2016-12-23 | 75/POJK.03/2016Added
This regulation mandates that Rural Credit Banks (BPR) and Sharia Rural Financing Banks (BPRS) implement specific Information Technology standards based on their core capital, requiring those with capital of at least IDR 50 billion to establish a Disaster Recovery Center. It requires banks to maintain core banking systems and data centers within Indonesia, ensuring daily data backups and real-time transaction recording. The rules define the responsibilities of the Board of Directors and Board of Commissioners, mandate independent IT units, and impose strict requirements on third-party IT service providers, including prohibitions on subcontracting and mandatory service level agreements.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
COPY
FINANCIAL SERVICES AUTHORITY REGULATION
NUMBER 75 /POJK.03/2016
ON
INFORMATION TECHNOLOGY IMPLEMENTATION STANDARDS FOR RURAL CREDIT BANKS AND SHARIA RURAL FINANCING BANKS BY THE GRACE OF THE ALMIGHTY GOD THE COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY, Considering:
a. that the development of information technology moves dynamically following the business environment and society's needs for banking products and services; b. that in order to improve operational efficiency and service quality to society, users of banking services, it is necessary for Rural Credit Banks and Sharia Rural Financing Banks to implement information technology effectively and efficiently;
c. that the implementation of information technology effectively and efficiently is the responsibility of management involving all levels of the organization in Rural Credit Banks and Sharia Rural Financing Banks as users of information technology;
d. that based on the considerations as referred to in letters a, b, and c, it is necessary to establish a Financial Services Authority Regulation FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA
on Information Technology Implementation Standards for Rural Credit Banks and Sharia Rural Financing Banks.
Considering:
DECIDING:
Establishing: FINANCIAL SERVICES AUTHABILITY REGULATION ON INFORMATION TECHNOLOGY IMPLEMENTATION STANDARDS FOR RURAL CREDIT BANKS AND SHARIA RURAL FINANCING BANKS
CHAPTER I
GENERAL PROVISIONS
Article 1
In this Financial Services Authority Regulation, the following terms are meant:
CHAPTER II
SCOPE OF INFORMATION TECHNOLOGY IMPLEMENTATION
Article 2
(1) BPR and BPRS are required to implement Information Technology at least in the form of:
a. Core Banking System and Data Center for BPR or BPRS that have core capital of less than IDR 50,000,000,000.00 (fifty billion rupiah); or b. Core Banking System, Data Center, and Disaster Recovery Center for BPR or BPRS that have core capital of at least IDR 50,000,000,000.00 (fifty billion rupiah). (2) BPR and BPRS may implement Information Technology as referred to in paragraph (1) independently or in cooperation with Information Technology service providers. (3) Information Technology implementation in cooperation with Information Technology service providers as referred to in paragraph (2) may be carried out for all or part of the implementation of Information Technology for BPR or BPRS, including the implementation of:
a. Core Banking System; b. Data Center;
c. Disaster Recovery Center; and/or
d. Other Information Technology implementation in accordance with applicable laws and regulations.
Article 3
(1) BPR and BPRS are required to place Data Centers and Disaster Recovery Centers as referred to in Article 2 paragraph (1) and paragraph (3) within the territory of Indonesia.
(2) Data Centers must be located in areas with risk characteristics different from the location of the Disaster Recovery Center.
Article 4
(1) BPR and BPRS that implement Information Technology independently as referred to in Article 2 paragraph (1) are required to:
a. perform data backup (back up) of activities processed using Information Technology; and b. have an installer for the Core Banking System used by BPR and BPRS to perform reinstallation.
(2) BPR and BPRS that cooperate in the implementation of Information Technology with Information Technology service providers are required to ensure that the Information Technology service provider performs data backup of activities and has a Core Banking System installer as referred to in paragraph (1). (3) Activity data of BPR and BPRS as referred to in paragraph (1) and paragraph (2) must be stored for a period of time in accordance with applicable laws and regulations regarding company documents. (4) Backups as referred to in paragraph (1) letter a and paragraph (2) must be performed every end of day for all activity data of BPR and BPRS.
Article 5
(1) BPR and BPRS are required to ensure that the Core Banking System as referred to in Article 2 is capable of:
a. applying applicable laws and regulations for BPR or BPRS; b. performing bookkeeping of transactions between office networks:
Article 6
(1) BPR and BPRS may develop and procure Core Banking Systems:
a. independently (in-house); or b. by purchasing Core Banking Systems developed by Core Banking System providers.
(2) Core Banking System providers as referred to in paragraph (1) letter b must:
a. be a legal entity; b. have competent human resources in the field of Information Technology; and
c. be located within the territory of Indonesia.
(3) The provisions as referred to in paragraph (2) letter a are exempted in cases where BPR and BPRS already have Core Banking Systems when this Financial Services Authority Regulation takes effect and cooperate with Core Banking System providers that are not legal entities for the development or maintenance of the aforementioned Core Banking Systems. (4) The development and procurement of Core Banking Systems for BPR or BPRS using Core Banking System providers as referred to in paragraph (1) letter b must be carried out based on a written agreement. (5) Further provisions regarding written agreements as referred to in paragraph (4) are regulated in a Financial Services Authority Circular Letter.
Article 7
BPR and BPRS are prohibited from providing Information Technology services to other parties, except related to products and services provided by BPR and BPRS.
Article 8
In the implementation of Information Technology as referred to in Article 2 paragraph (1), BPR and BPRS are required to record all transactions in the books of BPR or BPRS on the same day.
CHAPTER III
AUTHORITY AND RESPONSIBILITY OF THE BOARD OF DIRECTORS, BOARD OF COMMISSIONERS, AND HUMAN RESOURCES RELATED TO INFORMATION TECHNOLOGY IMPLEMENTATION
Article 9
BPR and BPRS are required to determine the authority and responsibility of the Board of Directors and Board of Commissioners regarding the implementation of Information Technology.
Article 10
The authority and responsibility of the Board of Directors as referred to in Article 9 include at least:
a. determining plans for the development and procurement of Information Technology for BPR or BPRS; b. determining policies and procedures related to the implementation of Information Technology that are adequate and communicating them effectively, both to the implementing work units and to users of Information Technology;
c. monitoring the adequacy of Information Technology implementation performance and improvement efforts; and
d. ensuring that:
Article 11
The authority and responsibility of the Board of Commissioners as referred to in Article 9 include at least:
a. directing and monitoring plans for the development and procurement of fundamental Information Technology for BPR or BPRS; and b. evaluating the accountability of the Board of Directors regarding the implementation of Information Technology for BPR or BPRS.
Article 12
(1) In the implementation of Information Technology effectively and efficiently, BPR and BPRS are required to appoint a work unit or employee responsible for the implementation of Information Technology. (2) The work unit or employee responsible for the implementation of Information Technology as referred to in paragraph (1) must be independent from fund collection, fund distribution, bookkeeping, and/or internal audit activities. (3) The authority and responsibility of the work unit or employee responsible for the implementation of Information Technology as referred to in paragraph (1) include at least:
a. assisting the Board of Directors and Board of Commissioners in the implementation of Information Technology related to planning, execution, and monitoring; b. supporting the development and/or procurement of Information Technology;
c. supporting the implementation, operation, and maintenance of Information Technology; and
d. taking steps to resolve operational Information Technology problems that cannot be resolved by the Information Technology user work unit.
CHAPTER IV
POLICIES AND PROCEDURES FOR INFORMATION TECHNOLOGY IMPLEMENTATION
Article 13
(1) BPR and BPRS are required to have policies and procedures for the implementation of Information Technology.
(2) The policies and procedures for the implementation of Information Technology as referred to in paragraph (1) include at least:
a. the authority and responsibility of the Board of Directors, Board of Commissioners, and work units or employees responsible for the implementation of Information Technology; b. development and procurement;
c. Information Technology operations;
d. communication networks; e. information security; f. Disaster Recovery Plan; g. Information Technology internal audit; and h. cooperation with Information Technology service providers.
Article 14
(1) In the implementation of Information Technology as referred to in Article 2 paragraph (1), BPR and BPRS are required to have tested and adequate Disaster Recovery Plans.
(2) The Disaster Recovery Plan as referred to in paragraph (1) must be executable effectively so that BPR and BPRS operations continue to run during significant disturbances and/or disasters to the Information Technology facilities used. (3) BPR and BPRS are required to conduct tests of the Disaster Recovery Plan for the Core Banking System, at least 1 (one) time in 3 (three) years involving Information Technology users. (4) BPR and BPRS are required to review the Disaster Recovery Plan periodically at least 1 (one) time in 3 (three) years considering the test results as referred to in paragraph (3).
Article 15
In the development and procurement of Electronic Systems for BPR and BPRS, steps must be taken to control the generation of systems and data that maintain confidentiality, integrity, and availability, and support the achievement of BPR or BPRS goals, including:
a. establishing and applying procedures for the development and procurement of Electronic Systems consistently; b. applying project management in the development and procurement of Electronic Systems;
c. conducting adequate testing during the development and procurement of Electronic Systems, including trials involving user work units, to ensure the accuracy and functionality of Electronic Systems according to user needs and the compatibility of one system with others;
d. documenting the procurement, development, and maintenance of Electronic Systems; e. having Electronic System change management; and f. ensuring that BPR and BPRS Electronic Systems are capable of displaying information completely.
CHAPTER V
INFORMATION TECHNOLOGY IMPLEMENTATION IN COOPERATION WITH SERVICE PROVIDERS
Article 16
BPR and BPRS are required to ensure that Information Technology service providers for BPR or BPRS as referred to in Article 2 paragraph (2) are legal entities and located within the territory of Indonesia.
Article 17
(1) In the implementation of Information Technology for BPR or BPRS in cooperation with Information Technology service providers as referred to in Article 2 paragraph (2), BPR and BPRS are required to:
a. be responsible for the implementation of Information Technology; b. supervise the implementation of Information Technology for BPR or BPRS implemented by Information Technology service providers;
c. monitor the reputation of Information Technology service providers and the continuity of service provision to BPR or BPRS;
d. select Information Technology service providers based on benefit and cost analysis involving work units or employees responsible for the implementation of Information Technology; e. provide access to the Financial Services Authority to the Database in a timely manner for both current and past data; and f. ensure that Information Technology service providers:
Article 18
(1) In cases where cooperation with Information Technology service providers as referred to in Article 2 paragraph (2) causes or is indicated to cause difficulties in the implementation of the Financial Services Authority's supervisory duties, the Financial Services Authority may request BPR or BPRS to take improvement efforts. (2) BPR or BPRS are required to submit action plans for improvement efforts as referred to in paragraph (1) no later than 20 (twenty) working days from the date the request from the Financial Services Authority as referred to in paragraph (1) is received. (3) In the implementation of action plans as referred to in paragraph (2), the Financial Services Authority provides a maximum period of 6 (six) months for BPR or BPRS to take improvement efforts. (4) In cases where BPR or BPRS cannot take improvement efforts after the period as referred to in paragraph (3), the Financial Services Authority may order BPR or BPRS to terminate cooperation with Information Technology service providers before the end of the agreement period.
Article 19
(1) In cases where cooperation with Information Technology service providers as referred to in Article 2 paragraph (2) has been realized, but there are conditions such as:
a. worsening performance of Information Technology implementation for BPR and BPRS caused by Information Technology service providers that can have a significant impact on the business activities of BPR or BPRS; b. Information Technology service providers experiencing financial difficulties causing insolvency, being in the process of liquidation, or declared bankrupt based on court decisions;
c. there is a violation by the Information Technology service provider regarding the obligation to maintain data and information security, including bank secrecy and customer personal data; and/or
d. there are conditions that cause the BPR or BPRS to be unable to provide data and information required for supervision by the Financial Services Authority;
then the BPR and BPRS must take certain actions.
(2) Certain actions as referred to in paragraph (1) include at least:
a. reporting to the Financial Services Authority no later than 3 (three) working days from the date the condition referred to in paragraph (1) is known by the BPR or BPRS; b. deciding on follow-up actions to be taken to address the problems, including terminating cooperation with the Information Technology service provider if necessary; and
c. reporting to the Financial Services Authority regarding the decision on follow-up actions that have been and/or will be taken, no later than 10 (ten) working days from the date of the condition report referred to in letter a.
(3) In the event that the BPR and BPRS decide to terminate cooperation with the Information Technology service provider as referred to in paragraph (2) letter b, the BPR and BPRS must report the termination of cooperation to the Financial Services Authority no later than 10 (ten) working days since the said termination of cooperation.
CHAPTER VI
SECURITY OF INFORMATION TECHNOLOGY IMPLEMENTATION, INCLUDING CONFIDENTIALITY OF CUSTOMER PERSONAL DATA
Article 20
(1) BPR and BPRS are required to implement necessary security measures to prevent security disruptions in the implementation of Information Technology that have the potential to harm the BPR, BPRS, and/or their customers.
(2) In order to implement security measures as referred to in paragraph (1), BPR and BPRS are required to maintain the confidentiality, integrity, availability, and traceability of electronic information and/or electronic documents related to customers and all activities of the BPR or BPRS in accordance with applicable legislation.
(3) BPR and BPRS are required to perform authorization controls in the implementation of Information Technology.
Article 21
In implementing Information Technology, BPR and BPRS are required to:
a. ensure that the acquisition, use, utilization, and/or disclosure of customer personal data is based on the consent of the relevant customer, unless otherwise determined by applicable legislation; and b. ensure that the use or disclosure of customer personal data is based on the consent of the relevant customer and in accordance with the purpose communicated to the customer at the time of data acquisition.
CHAPTER VII
INTERNAL AUDIT FUNCTION FOR INFORMATION TECHNOLOGY IMPLEMENTATION
Article 22
(1) BPR and BPRS are required to carry out internal audit functions regarding the implementation of Information Technology in accordance with applicable legislation.
(2) The internal audit function as referred to in paragraph (1) must be carried out periodically at least once within one year as part of the implementation of internal audit or carried out separately from the internal audit.
(3) In carrying out the internal audit function as referred to in paragraph (1), BPR and BPRS are required to ensure the availability of audit trails for all activities of Information Technology implementation for the purposes of supervision, law enforcement, dispute resolution, verification, testing, and other examinations.
(4) The implementation of the internal audit function as referred to in paragraph (1) may be conducted by external auditors.
(5) Further provisions regarding the implementation of the internal audit function as referred to in paragraph (1) are regulated in a Circular Letter of the Financial Services Authority.
CHAPTER VIII
REPORTS
First Section
Routine Reports
Article 23
(1) BPR and BPRS are required to submit reports to the Financial Services Authority regarding the implementation of the internal audit function as referred to in Article 22 paragraph (1).
(2) The time limit for submitting the report on the implementation of the internal audit function as referred to in paragraph (1):
a. for BPRs, refers to the time limit for submitting reports on the implementation and main points of internal audit results as regulated in the Financial Services Authority Regulation regarding Governance Implementation for BPRs; and b. for BPRSs, submitted no later than January 31 for audits conducted over the previous year-end period.
(3) In the event that January 31 as referred to in paragraph (2) letter b falls on a Saturday, Sunday, or national holiday, the report must be submitted no later than the next working day.
Second Section
Incidental Reports
Article 24
BPR and BPRS are required to submit reports to the Financial Services Authority regarding the current conditions of the implementation of Information Technology of the BPR or BPRS:
a. no later than 1 (one) year since this Financial Services Authority Regulation comes into force; and b. no later than 10 (ten) working days since the Information Technology effectively operates in the event that the time limit as referred to in letter a is exceeded and there is a fundamental change in the implementation of Information Technology.
Article 25
BPR and BPRS are required to submit reports on the realization of cooperation with Information Technology service providers as referred to in Article 2 paragraph (2) no later than 10 (ten) working days since the implementation of Information Technology of the BPR or BPRS by the Information Technology service provider effectively operates.
Article 26
(1) BPR and BPRS are required to report to the Financial Services Authority regarding critical events, misuse, and/or crimes in the implementation of Information Technology that can or have resulted in significant financial losses and/or disrupted the smooth operations of the BPR or BPRS.
(2) Reports as referred to in paragraph (1) must be submitted via email or telephone no later than 1 (one) day after the critical event, misuse, and/or crime is known, followed by a written report no later than 7 (seven) working days since the critical event, misuse, and/or crime is known.
CHAPTER IX
SANCTIONS
Article 27
Violations against the provisions of Article 2 paragraph (1), Article 3, Article 4, Article 5 paragraph (1), Article 6 paragraph (4), Article 7, Article 8, Article 9, Article 12 paragraph (1), Article 13 paragraph (1), Article 14 paragraph (1), Article 14 paragraph (3), Article 14 paragraph (4), Article 15, Article 16, Article 17 paragraph (1), Article 17 paragraph (2), Article 17 paragraph (3), Article 17 paragraph (4), Article 18 paragraph (2), Article 19 paragraph (1), Article 19 paragraph (3), Article 20, Article 21, Article 22 paragraph (1), Article 22 paragraph (2), and/or Article 22 paragraph (3) are subject to administrative sanctions in the form of:
a. written reprimand; b. downgrade of health rating;
c. prohibition on opening branch networks;
d. temporary suspension of some business activities of the BPR and BPRS; and/or e. listing of the management of the BPR or BPRS in the list of parties who fail through the mechanism of competence and propriety tests for BPRs and BPRSs.
Article 28
(1) BPRs and BPRSs that are late in submitting reports as referred to in Article 23 paragraph (1), Article 23 paragraph (3), Article 24, Article 25, and/or Article 26 paragraph (2) are subject to administrative sanctions in the form of written reprimands and an obligation to pay IDR 100,000.00 (one hundred thousand rupiah) per working day of delay with a maximum amount of IDR 2,000,000.00 (two million rupiah).
(2) BPRs and BPRSs are considered late in submitting reports as referred to in paragraph (1) if the Financial Services Authority receives reports submitted by the BPR or BPRS within a time limit of no later than 20 (twenty) working days after the final deadline for report submission as referred to in Article 23 paragraph (1), Article 23 paragraph (3), Article 24, Article 25, and/or Article 26 paragraph (2).
Article 29
(1) BPRs and BPRSs that do not submit reports as referred to in Article 23 paragraph (1), Article 23 paragraph (3), Article 24, Article 25, and/or Article 26 paragraph (2) are subject to sanctions in the form of an obligation to pay IDR 5,000,000.00 (five million rupiah).
(2) BPRs and BPRSs are considered not to have submitted reports as referred to in paragraph (1) if the Financial Services Authority does not receive reports from the BPR or BPRS within a period of 20 (twenty) working days after the final deadline for report submission as referred to in Article 23 paragraph (1), Article 23 paragraph (3), Article 24, Article 25, and/or Article 26 paragraph (2).
(3) BPRs and BPRSs subject to sanctions as referred to in paragraph (1) remain obligated to submit reports as referred to in Article 23 paragraph (1), Article 23 paragraph (3), Article 24, Article 25, and/or Article 26 paragraph (2).
CHAPTER X
TRANSITIONAL PROVISIONS
Article 30
(1) BPRs and BPRSs that have obtained business licenses at the time this POJK is promulgated are required to meet the provisions as referred to in Article 2 paragraph (1), Article 3, Article 4, Article 5 paragraph (1), Article 6 paragraph (2), Article 8, Article 9, Article 12 paragraph (1), Article 13 paragraph (1), Article 14 paragraph (1), Article 14 paragraph (3), Article 14 paragraph (4), Article 16, Article 22 paragraph (1), Article 22 paragraph (2), Article 22 paragraph (3), Article 23 paragraph (1), and Article 23 paragraph (3) no later than 3 (three) years since this Financial Services Authority Regulation comes into force.
(2) BPRs and BPRSs in the process of establishment and have not yet obtained business licenses from the Financial Services Authority are required to meet all provisions in this Financial Services Authority Regulation at the time of operational activities.
CHAPTER XI
CLOSING PROVISIONS
Article 31
Further provisions regarding the Standards for Information Technology Implementation for BPRs or BPRSs are regulated in a Circular Letter of the Financial Services Authority.
Article 32
With the coming into force of this Financial Services Authority Regulation, then:
a. Director's Decision of Bank Indonesia Number 27/164/KEP/DIR and Bank Indonesia Circular Letter Number 27/9/UPPB both dated March 31, 1995 regarding the Use of Information System Technology by Banks; and b. Director's Decision of Bank Indonesia Number 31/175/KEP/DIR and Bank Indonesia Circular Letter Number 31/14/UPPB dated December 22, 1998 regarding the Improvement of Bank Information System Technology in Facing the Year 2000, are repealed and declared invalid since this Financial Services Authority Regulation is implemented.
Article 33
This Financial Services Authority Regulation comes into force on the date of its promulgation.
To make everyone aware thereof, it orders the promulgation of this Financial Services Authority Regulation by placing it in the State Gazette of the Republic of Indonesia.
Established in Jakarta on December 23, 2016
CHAIRMAN OF THE COMMISSIONERS COUNCIL
FINANCIAL SERVICES AUTHORITY, sd
MULIAMAN D. HADAD
Promulgated in Jakarta on December 28, 2016
MINISTER OF LAW AND HUMAN RIGHTS
REPUBLIC OF INDONESIA, sd
YASONNA H. LAOLY
STATE GAZETTE OF THE REPUBLIC OF INDONESIA YEAR 2016 NUMBER 308 Copy consistent with the original Legal Director 1 Ministry of Law sd Yuliana
EXPLANATION
OF
FINANCIAL SERVICES AUTHORITY REGULATION
NUMBER 75 /POJK.03/2016
REGARDING
STANDARDS FOR INFORMATION TECHNOLOGY IMPLEMENTATION FOR RURAL CREDIT BANKS AND SHARIA RURAL FINANCING BANKS
I. GENERAL
The role of Information Technology for the banking industry, including BPRs and BPRSs, is very important and inseparable from banking operations in serving community users of banking services.
The implementation of Information Technology can increase the effectiveness and efficiency of BPR and BPRS operations. The implementation of Information Technology by BPRs and BPRSs is also expected to support the implementation of adequate management information systems, including in fulfilling reporting obligations to authorities. Besides these positive impacts, the implementation of Information Technology by BPRs and BPRSs also contains potential risks that can harm banks and community users of banking services. Therefore, BPRs and BPRSs must implement controls and security for Information Technology to minimize all potential emerging risks. The development of Information Technology in the banking industry moves dynamically following changes in the bank's business environment and customer needs for Information Technology-based products and banking services. This condition triggers changes in the pattern of Information Technology implementation by BPRs and BPRSs, whether implemented independently or in cooperation with Information Technology service providers. In cases using Information Technology service providers, clarity of each party's role is needed to achieve optimal success in the implementation of Information Technology. The implementation of Information Technology by BPRs and BPRSs, which includes planning, development and procurement, operation, and maintenance of Information Technology, is the responsibility of the Board of Directors and Board of Commissioners. Therefore, the Board of Directors and Board of Commissioners must ensure that the implementation of Information Technology aligns with the achievement of the vision and mission of the respective BPR and BPRS. In order to realize effective and efficient implementation of Information Technology, management must involve all levels of the BPR and BPRS organization. Provisions regarding Standards for Information Technology Implementation for BPRs and BPRSs are expected to serve as guidelines for BPRs and BPRSs and interested parties in the implementation of Information Technology. Compliance of BPRs and BPRSs with these provisions is expected to build adequate awareness and understanding across all organizational levels regarding the role of Information Technology in supporting BPR and BPRS operations.
II. ARTICLE BY ARTICLE
Article 1
Clearly sufficient.
Article 2
Paragraph (1)
Clearly sufficient.
Paragraph (2)
What is meant by "cooperating with Information Technology service providers" is cooperation with other parties in the implementation of Information Technology of the BPR or BPRS continuously and/or for a specific period.
Paragraph (3)
Letter a
Clearly sufficient.
Letter b
Clearly sufficient.
Letter c
Clearly sufficient.
Letter d
Included in other implementations of Information Technology is switching cooperation.
Example: A BPR or BPRS acting as an issuer of ATM cards or debit cards will cooperate with a switching company to join a shared ATM network.
Article 3
Paragraph (1)
Clearly sufficient.
Paragraph (2)
What is meant by "risk characteristics" includes riots and natural disasters such as earthquakes, floods.
Article 4
Paragraph (1)
Letter a
What is meant by "backup" is the process of creating backup data by copying or archiving computer data in electronic storage media, including but not limited to storage media such as hard disks, flash drives, and/or compact discs, so that the data can be displayed again. Storage media does not include public online storage media. Backup aims to restore data if the data is lost, whether deleted or corrupted, and to restore data to a specific position.
Letter b
What is meant by Core Banking Application installer is software that can be reinstalled if necessary.
Paragraph (2)
Clearly sufficient.
Paragraph (3)
Clearly sufficient.
Paragraph (4)
Clearly sufficient.
Article 5
Paragraph (1)
Letter a
Included in applicable legislation provisions for BPRs and BPRSs are provisions regarding quality of productive assets and provision for write-off of productive assets, maximum credit limits, maximum fund disbursement limits, accounting standards, and reporting.
Letter b
Provisions regarding electronic banking services and/or activities as ATM card issuers refer to applicable legislation provisions regarding business activities and branch network areas for BPRs based on core capital, and applicable legislation provisions regarding products and activities for BPRSs.
Letter c
Data and information included in the preparation of reports for external needs are reports submitted by BPRs and BPRSs to authorities, including monthly reports, maximum credit limit reports or maximum fund disbursement limit reports, public financial publication reports, and business plans of BPRs and BPRSs, as well as debtor information system/financial information service system reports for BPRs and BPRSs as reporters.
Letter d
Clearly sufficient.
Paragraph (2)
What is meant by "integrated customer profile" is customer profile data covering all accounts owned by one customer at a BPR and BPRS, including savings, deposits, and loans or financing.
Article 6
Paragraph (1)
Clearly sufficient.
Paragraph (2)
Clearly sufficient.
Paragraph (3)
What is meant by "competent human resources in the field of Information Technology" is a person who has special expertise in the field of Information Technology as proven by expertise certificates, experience letters, and/or educational diplomas according to the needs of Information Technology implementation.
Paragraph (4)
Clearly sufficient.
Paragraph (5)
Clearly sufficient.
Article 7
What is meant by "provision of Information Technology services activity" is the provision of Information Technology infrastructure in the form of hardware, software, and/or supporting Information Technology facilities, such as Data Centers, Disaster Recovery Centers, communication networks, and/or other electronic devices not related to the business activities of funds collection and disbursement by BPRs and BPRSs.
Article 8
Clearly sufficient.
Article 9
Clearly sufficient.
Article 10
Clearly sufficient.
Article 11
Letter a
What is meant by "Information Technology development" is the process of developing new information technology systems including replacing or improving existing technology systems, whether done independently by the BPR or BPRS or in cooperation with Information Technology service providers. What is meant by "Information Technology procurement" is the process of fulfilling or providing goods and/or services related to information technology. Included in fundamental Information Technology development and procurement are significant changes to Information Technology configuration or Core Banking Applications, procurement of new Core Banking Applications, cooperation with Information Technology service providers, and other fundamental Information Technology development and procurement that can add and/or increase the risk of the BPR or BPRS.
Letter b
Clearly sufficient.
Article 12
Paragraph (1)
Clearly sufficient.
Paragraph (2)
What is meant by "independent from funds collection, funds disbursement, bookkeeping, and/or internal audit activities" is not handling activities directly related to funds collection, funds disbursement, bookkeeping, and/or internal audit activities.
Paragraph (3)
Clearly sufficient.
Article 13
Clearly sufficient.
Article 14
Paragraph (1)
Disaster Recovery Plans cover recovery plans at various levels of disruption and disaster, such as minor disasters having small impact and not requiring large costs and can be resolved in a short period; major disasters having large impact and becoming more severe if not addressed immediately; and catastrophic events having permanent damage impact requiring relocation or replacement with large costs.
Paragraph (2)
What is meant by "can be implemented effectively" is that Information Technology operations can resume immediately after disruption and/or disaster occurs so as not to disrupt service to customers.
Paragraph (3)
Clearly sufficient.
Paragraph (4)
Review of the Disaster Recovery Plan is conducted on all or partial aspects related, such as in the event of significant changes to Core Banking Applications, and changes to Data Center/Disaster Recovery Center locations.
Article 15
Letter a
Clearly sufficient.
Letter b
Clearly sufficient.
Letter c
Clearly sufficient.
Letter d
Clearly sufficient.
Letter e
Clearly sufficient.
Letter f
Information displayed again is information related to systems no longer used in BPR and BPRS operations, proprietary systems, or systems still used in BPR and BPRS operations but experiencing disruption. What is meant by "completely" is information that is fully displayed.
Article 16
Clearly sufficient.
Article 17
Paragraph (1)
Letter a
Clearly sufficient.
Letter b
Clearly sufficient.
Letter c
Monitoring of the reputation of Information Technology service providers can be done based on information obtained from various sources, both internal and external.
Letter d
Clearly sufficient.
Letter e
Access to Database includes but is not limited to the provision of terminals, user IDs, and passwords to perform query and download data.
Letter f
Number 1
Clearly sufficient.
Number 2
The intended Information Technology control is to ensure that the Core Banking Applications, Data Centers, and Disaster Recovery Centers used by BPRs and BPRSs have adequate Information Technology controls at least including physical security and logical security.
Number 3
Clearly sufficient.
Number 4
Clearly sufficient.
Number 5
What is meant by "maintaining the security of all information" is maintaining the security of data and information including systems and devices used to process, store, and transmit information.
Information, systems, and devices are assets whose security must be maintained by the service provider by protecting them from unrelated parties and dangers that can disrupt confidentiality, integrity, and availability. What is meant by "customer personal data" is specific individual data stored, treated, and kept accurate and protected for confidentiality.
Number 6
What is meant by "critical event" is serious system failure, system downtime, and system performance degradation affecting the performance of the BPR or BPRS in providing services to customers.
Number 7
Clearly sufficient.
Number 8
Clearly sufficient.
Number 9
Fulfillment of service levels is done to ensure that the implementation of Information Technology can support BPRs and BPRSs to operate as they should.
Paragraph (2)
Clearly sufficient.
Paragraph (3)
Clearly sufficient.
Paragraph (4)
What is meant by "normal cooperative relationship" is a condition where transactions between parties are independent, including having equality and based on fair market prices so as to minimize the occurrence of conflicts of interest. What is meant by "related parties with the BPR or BPRS" is related parties as regulated in applicable legislation provisions regarding maximum credit limits for BPRs or maximum fund disbursement limits for BPRSs.
Paragraph (5)
Clearly sufficient.
Article 18
Paragraph (1)
What is meant by "causing or indicated to cause difficulties in the implementation of the Financial Services Authority's supervisory duties" includes:
The term “fundamental changes” includes, among others, changes to Information Technology configurations or Core Banking Applications, procurement of Core Banking Applications, cooperation with Information Technology service providers, and development and procurement of other fundamental Information Technology that can add and/or increase the risks of BPR or BPRS. The term “effectively operating” refers to the stage where Information Technology has been implemented and used in the operational activities of BPR or BPRS.
Article 25
Sufficiently clear.
Article 26
Paragraph (1)
Critical incidents include, among others, serious system failures, system downtime, and system performance degradation that affect the performance of BPR and BPRS in providing services to customers. Paragraph (2) Sufficiently clear.
Article 27
Sufficiently clear.
Article 28
Sufficiently clear.
Article 29
Sufficiently clear.
Article 30
Sufficiently clear.
Article 31
Sufficiently clear.
Article 32
Sufficiently clear.
Article 33
Sufficiently clear.
SUPPLEMENT TO THE STATE GAZETTE OF THE REPUBLIC OF INDONESIA NUMBER 5998 ---
Read the rest free
Amended 1 time · last 2025-12-18
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works