2023-07-07
Added · Updated
Pension funds, premium pension institutions, and insurers must implement adequate procedures and measures to manage ICT risks, ensuring the integrity, continuous availability, and security of automated data processing. These control measures, based on risk analysis, must address technology, people, processes, and facilities, and apply to both internal operations and (sub)outsourced activities. Institutions are required to periodically evaluate the effectiveness of these controls and establish governance structures that ensure the independence of ICT risk management and internal audit functions. The document outlines specific good practices across governance, organization, outsourcing, and testing to help supervised entities comply with statutory requirements under the Financial Supervision Act and related decrees.