2016-12-07 | 38/POJK.03/2016

Added

POJK on the Implementation of Risk Management in the Use of Information Technology by Commercial Banks

Commercial banks must implement effective information technology risk management, including active oversight by the Board of Directors and Board of Commissioners, adequate policies and procedures, and integrated risk identification and control processes. Banks are required to establish an IT Steering Committee, maintain a Disaster Recovery Plan with annual testing and review, and ensure information security through confidentiality, integrity, and availability principles. The regulation mandates internal audit functions for IT, requiring annual audits and a triennial independent review, while holding banks accountable for the risk management practices of their third-party IT service providers.

Otoritas Jasa Keuangan (Financial Services Authority) logo

Indonesia

Otoritas Jasa Keuangan (Financial Services Authority)

Scan of the document's first page
Share

OJK published 7 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: Superseded

amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from OJK

OJK published 7 documents in the last 30 days. We email you each new one the day it's published.