2025-12-18

Added · Updated

OJK Regulation No. 34 of 2025 on Information Technology Management by Rural Banks and Sharia Rural Banks

This regulation replaces OJK Regulation No. 75/POJK.03/2016 to establish new requirements for information technology governance, risk management, and cyber resilience for Rural Banks (BPR) and Sharia Rural Banks (BPR Syariah). It mandates the implementation of IT governance frameworks, clear assignment of responsibilities to the Board of Directors and Board of Commissioners, and the establishment of independent IT operational units, particularly for banks providing digital services. The document imposes specific obligations regarding disaster recovery planning, with mandatory testing every two years for digital service providers and every three years for others, as well as requirements for core banking application availability and daily data backups. Furthermore, it regulates the use of third-party IT service providers, requiring strict due diligence, arm's length principles, and immediate reporting of service disruptions to the Financial Services Authority.

Otoritas Jasa Keuangan (Financial Services Authority) logo

Indonesia

Otoritas Jasa Keuangan (Financial Services Authority)

Click to view full text

More like this from OJK

OJK published 2 documents in the last 30 days. We email you each new one the day it's published.

Share