using Information Technology, must have a Data Center and a Disaster Recovery Center. (5) The Financial Services Authority is authorized to request LJKNB:
a. meeting the criteria as referred to in paragraph (1) to have a Data Center; and b. meeting the criteria as referred to in paragraph (2) to have a Disaster Recovery Center, in the event of a need to increase the implementation of risk management in the use of Information Technology. (6) LJKNB must fulfill the request of the Financial Services Authority as referred to in paragraph (5). (7) The calculation of total assets as referred to in paragraph (1), paragraph (2), and paragraph (4) uses total asset information contained in the latest periodic reports submitted to the Financial Services Authority in accordance with Financial Services Authority regulations regarding monthly reports and/or business organization of each LJKNB at the time of implementation of this Financial Services Authority Regulation for the respective LJKNB.
(8) In the event of asset decline, LJKNB remains obligated to fulfill the provisions as referred to in paragraphs (1), (2), and (4).
Second Section
Placement of Electronic Systems in Data Centers and/or Disaster Recovery Centers
Article 23
(1) LJKNB having a Data Center and/or Disaster Recovery Center must place Electronic Systems in the Data Center and/or Disaster Recovery Center within Indonesian territory. (2) LJKNB as referred to in paragraph (1) must place Electronic Systems in the Data Center at a location different from the Disaster Recovery Center by considering geographical factors. (3) LJKNB as referred to in paragraph (1) is prohibited from placing Electronic Systems in the Data Center and/or Disaster Recovery Center outside Indonesian territory unless approval has been obtained from the Financial Services Authority. (4) Electronic Systems that can be placed in Data Centers and/or Disaster Recovery Centers outside Indonesian territory as referred to in paragraph (3), Electronic Systems used:
a. to support integrated analysis in order to fulfill provisions issued by the home country authority of LJKNB that are global, including cross-border; b. for integrated risk management with the parent company, main entity, and/or other entities having similar business activities within one LJKNB group outside Indonesian territory;
c. in the implementation of anti-money laundering and counter-terrorism financing integrated with the parent company, main entity, and/or other entities having similar business activities within one LJKNB group outside Indonesian territory;
d. for global consumer services, requiring integration with Electronic Systems owned by the LJKNB group outside Indonesian territory; e. for communication management with the parent company, main entity, and/or other entities having similar business activities within one LJKNB group; and/or f. for internal management. (5) Requests for approval from the Financial Services Authority as referred to in paragraph (3) may be submitted if LJKNB:
a. meets the requirements as referred to in Article 21 paragraphs (2) to (4); b. submits the results of country risk analysis;
c. ensures that the organization of Electronic Systems outside Indonesian territory does not reduce the effectiveness of Financial Services Authority supervision, proven by a statement letter from the LJKNB Board of Directors and the Information Technology service provider;
d. ensures that information regarding LJKNB secrets is only disclosed insofar as it meets Indonesian legislation provisions, proven by a cooperation agreement between LJKNB and the Information Technology service provider; e. ensures that the written agreement with the Information Technology service provider contains a choice of law clause; f. submits a statement letter of no objection from the supervisory authority of the Information Technology service provider outside Indonesian territory that the Financial Services Authority is granted access to conduct examinations of the Information Technology service provider; g. submits a statement letter that LJKNB will periodically submit the results of assessments conducted by the parent company, main entity, and/or other entities having similar business activities within one LJKNB group outside Indonesian territory regarding the implementation of risk management on the Information Technology service provider; h. ensures that the benefits obtained by LJKNB from the plan to place Electronic Systems outside Indonesian territory are greater than the burdens borne by LJKNB; and
i. submits LJKNB's plan to improve LJKNB's human resource capabilities both related to Information Technology organization and business transactions or products offered.
(6) LJKNB as referred to in paragraph (1) must ensure that data used in Electronic Systems placed in Data Centers and/or Disaster Recovery Centers outside Indonesian territory is not used for purposes other than as referred to in paragraph (4). (7) In the event that based on the Financial Services Authority's assessment, the placement of Electronic Systems in Data Centers and/or Disaster Recovery Centers outside Indonesian territory:
a. does not match the plan to place Electronic Systems in Data Centers and/or Disaster Recovery Centers outside Indonesian territory submitted to the Financial Services Authority; b. has the potential to reduce the effectiveness of Financial Services Authority supervision;
c. has the potential to have a negative impact on LJKNB's performance; and/or
d. does not comply with applicable legislation, the Financial Services Authority is authorized to request LJKNB to place Electronic Systems in Data Centers and/or Disaster Recovery Centers within Indonesian territory. (8) LJKNB must fulfill the Financial Services Authority's request to place Electronic System data in Data Centers and/or Disaster Recovery Centers within Indonesian territory as referred to in paragraph (7). (9) LJKNB intending to place Electronic Systems in Data Centers and/or Disaster Recovery Centers outside Indonesian territory as referred to in paragraph (3) must submit a request for approval to the Financial Services Authority at the latest 3 (three) months before the Electronic Systems in Data Centers and/or Disaster Recovery Centers are placed outside Indonesian territory. (10) Approval or rejection of the request as referred to in paragraph (5) is given by the Financial Services Authority at the latest 20 (twenty) working days after the complete request documents are received.
Article 24
LJKNB must ensure that the Data Center and/or Disaster Recovery Center as referred to in Article 23 can guarantee the continuity of LJKNB's business.
Third Section
Organization of Information Technology-Based Transaction Processing by Service Providers
Article 25
(1) LJKNB must organize Information Technology-Based Transaction Processing within Indonesian territory.
(2) Information Technology-Based Transaction Processing may be conducted by service providers within Indonesian territory.
(3) The organization of Information Technology-Based Transaction Processing by service providers as referred to in paragraph (2) may be conducted as long as:
a. it meets the principle of prudence; b. it meets the requirements as referred to in Article 21 paragraphs (2) to (4); and
c. it considers consumer protection aspects.
Article 26
(1) LJKNB must include the plan to use Information Technology service providers in the organization of Data Centers, Disaster Recovery Centers, and/or Information Technology-Based Transaction Processing in LJKNB's Information Technology development plan. (2) The realization of the plan to organize Data Centers, Disaster Recovery Centers, and/or Information Technology-Based Transaction Processing by Information Technology service providers must be reported as part of the business plan realization report. (3) The obligation as referred to in paragraph (2) only applies to LJKNB required to submit business plan realization reports to the Financial Services Authority.
CHAPTER VIII
ELECTRONIC FINANCIAL SERVICES
Article 27
LJKNB organizing Electronic Financial Services must fulfill the provisions of the Financial Services Authority and/or other related authorities.
Article 28
(1) LJKNB organizing Electronic Financial Services as referred to in Article 27 must include the plan for issuing Electronic Financial Service products in LJKNB's business plan. (2) The obligation as referred to in paragraph (1) only applies to LJKNB required to submit business plans to the Financial Services Authority.
Article 29
(1) LJKNB must apply data security control principles for consumer data and Electronic Financial Service transactions on every Electronic System used by LJKNB.
(2) The data security control principles for consumer data and Electronic Financial Service transactions on every Electronic System as referred to in paragraph (1) include at least:
a. confidentiality; b. integrity;
c. availability;
d. authenticity; e. non-repudiation; f. authorization control in systems, Databases, and applications; g. separation of duties and responsibilities; and h. audit trail maintenance.
CHAPTER IX
PROTECTION OF CONSUMER PERSONAL DATA CONFIDENTIALITY
Article 30
In organizing Information Technology, LJKNB must ensure:
a. the acquisition, processing, use, storage, updating, and/or disclosure of consumer personal data is conducted based on the consent of the respective consumer, unless otherwise determined by applicable legislation; and b. the use or disclosure of consumer personal data is in accordance with the purpose communicated to the consumer at the time of data acquisition.
CHAPTER X
REPORTING
Article 31
(1) LJKNB must report critical incidents, misuse, and/or crimes in the organization of Information Technology that can and/or have caused significant financial loss and/or disrupted LJKNB's operational smoothness. (2) Reports as referred to in paragraph (1) must be submitted to the Financial Services Authority at the latest 5 (five) working days after the critical incident and/or misuse or crime is known, using the format as contained in the Appendix which is an integral part of this Financial Services Authority Regulation.
CHAPTER XI
EXAMINATION
Article 32
(1) The Financial Services Authority may conduct examinations or request LJKNB to conduct audits on all aspects related to the use of Information Technology.
(2) LJKNB must provide access to the Financial Services Authority to conduct examinations on all aspects related to the organization of Information Technology conducted by itself and/or Information Technology service providers.
CHAPTER XII
OTHER PROVISIONS
Article 33
Further provisions regarding the implementation of Risk Management in the Use of Information Technology by LJKNB are determined by the Financial Services Authority.
CHAPTER XIII
COMPLIANCE ENFORCEMENT
First Section
Administrative Sanctions
Article 34
(1) Violations of the provisions as referred to in Article 3 paragraph (1), Article 4, Article 5, Article 8 paragraph (1), paragraph (5), Article 9 paragraph (1), paragraph (2), paragraph (4), paragraph (5), paragraph (6), Article 10 paragraph (1), Article 11 paragraph (1), paragraph (2), paragraph (4), Article 12 paragraph (1), Article 13, Article 14, Article 15, Article 16, Article 17, Article 18 paragraph (1), Article 19 paragraph (1), paragraph (3), paragraph (4), Article 20, Article 21 paragraphs (2), (3), (4), (5), (9), Article 22 paragraphs (1), (2), (3), (4), (6), (8), Article 23 paragraphs (1), (2), (3), (6), (8), (9), Article 24, Article 25 paragraph (1), Article 26 paragraphs (1), (2), Article 27, Article 28 paragraph (1), Article 29 paragraph (1), Article 30, Article 31, and Article 32 paragraph (2) are subject to administrative sanctions in the form of written warnings valid until the provisions are fulfilled. (2) LJKNB that does not fulfill the provisions in Article 31 paragraph (2) is subject to additional administrative sanctions in the form of an administrative fine of Rp500,000.00 (five hundred thousand rupiah) per day of delay and at most Rp25,000,000.00 (twenty-five million rupiah). (3) In the event that LJKNB violates the provisions as referred to in paragraph (1) but the violation has been corrected, it is still subject to written warning sanctions that end automatically. (4) In the event that LJKNB has fulfilled the provisions as referred to in paragraph (1), the Financial Services Authority revokes the written warning sanction. Second Section Reduction of Health Level Assessment Results and Re-assessment of LJKNB Principal Parties
Article 35
In the event that the Financial Services Authority has imposed administrative sanctions as referred to in Article 34 paragraph (1) and LJKNB does not fulfill the provisions causing the administrative sanction, the Financial Services Authority may:
a. reduce the health level assessment results; and/or b. conduct a re-assessment of LJKNB's principal parties.
CHAPTER XIV
TRANSITIONAL PROVISIONS
Article 36
For LJKNB that have issued Electronic Financial Service products before the implementation of this Financial Services Authority Regulation, it is declared valid and applicable.
Article 37
(1) For LJKNB that have placed Electronic Systems in Data Centers and/or Disaster Recovery Centers outside Indonesian territory before this Financial Services Authority Regulation is promulgated, must:
a. submit a request to the Financial Services Authority at the latest 6 (six) months since this Financial Services Authority Regulation is promulgated to obtain approval for the placement of Electronic Systems in Data Centers and/or Disaster Recovery Centers outside Indonesian territory as referred to in Article 23 paragraph (3); and b. move Electronic Systems that do not meet the provisions of Article 23 paragraph (4) in Data Centers and/or Disaster Recovery Centers within Indonesian territory at the latest 1 (one) year since this Financial Services Authority Regulation is promulgated. (2) In the event that the request as referred to in paragraph (1) letter a is rejected, LJKNB must move Electronic Systems in Data Centers and/or Disaster Recovery Centers within Indonesian territory at the latest 1 (one) year since the rejection.
Article 38
(1) Every administrative sanction that has been imposed on LJKNB based on:
a. Article 49 paragraph (3), Article 50, Article 51 paragraph (2), Financial Services Authority Regulation Number 69/POJK.05/2016 concerning the Organization of Business of Insurance Companies, Sharia Insurance Companies, Reinsurance Companies, and Sharia Reinsurance Companies; b. Article 25 and Article 28 paragraph (1) Financial Services Authority Regulation Number 77/POJK.01/2016 concerning Technology-Based Money Lending Services;
c. Article 44 paragraph (2) and Article 46 Financial Services Authority Regulation Number 2/POJK.05/2017 concerning the Organization of Business of Guarantee Institutions;
d. Article 19 paragraph (2) Financial Services Authority Regulation Number 35/POJK.05/2018 concerning the Organization of Business of Financing Companies; e. Article 14 paragraph (2) Financial Services Authority Regulation Number 10/POJK.05/2019 concerning the Organization of Business of Sharia Financing Companies and Sharia Business Units of Financing Companies; f. Article 49 paragraph (2) letter c Financial Services Authority Regulation Number 15/POJK.05/2019 concerning Pension Fund Governance; or g. Financial Services Authority Regulation Number 38/POJK.05/2020 concerning Amendments to Financial Services Authority Regulation Number 69/POJK.05/2016 Concerning the Organization of Business of Insurance Companies, Sharia Insurance Companies, Reinsurance Companies, and Sharia Reinsurance Companies, is declared valid and applicable. (2) LJKNB that have not been able to overcome the causes of administrative sanctions as referred to in paragraph (1) are subject to further sanctions in accordance with this Financial Services Authority Regulation.
Article 39
Provisions in:
a. Article 51 Financial Services Authority Regulation Number 69/POJK.05/2016 concerning the Organization of Business of Insurance Companies, Sharia Insurance Companies, Reinsurance Companies, and Sharia Reinsurance Companies (State Gazette of the Republic of Indonesia Year 2016 Number 302, Additional State Gazette of the Republic of Indonesia Number 5992); b. Article 65 paragraph (2) letter c Financial Services Authority Regulation Number 73/POJK.05/2016 concerning Good Corporate Governance for Insurance Companies (State Gazette of the Republic of Indonesia Year 2016 Number 306, Additional State Gazette of the Republic of Indonesia Number 5996);
c. Article 25 paragraph (1), paragraph (3), and Article 28 paragraph (1) Financial Services Authority Regulation Number
77/POJK.01/2016 concerning Technology-Based Money Lending Services (State Gazette
of the Republic of Indonesia Year 2016 Number 308, Additional State Gazette of the Republic of Indonesia Number 6000); d. Article 19 paragraph (2) Financial Services Authority Regulation Number 35/POJK.05/2018 concerning the Organization of Business of Financing Companies (State Gazette of the Republic of Indonesia Year 2018 Number 100, Additional State Gazette of the Republic of Indonesia Number 6190); and e. Article 14 paragraph (2) Financial Services Authority Regulation Number 10/POJK.05/2019 concerning the Organization of Business of Sharia Financing Companies and Sharia Business Units of Financing Companies (State Gazette of the Republic of Indonesia Year 2019 Number 100, Additional State Gazette of the Republic of Indonesia Number 6330), are declared repealed and no longer applicable.
Republic of Indonesia Year 2016 Number 324, Supplement to the State Gazette of the Republic of Indonesia Number 6005); d. Article 44 and Article 46 paragraph (2) of Financial Services Authority Regulation 2/POJK.05/2017 concerning the Conduct of Business of Guarantee Institutions (State Gazette of the Republic of Indonesia Year 2017 Number 7, Supplement to the State Gazette of the Republic of Indonesia Number 6014); e. Article 19 paragraph (2) letters a, b, and d of Financial Services Authority Regulation 35/POJK.05/2018 concerning the Conduct of Business of Financing Companies (State Gazette of the Republic of Indonesia Year 2018 Number 260, Supplement to the State Gazette of the Republic of Indonesia Number 6286); f. Article 14 paragraph (2) letters a, b, and d of Financial Services Authority Regulation 10/POJK.05/2019 concerning the Conduct of Business of Sharia Financing Companies and Sharia Business Units of Financing Companies (State Gazette of the Republic of Indonesia Year 2019 Number 40, Supplement to the State Gazette of the Republic of Indonesia Number 6320); and g. Article 49 paragraph (2) letter c of Financial Services Authority Regulation 15/POJK.05/2019 concerning Pension Fund Management (State Gazette of the Republic of Indonesia Year 2019 Number 106, Supplement to the State Gazette of the Republic of Indonesia Number 6356), shall remain valid until:
a. 1 (one) year since the Financial Services Authority Regulation was enacted for providers of IT-based lending services and Non-Bank Financial Service Institutions (LJKNB) having total assets exceeding IDR 1,000,000,000,000.00 (one trillion rupiah); b. 2 (two) years since the Financial Services Authority Regulation was enacted for LJKNB having total assets exceeding IDR 500,000,000,000.00 (five hundred billion rupiah) up to IDR 1,000,000,000,000.00 (one trillion rupiah); and
c. 3 (three) years since the Financial Services Authority Regulation was enacted for LJKNB having total assets up to IDR 500,000,000,000.00 (five hundred billion rupiah).
CHAPTER XV
FINAL PROVISIONS
Article 40
At the time this Financial Services Authority Regulation takes effect, provisions regarding procedures and methods for imposing administrative sanctions in the insurance sector as regulated in Financial Services Authority Regulations concerning procedures and methods for imposing administrative sanctions in the insurance sector and blocking the assets of insurance companies, Sharia insurance companies, reinsurance companies, and Sharia reinsurance companies shall not apply to violations of this Financial Services Authority Regulation.
Article 41
Provisions other than Article 23 of this Financial Services Authority Regulation shall take effect:
a. 1 (one) year since this Financial Services Authority Regulation was enacted for:
Article 42
At the time this Financial Services Authority Regulation takes effect:
a. Article 49 paragraph (3), Article 50, and Article 51 of Financial Services Authority Regulation Number 69/POJK.05/2016 concerning the Conduct of Business of Insurance Companies, Sharia Insurance Companies, Reinsurance Companies, and Sharia Reinsurance Companies (State Gazette of the Republic of Indonesia Year 2016 Number 302, Supplement to the State Gazette of the Republic of Indonesia Number 5992); b. Article 65 paragraph (2) letter c of Financial Services Authority Regulation Number 73/POJK.05/2016 concerning Good Corporate Governance for Insurance Companies (State Gazette of the Republic of Indonesia Year 2016 Number 306, Supplement to the State Gazette of the Republic of Indonesia Number 5996);
c. Article 25 and Article 28 paragraph (1) of Financial Services Authority Regulation Number 77/POJK.01/2016 concerning IT-Based Lending Services (State Gazette of the Republic of Indonesia Year 2016 Number 324, Supplement to the State Gazette of the Republic of Indonesia Number 6005);
d. Article 44 and Article 46 of Financial Services Authority Regulation 2/POJK.05/2017 concerning the Conduct of Business of Guarantee Institutions (State Gazette of the Republic of Indonesia Year 2017 Number 7, Supplement to the State Gazette of the Republic of Indonesia Number 6014); e. Article 19 paragraph (2) of Financial Services Authority Regulation 35/POJK.05/2018 concerning the Conduct of Business of Financing Companies (State Gazette of the Republic of Indonesia Year 2018 Number 260, Supplement to the State Gazette of the Republic of Indonesia Number 6286); f. Article 14 paragraph (2) of Financial Services Authority Regulation 10/POJK.05/2019 concerning the Conduct of Business of Sharia Financing Companies and Sharia Business Units of Financing Companies (State Gazette of the Republic of Indonesia Year 2019 Number 40, Supplement to the State Gazette of the Republic of Indonesia Number 6320); g. Article 49 paragraph (2) letter c of Financial Services Authority Regulation 15/POJK.05/2019 concerning Pension Fund Management (State Gazette of the Republic of Indonesia Year 2019 Number 106, Supplement to the State Gazette of the Republic of Indonesia Number 6356); and h. Financial Services Authority Regulation Number 38/POJK.05/2020 concerning the Amendment to POJK 69/POJK/2016 concerning the Conduct of Business of Insurance Companies, Sharia Insurance Companies, Reinsurance Companies, and Sharia Reinsurance Companies (State Gazette of the Republic of Indonesia Year 2020 Number 149, Supplement to the State Gazette of the Republic of Indonesia Number 6527), are revoked and declared invalid.
Article 43
This Financial Services Authority Regulation shall take effect upon enactment.
This copy is consistent with the original
Director of Law 1
Legal Department signed
Mufli Asmawidjaja
To ensure that everyone knows it, ordering the enactment of this Financial Services Authority Regulation by placing it in the State Gazette of the Republic of Indonesia. Established in Jakarta on 9 March 2021 CHAIRMAN OF THE COMMISSIONERS BOARD FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA, signed WIMBOH SANTOSO
Enacted in Jakarta on 17 March 2021
MINISTER OF LAW AND HUMAN RIGHTS
REPUBLIC OF INDONESIA, signed
YASONNA H. LAOLY
STATE GAZETTE OF THE REPUBLIC OF INDONESIA YEAR 2021 NUMBER 78
EXPLANATION
OF
FINANCIAL SERVICES AUTHORITY REGULATION
OF THE REPUBLIC OF INDONESIA
NUMBER 4 /POJK.05/2021
CONCERNING
IMPLEMENTATION OF RISK MANAGEMENT IN THE USE OF INFORMATION TECHNOLOGY BY NON-BANK FINANCIAL SERVICE INSTITUTIONS
I. GENERAL
Law Number 21 of 2011 concerning the Financial Services Authority mandates that the supervision and regulation functions for all activities within the financial services sector operating in Indonesia are carried out by the Financial Services Authority. The purpose of establishing the Financial Services Authority is to ensure that all financial services activities are conducted in an orderly, fair, transparent, and accountable manner, and are capable of protecting consumer and public interests.
The development of information technology is one of the impacts of the rapid advancement of time. Many factors underlie the development of information technology, one of which is the public's need to carry out various activities more easily and effectively.
In the financial services sector, information technology plays a very important role. The use of information technology can increase the effectiveness and efficiency of LJKNB operational activities and the quality of LJKNB services to consumers.
On the other hand, the utilization of information technology also has potential risks that can harm LJKNB and consumers of LJKNB services and products. Therefore, to protect the interests of LJKNB and consumers, LJKNB is required to effectively implement information technology risk management so that LJKNB can control potential risks that may occur.
So far, information technology risk management for certain types of LJKNB has been regulated in separate regulations with different substantive scopes. Through this Financial Services Authority Regulation, provisions regarding information technology risk management, which were previously regulated in each respective LJKNB, are harmonized in an integrated manner in this Financial Services Authority Regulation concerning the Implementation of Risk Management in the Use of Information Technology by Non-Bank Financial Service Institutions.
Provisions regarding the implementation of risk management in the use of information technology are expected to serve as a guide for LJKNB and related parties in the use of Information Technology. LJKNB compliance with these provisions is expected to build comprehensive awareness and understanding for LJKNB regarding the role and potential risks of using Information Technology.
II. ARTICLE BY ARTICLE
Article 1
Sufficiently clear.
Article 2
Letter a
Number 1
Insurance companies include Sharia units of insurance companies that conduct part of their business based on Sharia principles.
Number 2
Reinsurance companies include Sharia units of reinsurance companies that conduct part of their business based on Sharia principles.
Number 3
Sufficiently clear.
Number 4
Sufficiently clear.
Number 5
Sufficiently clear.
Number 6
Sufficiently clear.
Number 7
Sufficiently clear.
Letter b
Pension funds include those that conduct all or part of their business based on Sharia principles.
Letter c
Number 1
Financing companies include Sharia business units of financing companies that conduct part of their business based on Sharia principles.
Number 2
Sufficiently clear.
Number 3
Venture capital companies include Sharia business units of venture capital companies that conduct part of their business based on Sharia principles.
Number 4
Sufficiently clear.
Number 5
Infrastructure financing companies include those that conduct part of their business based on Sharia principles.
Letter d
Number 1
Pawnshop companies include those that conduct all or part of their business based on Sharia principles.
Number 2
Letter a)
Guarantee companies include Sharia business units of guarantee companies that conduct part of their business based on Sharia principles.
Letter b)
Sufficiently clear.
Letter c)
Sufficiently clear.
Letter d)
Sufficiently clear.
Number 3
Sufficiently clear.
Number 4
Sufficiently clear.
Number 5
Sufficiently clear.
Number 6
Sufficiently clear.
Number 7
Sufficiently clear.
The term "conduct of business" refers to the conduct of business as regulated in Financial Services Authority Regulations concerning the conduct of business of each respective LJKNB or other legislation.
Article 3
Paragraph (1)
The implementation of risk management in the use of Information Technology is part of the implementation of general risk management.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
The term "Information Technology resources" includes, among others, Data Centers, Disaster Recovery Centers, hardware, software, databases, communication networks, human resources, data, and information. The term "hardware" refers to one (1) or a series of devices connected within an Electronic System. The term "software" refers to one (1) or a collection of computer programs, procedures, and/or documentation related to the operation of an Electronic System. Paragraph (4) Sufficiently clear.
Article 4
Business complexity includes, among others:
a. diversity in business activities, products, and/or services; b. office branch networks or distribution channels; and/or
c. supporting technology used.
Article 5
The determination of authority and responsibility needs to consider, among others, the principle of separation of duties and responsibilities, for example, for officials at certain job levels, the party performing data input is different from the party performing data validation.
Article 6
Letter a
The term "Information Technology development plan" refers to plans for the development and procurement of information technology.
Letter b
The term "Information Technology service unit" refers to a unit that executes or oversees the function of Information Technology services.
Letter c
Number 1
Sufficiently clear.
Number 2
Enhancement of human resource competence includes, among others, continuous education and training programs regarding the provision and use of Information Technology. The adequacy and enhancement of human resource competence related to the provision and use of Information Technology, including the adequacy of human resources in conducting information technology security supervision. Number 3 Sufficiently clear. Number 4 Sufficiently clear. Number 5 Sufficiently clear. Number 6 Sufficiently clear.
Article 7
Sufficiently clear.
Article 8
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Letter a
The term "Information Technology development plan aligned with LJKNB business activities" refers to Information Technology development plans aligned with current LJKNB business activities or plans for changes or development of business activities. Letter b Sufficiently clear. Letter c Sufficiently clear. Letter d Sufficiently clear. Letter e Sufficiently clear. Letter f Sufficiently clear. Letter g Sufficiently clear. Letter h Sufficiently clear. Letter i Sufficiently clear. Paragraph (3) Sufficiently clear. Paragraph (4) Sufficiently clear. Paragraph (5) Example:
LJKNB required to have an Information Technology Steering Committee remains obligated to fulfill this requirement even if LJKNB assets fall to less than IDR 1,000,000,000,000.00 (one trillion rupiah).
Article 9
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
Letter a
The term "management" includes, among others, the Board of Directors and Board of Commissioners.
Letter b
Sufficiently clear.
Letter c
Sufficiently clear.
Letter d
Sufficiently clear.
Letter e
Information security covers not only security aspects and components of Information Technology but also information in a broader sense, including information that can cause detrimental impacts, both financial and/or non-financial, to LJKNB, consumers, and/or other LJKNB. Letter f Sufficiently clear. Letter g Sufficiently clear. Letter h Sufficiently clear. Paragraph (4) The term "risk limit" refers to the level of error still tolerable by the system (risk tolerance) or security standards established or approved not to be exceeded. Security standards as mentioned above are adjusted to the risk appetite owned by LJKNB. Paragraph (5) Reviews and updates are conducted so that policies and procedures remain relevant to developments in times, LJKNB, and Information Technology. Paragraph (6) Sufficiently clear.
Article 10
Paragraph (1)
Information Technology development plans are fundamental plans for the development and procurement of Information Technology, including information regarding the costs of technology development and maintenance, including, among others:
a. significant changes to the configuration of core information technology or applications of LJKNB; b. procurement of new core applications;
c. cooperation with information technology service providers; and
d. other fundamental information technology development and procurement that can add and/or increase LJKNB risk.
The term "core application" refers to applications used by LJKNB to conduct business activities.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
Sufficiently clear.
Article 11
Sufficiently clear.
Article 12
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Letter a
Sufficiently clear.
Letter b
Sufficiently clear.
Letter c
Sufficiently clear.
Letter d
Sufficiently clear.
Letter e
Sufficiently clear.
Letter f
Information displayed again regarding systems no longer used in LJKNB operations, paid systems or systems whose copyright is owned by third parties (proprietary systems), or systems still used in LJKNB operations but experiencing disruptions. The term "in full" refers to information displayed completely so as to generate accurate information. Control steps involve ensuring that LJKNB Information Technology systems are able to display information in full, primarily conducted for Information Technology systems that have the function of displaying information when needed. Letter g The term "created by third parties" refers to applications created by third parties based on LJKNB business processes and needs and can only be used by the respective LJKNB.
Article 13
Examples of risks that may potentially disrupt LJKNB operational activities include the development of Information Technology systems involving LJKNB's main business activities.
Article 14
Sufficiently clear.
Article 15
The term "having systems that can generate separate reports" refers to systems that can identify inputs, processes, and outputs of transactions based on Sharia principles.
Article 16
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Disaster Recovery Plans include recovery plans at various levels of disasters and/or disruptions, such as:
a. minor disasters, which have small impacts and do not require large costs and can be resolved in a short period; b. major disasters, which have large impacts and can become worse if not addressed immediately; and
c. catastrophic disasters, which result in permanent damage requiring relocation or replacement at large costs.
Paragraph (3)
Tests of Disaster Recovery Plans are conducted at various levels of disasters and/or disruptions.
The term "critical infrastructure" refers to infrastructure that has a significant impact on LJKNB operational activities. For example, changes to core application systems, application servers, and network topology. Paragraph (4) Sufficiently clear. Paragraph (5) Sufficiently clear.
Article 17
Letter a
The term "considering legislative provisions" includes, among others, provisions concerning the conduct of business of each respective LJKNB and consumer protection. Letter b Sufficiently clear. Letter c Sufficiently clear. Letter d Sufficiently clear.
Article 18
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Letter a
Sufficiently clear.
Letter b
Sufficiently clear.
Letter c
Sufficiently clear.
Letter d
Sufficiently clear.
Letter e
Number 1
Sufficiently clear.
Number 2
Sufficiently clear.
Number 3
The term "third parties conducting monitoring and correction of deviations" includes, among others, external auditors.
Paragraph (3)
The term "adequate" includes, among others, technology suitable for LJKNB operational activities, competent human resources, and an organizational structure that does not provide opportunities to commit and/or conceal errors or deviations. Paragraph (4) Sufficiently clear.
Article 19
Paragraph (1)
Sufficiently clear.
Paragraph (2)
The use of external auditors to perform internal audit functions over Information Technology does not reduce the responsibility of the internal audit unit leadership. Furthermore, the use of external auditors must consider the size and complexity of LJKNB business activities and comply with legislative provisions regarding external auditors. In the event that LJKNB uses external auditors to perform internal audit functions over Information Technology, the enterprise data management process must still be executed by the internal audit unit. The term "group internal auditor" includes, among others, internal auditors from the founders of financial institution pension funds. Paragraph (3) Sufficiently clear. Paragraph (4) Sufficiently clear.
Article 20
Sufficiently clear.
Article 21
Paragraph (1)
Information Technology services include, among others:
a. core applications of LJKNB; b. placement of Electronic Systems in Data Centers; and/or
c. placement of Electronic Systems in Disaster Recovery Centers.
Information Technology services provided by third-party Information Technology service providers can be conducted continuously and/or for specific periods.
LJKNB that entrust the provision of Information Technology services to third-party Information Technology service providers are still referred to as providers of Electronic Systems for every Electronic System used by LJKNB in conducting their business activities. Paragraph (2) Letter a The term "responsible for implementing risk management" includes, among others, ensuring that Information Technology service providers implement adequate risk management in LJKNB activities conducted by third-party Information Technology service providers in accordance with this Financial Services Authority Regulation. Letter b Sufficiently clear. Letter c Sufficiently clear. Letter d The term "cost-benefit analysis" refers to a comparative analysis between investment costs and benefits obtained by LJKNB from each alternative provider choice. The results of this analysis become one of the considerations for LJKNB to decide which Information Technology service provider to select. Letter e The term "periodically" refers to monitoring and evaluating the reliability of third-party Information Technology service providers according to LJKNB needs to effectively implement risk management in the use of Information Technology. Letter f The term "providing access" means granting the right to obtain data and information so that examinations can be conducted effectively. Letter g Access to Databases includes, among others, the provision of terminals, user IDs for querying and downloading data. Letter h Number 1 Sufficiently clear. Number 2 This condition is intended to verify that Data Centers, Disaster Recovery Centers, and/or Information Technology services used by LJKNB have adequate Information Technology controls, at minimum covering physical security and logical security. Number 3 Access as mentioned in this number is needed to obtain data and information required accurately and promptly whenever needed for the purpose of Information Technology audits, audits, and/or other examinations. Number 4 Sufficiently clear. Number 5 Information, including systems and devices used to process, store, and transmit information, is an asset that must be guaranteed in security by third-party Information Technology service providers by being protected from enemies and threats that can interfere with the principles of confidentiality, integrity, and availability. Number 6 Sufficiently clear. Number 7 Sufficiently clear. Number 8 Sufficiently clear. Number 9 Sufficiently clear. Number 10 Service level fulfillment includes, among others, ensuring that Information Technology services support LJKNB operations as intended. Number 11 Sufficiently clear. Paragraph (3) Sufficiently clear. Paragraph (4) The term "arm's length principle" refers to a condition where transactions between parties are independent, as if between unrelated parties, including having equality and being based on fair market prices, thereby minimizing conflicts of interest. The term "related parties" refers to related
parties as regulated in Financial Services Authority Regulations concerning the conduct of business of each respective LJKNB. Paragraph (5) Letter a Sufficiently clear. Letter b The term "insolvent" refers to a state of being unable to pay or settle debts. Letter c Sufficiently clear. Letter d Sufficiently clear. Paragraph (6) Sufficiently clear. Paragraph (7) Indications of supervisory difficulties include, among others:
a. difficulties for supervisory authorities in accessing data and information; b. difficulties in conducting examinations of third-party Information Technology service providers; and/or
c. third-party Information Technology service providers being used as media to manipulate LJKNB data and/or LJKNB financials.
Paragraph (8)
Sufficiently clear.
Paragraph (9)
Sufficiently clear.
Paragraph (10)
Sufficiently clear.
Paragraph (11)
Clear enough.
Article 22
Paragraph (1)
What is meant by "backup" is the process of creating backup data by copying or creating computer data archives on electronic storage media, such as on storage media like hard disks, flash disks, and/or compact disks, so that the data can be displayed again. Storage media does not include public online storage media. What is meant by "periodically" is the monitoring and evaluation of the reliability of Information Technology service providers according to the needs of LJKNB to implement risk management in the use of Information Technology effectively. Backup aims to restore data if the data is lost, whether deleted or corrupted, and to restore data to a specific position.
Paragraph (2)
Letter a
What is meant by "having a Data Center" is that LJKNB has a Data Center independently and/or cooperates/rents from an Information Technology service provider.
Letter b
Clear enough.
Paragraph (3)
Clear enough.
Paragraph (4)
Letter a
Clear enough.
Letter b
What is meant by "the majority of its business operations are conducted using Information Technology" includes:
a. providers of technology-based money lending services; b. insurance companies and Sharia insurance companies where the majority of premium/contribution revenue or number of policyholders is obtained from the use of Information Technology;
c. insurance brokers and reinsurance brokers where the majority of their brokerage service revenue is obtained from the use of Information Technology;
d. financial service institutions whose business activities involve the distribution of financing where the majority of financing distribution or number of policyholders is obtained from the use of Information Technology; e. pension funds where the majority of participant data filling and updating, as well as the delivery of information on the development of participant funds, has used Information Technology; f. pawnshop companies where the majority of loan distribution or number of policyholders is obtained from the use of Information Technology; and g. guarantee companies and Sharia guarantee companies where the majority of guarantee service fee revenue or number of policyholders is obtained from the use of Information Technology.
Paragraph (5)
For example, an LJKNB with total assets of IDR 150,000,000,000.00 (one hundred fifty billion rupiah) may be required to have a Data Center if data backup is deemed insufficient to support the smooth running of the LJKNB's business activities.
Paragraph (6)
Clear enough.
Paragraph (7)
Clear enough.
Paragraph (8)
LJKNB required to have a Data Center and Disaster Recovery Center must continue to fulfill these obligations even if the LJKNB's assets drop to less than IDR 1,000,000,000,000.00 (one trillion rupiah).
Article 23
Paragraph (1)
A Data Center can be a facility and/or location used to house computer systems and related elements, including data communication systems and data storage.
A Disaster Recovery Center can be a backup facility and/or location for housing computer systems and related elements, used to handle disasters caused by nature or humans faced by the company.
Paragraph (2)
Examples of geographical factors include the location of the Disaster Recovery Center not being in earthquake-prone, flood-prone, or lightning-prone areas, and being connected to communication and electricity infrastructure different from the Data Center, as well as other facilities necessary for the continued operation of a system.
Paragraph (3)
Clear enough.
Paragraph (4)
Letter a
Clear enough.
Letter b
Clear enough.
Letter c
Clear enough.
Letter d
Global consumer services refer to Front-end Electronic Systems used by LJKNB or consumers to obtain services provided globally to all consumers, both domestically and internationally. However, back-end electronic systems that process and/or store individual consumer data, accounts, and/or transactions are not included in the scope of this service.
Letter e
Clear enough.
Letter f
Electronic Systems used for internal management are not related to LJKNB operations and/or consumer services.
Electronic Systems used for internal management include, among others, personnel, remuneration, and/or internal audit.
Paragraph (5)
Letter a
Clear enough.
Letter b
What is meant by "country risk" is all possibilities arising in a country that can cause losses impacting LJKNB that places Electronic Systems in a Data Center and/or Disaster Recovery Center in that country, for example, political and economic instability, disaster vulnerability, war, and others.
Letter c
What is meant by "not reducing the effectiveness of OJK supervision" is not causing difficulties for supervisors in obtaining necessary data and information, such as having access to the Database and having a Database structure for each application used.
Letter d
Clear enough.
Letter e
Clear enough.
Letter f
A statement letter is submitted if the Information Technology service provider has supervisory authority.
Letter g
What is meant by "LJKNB parent company outside the territory of Indonesia" is a financial institution or foreign company located outside the territory of Indonesia that has a subsidiary in the form of an LJKNB in Indonesia.
Letter h
Expected benefits include improved service quality for consumers and the implementation of anti-money laundering and counter-terrorism financing programs.
Letter i
Clear enough.
Paragraph (6)
Clear enough.
Paragraph (7)
Clear enough.
Paragraph (8)
Clear enough.
Paragraph (9)
Clear enough.
Paragraph (10)
Clear enough.
Article 24
What is meant by "ensuring business continuity" is ensuring that business continuity can continue to run as it should when a disaster or disruption occurs, including ensuring the readiness of Electronic Systems contained in the Data Center and Disaster Recovery Center.
Article 25
Paragraph (1)
Clear enough.
Paragraph (2)
Clear enough.
Paragraph (3)
Letter a
What is meant by "prudence principle" includes, among others, the management of risks in the development or expansion of business activities as regulated in provisions regarding LJKNB risk management.
Letter b
Clear enough.
Letter c
Clear enough.
Article 26
Clear enough.
Article 27
What is meant by "OJK provisions" is all OJK provisions applicable to each LJKNB, including OJK Regulations regarding the conduct of business for each LJKNB and OJK Regulations regarding the implementation of anti-money laundering and counter-terrorism financing programs.
Article 28
Paragraph (1)
What is meant by "Electronic Financial Service Products" is financial products and/or business activities whose transactions are conducted electronically.
Paragraph (2)
Clear enough.
Article 29
Paragraph (1)
Clear enough.
Paragraph (2)
Letter a
LJKNB ensures that the methods and procedures used can protect the confidentiality of consumer data.
Letter b
LJKNB ensures that the methods and procedures used are able to guarantee that the data used is accurate, reliable, consistent, and proven true, so as to avoid errors, fraud, manipulation, misuse, and data destruction.
Letter c
LJKNB ensures the availability of services and Electronic Systems used can generate consumer data continuously.
Letter d
LJKNB can test the authenticity of consumer identity to ensure that information provided and/or financial transactions are conducted by authorized consumers.
Letter e
LJKNB must formulate, establish, and implement procedures that can ensure that transactions conducted by consumers cannot be denied and can be accounted for.
Letter f
LJKNB ensures:
a. the existence of controls over access rights and appropriate authorization for systems, Databases, and applications used in the conduct of Information Technology; and b. all information and data regarding the conduct of Information Technology that is confidential can only be accessed by parties who have authorization and must be maintained securely and protected from the possibility of being known or modified by unauthorized parties.
Letter g
LJKNB ensures the separation of duties and responsibilities regarding systems, Databases, and applications used in the conduct of Information Technology to implement check and balance functions, for example, the separation of duties between the party initiating data and the party responsible for verifying and/or authorizing the correctness of that data.
Letter h
LJKNB ensures the availability and maintenance of transaction logs in accordance with data retention policies and statutory regulations, so that there is a clear audit trail to help prove, resolve disputes, and detect intrusion attempts on Electronic Systems.
Article 30
Clear enough.
Article 31
Paragraph (1)
What is meant by "critical incident" is an incident that significantly increases risk exposure, including:
a. serious system failures, system downtime, and system performance degradation that affect LJKNB's performance in providing services to consumers; and b. incidents that cause consumer data leaks.
Paragraph (2)
Clear enough.
Article 32
Paragraph (1)
Clear enough.
Paragraph (2)
The provision of access to OJK is intended so that supervision by OJK can be carried out effectively, including ensuring the integrity, validity, availability, and authenticity of data for every transaction conducted by LJKNB. Access to OJK includes access to:
a. Databases for both current and past data; and b. supporting infrastructure.
Article 33
Clear enough.
Article 34
Clear enough.
Article 35
Clear enough.
Article 36
Clear enough.
Article 37
Clear enough.
Article 38
Clear enough.
Article 39
Clear enough.
Article 40
Clear enough.
Article 41
The calculation of total assets uses information on total assets contained in the latest periodic reports submitted to OJK in accordance with OJK regulatory provisions regarding monthly reports and/or the conduct of business for each LJKNB. In the event that LJKNB meets the asset value criteria according to the group in these provisions, the applicability of this OJK Regulation refers to the said group. As an example:
This OJK Regulation was promulgated on March 1, 2021. If on February 1, 2022, the LJKNB has total assets of IDR 900,000,000,000.00 (nine hundred billion rupiah), on March 1, 2022, this OJK Regulation does not yet apply to the said LJNB. If on April 1, 2022, the total assets of the said LJKNB increase to IDR 1,000,000,000,000.00 (one trillion rupiah), then this OJK Regulation automatically applies since April 1, 2022.
Article 42
Clear enough.
Article 43
Clear enough.
SUPPLEMENT TO THE STATE GAZETTE OF THE REPUBLIC OF INDONESIA NUMBER 6668
APPENDIX
OJK REGULATION
OF THE REPUBLIC OF INDONESIA
NUMBER 4 /POJK.05/2021
REGARDING
THE IMPLEMENTATION OF RISK MANAGEMENT IN THE
USE OF INFORMATION TECHNOLOGY
BY NONBANK FINANCIAL SERVICE INSTITUTIONS
FORMAT FOR REPORTING CRITICAL INCIDENTS, MISUSE, AND/OR CRIMES IN THE CONDUCT OF INFORMATION TECHNOLOGY
LJKNB Name :
LJKNB Head Office Address :
Responsible Person Name :
Responsible Person Position :
Incident Date :
Report Date :
Category of Critical Incident, Misuse, and/or Crime 1)
: Serious system failure, system downtime, and system performance degradation affecting LJKNB's performance in providing services to consumers Incidents causing consumer data leaks Others: …………………………………………………………… ………………………………………………………………………………
Incident Chronology
………………………………………………………………………………………………
………………………………………………………………………………………………
………………………………………………………………………………………………
Is There an Element of Intent? (Yes/No)
Explanation:
………………………………………………………………………………………………
This copy is consistent with the original
Legal Director 1
Legal Department signed
Mufli Asmawidjaja
………………………………………………………………………………………………
………………………………………………………………………………………………
Impact Caused
………………………………………………………………………………………………
………………………………………………………………………………………………
………………………………………………………………………………………………
Planned Corrective Actions
………………………………………………………………………………………………
………………………………………………………………………………………………
………………………………………………………………………………………………
Additional Information 3)
………………………………………………………………………………………………
………………………………………………………………………………………………
………………………………………………………………………………………………
Notes:
Decreed in Jakarta on March 9, 2021
CHAIRMAN OF THE COMMISSIONERS COUNCIL
FINANCIAL SERVICES AUTHORITY
OF THE REPUBLIC OF INDONESIA, signed
WIMBOH SANTOSO
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.