2023-06-01

Added · Updated

Joint Standard on IT Governance and Risk Management Requirements

The Financial Sector Conduct Authority and Prudential Authority have issued a consultation report finalizing the IT Governance and Risk Management Joint Standard, which mandates financial institutions to implement robust board-approved IT risk frameworks, conduct annual strategy reviews with quarterly action plan assessments, and report directly to their responsible regulatory authority. The finalized requirements adjust the initial commencement timeline to twelve months post-publication, clarify that IT risk management may operate within broader enterprise frameworks, and refine compliance obligations based on the nature, scale, and complexity of each institution. By consolidating reporting obligations and explicitly defining independent reviews and fit-and-proper standards for vendors, the standard ensures that financial entities maintain adequate cybersecurity resilience while mitigating compliance costs across small to medium enterprises.

Financial Sector Conduct Authority logo

South Africa

Financial Sector Conduct Authority

Scan of the document's first page
Share

Get FSCA alerts — same-day email on every new publication.

Read the rest free

Lineage: In force

Financial Sector Regulation Act…2017Financial Sector Regulation Act, 2017 (Act No. 9 of 2017) (2017-08-21)Joint Standard on ITGovernance and Risk Managemen…2023-06-01 · this documentJoint Standard on IT Governance and Risk Management Requirements (2023-06-01)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Financial Sector Conduct Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from FSCA

We email you every new FSCA publication the day it's published.