2022-07-07 | 11/POJK.03/2022Added
The Financial Services Authority mandates commercial banks to implement robust IT governance, architecture, risk management, and cyber resilience frameworks. Banks are required to establish IT steering committees, conduct annual cyber maturity self-assessments, perform scenario-based security testing at least once a year, and submit related reports to the regulator. Non-compliance with these obligations subjects banks to administrative sanctions, including written reprimands, bans on new products, suspension of business activities, or downgrades in health assessment ratings.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
COPY
FINANCIAL SERVICES AUTHORITY REGULATION
REPUBLIC OF INDONESIA
NUMBER 11 /POJK.03/2022
CONCERNING
THE MANAGEMENT OF INFORMATION TECHNOLOGY
BY COMMERCIAL BANKS
BY THE GRACE OF GOD THE ALMIGHTY
THE COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY, Considering: a. that to support operational continuity and banking services to the community, the utilization of information technology by banks is required; b. that the utilization of information technology has the potential to increase risk exposure for banks, so banks need to strengthen governance in the management of information technology so that the bank's information technology management can add value to the bank through the optimization of resources to mitigate the risks faced by the bank;
c. that in line with the dynamics of regulations regarding the use of information technology and the development of national and international standards, it is necessary to replace the Financial Services Authority Regulation Number 38/POJK.03/2016 concerning the Implementation of Risk Management in the Use of Information Technology by Commercial Banks as amended by the Financial Services Authority Regulation Number 13/POJK.03/2020 concerning Amendments to the Financial Services Authority Regulation Number 38/POJK.03/2016 concerning the Implementation of Risk Management in the Use of Information Technology by Commercial Banks;
d. that based on the considerations as referred to in letters a, b, and c, it is necessary to establish a Financial Services Authority Regulation concerning the Management of Information Technology by Commercial Banks; Recalling: 1. Law Number 7 of 1992 concerning Banking (State Gazette of the Republic of Indonesia Year 1992 Number 31, Supplement to the State Gazette of the Republic of Indonesia Number 3472) as amended by Law Number 10 of 1998 concerning Amendments to Law Number 7 of 1992 concerning Banking (State Gazette of the Republic of Indonesia Year 1998 Number 182, Supplement to the State Gazette of the Republic of Indonesia Number 3790);
2. Law Number 21 of 2008 concerning Islamic Banking (State Gazette of the Republic of Indonesia Year 2008 Number 94, Supplement to the State Gazette of the Republic of Indonesia Number 4867); and
3. Law Number 21 of 2011 concerning the Financial Services Authority (State Gazette of the Republic of Indonesia Year 2011 Number 111, Supplement to the State Gazette of the Republic of Indonesia Number 5253);
DECIDING:
Decree: FINANCIAL SERVICES AUTHORITY REGULATION CONCERNING THE MANAGEMENT OF INFORMATION TECHNOLOGY BY COMMERCIAL BANKS.
CHAPTER I
GENERAL PROVISIONS
Article 1
In this Financial Services Authority Regulation, the following terms are defined as:
CHAPTER II
BANK IT GOVERNANCE
First Section
General
Article 2
(1) Banks are required to implement good IT governance in the management of IT.
(2) In implementing good IT governance as referred to in paragraph (1), Banks consider at least the following factors:
a. the Bank's business strategy and objectives; b. the size and complexity of the Bank's business;
c. the role of IT for the Bank;
d. IT resource procurement methods; e. IT-related risks and issues; f. practices or standards applicable nationally or internationally; and g. provisions of legislation. (3) In implementing good IT governance as referred to in paragraph (1), Banks carry out at least the following activities:
a. evaluation of strategy choices, direction of IT management strategy, and monitoring of strategy achievement; b. alignment, planning, and organization of all units, strategies, and activities supporting IT management;
c. definition, acquisition, and implementation of IT solutions and their integration into the Bank's business processes;
d. provision of IT service operational support to stakeholders; and e. monitoring of IT management performance and compliance with internal performance targets, internal controls, and legislative provisions. (4) The implementation of good IT governance as referred to in paragraph (1) applies to all units and/or functions:
a. IT managers; and b. IT users, in the Bank.
Article 3
(1) In implementing IT governance, Banks are required to map, plan, and/or determine at least the following aspects:
a. business processes; b. organizational structure;
c. policies, standards, and procedures;
d. information needs and flows supporting business processes; e. supporting human resources; f. IT culture; and g. infrastructure and applications.
(2) Banks ensure synergy is created in all aspects as referred to in paragraph (1).
(3) Banks are required to consistently and continuously apply the policies, standards, and procedures as referred to in paragraph (1) letter c.
(4) Banks are required to periodically review and revise the policies, standards, and procedures as referred to in paragraph (1) letter c.
Second Section
Implementation of Bank IT Governance
Article 4
Banks are required to establish clear authority and responsibilities of the Board of Directors, Board of Commissioners, and officials at each job level related to the implementation of IT governance.
Article 5
The authority and responsibilities of the Board of Directors as referred to in Article 4 include at least:
a. establishing IT strategic plans; b. establishing adequate policies, standards, and procedures related to IT management and use and communicating them effectively, both to IT management units and IT users; and
c. evaluating strategic objectives, directing Bank executive officials, and monitoring all IT management activities to ensure:
CHAPTER III
BANK IT ARCHITECTURE
First Section
Preparation of Bank IT Architecture
Article 11
(1) Banks are required to have IT architecture.
(2) In preparing IT architecture as referred to in paragraph (1), Banks consider at least the following factors:
a. the Bank's vision and mission; b. the Bank's corporate plan;
c. the Bank's business processes and capabilities;
d. IT governance; e. the Bank's data, application, and technology management principles; f. the size and complexity of the Bank's business; g. the Bank's capital adequacy; h. standards applicable nationally or internationally; and
i. provisions of legislation.
(3) IT architecture as referred to in paragraph (1) is prepared comprehensively covering the processes:
a. planning; b. design;
c. implementation; and
d. control.
(4) In the event of changes to the factors as referred to in paragraph (2), Banks are required to revise the IT architecture.
(5) Further provisions regarding the preparation of IT architecture are established by the Financial Services Authority.
Second Section
Preparation of Bank IT Strategic Plan
Article 12
(1) Banks are required to have an IT strategic plan that supports the Bank's corporate plan.
(2) The IT strategic plan as referred to in paragraph (1) is prepared for IT management in the long term in accordance with the Bank's corporate plan period. (3) Further provisions regarding the preparation of IT strategic plans are established by the Financial Services Authority.
Article 13
(1) Banks are required to submit the IT strategic plan as referred to in Article 12 paragraph (1) to the Financial Services Authority at the latest by the end of November of the year before the start of the IT strategic plan period. (2) In the event of conditions that significantly affect the Bank's IT objectives and strategies as contained in the ongoing IT strategic plan, the Bank may make changes to the IT strategic plan. (3) The Bank submits changes to the IT strategic plan as referred to in paragraph (2) to the Financial Services Authority at any time during the IT strategic plan period as referred to in Article 12 paragraph (2).
Article 14
(1) Banks violating the provisions as referred to in Article 11 paragraph (1), paragraph (4), Article 12 paragraph (1), and/or Article 13 paragraph (1), are subject to administrative sanctions in the form of written reprimands. (2) In the event that a Bank has been subject to administrative sanctions as referred to in paragraph (1) and has not fulfilled the provisions as referred to in Article 11 paragraph (1), paragraph (4), Article 12 paragraph (1), and/or Article 13 paragraph (1), the Bank is subject to administrative sanctions in the form of:
a. prohibition on issuing new Bank products; b. suspension of certain business activities; and/or
c. downgrade of the governance factor assessment in the Bank's health level assessment.
CHAPTER IV
IMPLEMENTATION OF RISK MANAGEMENT
IN BANK IT MANAGEMENT
First Section
General
Article 15
(1) Banks are required to implement risk management effectively in IT management.
(2) The implementation of risk management as referred to in paragraph (1) must be carried out in an integrated manner in every stage of IT management.
(3) In implementing risk management as referred to in paragraph (1), Banks carry out at least the following processes:
a. risk identification; b. risk measurement;
c. risk monitoring; and
d. risk control.
(4) Banks are required to ensure the adequacy of the risk management information system in IT management.
(5) Further provisions regarding the implementation of risk management in IT management are established by the Financial Services Authority.
Second Section
Information Security in
Bank IT Management
Article 16
(1) Banks are required to ensure that information security is carried out effectively and efficiently.
(2) Information security as referred to in paragraph (1) is carried out against human resources, processes, technology, and physical or environmental aspects, in the overall management of IT. (3) The implementation of information security as referred to in paragraph (1) is carried out based on the results of risk assessments on information owned by the Bank. (4) Further provisions regarding information security are established by the Financial Services Authority.
Article 17
(1) Banks are required to ensure that communication networks provided by the Bank meet the principles of confidentiality, integrity, and availability.
(2) Further provisions regarding communication networks are established by the Financial Services Authority.
Article 18
(1) Banks are required to have a Disaster Recovery Plan.
(2) Banks are required to ensure that the Disaster Recovery Plan as referred to in paragraph (1) can be implemented, so that the Bank's operational continuity continues during disasters and/or disturbances to the IT facilities used by the Bank. (3) Banks are required to conduct tests of the Disaster Recovery Plan for all critical applications and infrastructure in accordance with the results of business impact analysis, at least 1 (one) time in 1 (one) year involving IT users. (4) Banks are required to review the Disaster Recovery Plan at least 1 (one) time in 1 (one) year. (5) Further provisions regarding the Disaster Recovery Plan are established by the Financial Services Authority.
Article 19
Conventional commercial banks that have Sharia business units are required to have a system that can generate separate reports for Sharia business unit activities.
Article 20
(1) Banks violating the provisions as referred to in Article 15 paragraph (1), paragraph (4), Article 16 paragraph (1), Article 17 paragraph (1), Article 18 paragraph (1), paragraph (2), paragraph (3), paragraph (4), and/or Article 19, are subject to administrative sanctions in the form of written reprimands. (2) In the event that a Bank has been subject to administrative sanctions as referred to in paragraph (1) and has not fulfilled the provisions as referred to in Article 15 paragraph (1), paragraph (4), Article 16 paragraph (1), Article 17 paragraph (1), Article 18 paragraph (1), paragraph (2), paragraph (3), paragraph (4), and/or Article 19, the Bank is subject to administrative sanctions in the form of:
a. prohibition on issuing new Bank products; b. suspension of certain business activities; and/or
c. downgrade of the governance factor assessment in the Bank's health level assessment.
CHAPTER V
BANK CYBER RESILIENCE AND SECURITY
Article 21
(1) Banks are required to maintain cyber resilience.
(2) To maintain cyber resilience as referred to in paragraph (1), Banks carry out at least the following processes:
a. identification of assets, threats, and vulnerabilities; b. asset protection;
c. detection of cyber incidents; and
d. handling and recovery of cyber incidents.
(3) Banks ensure that the processes for maintaining cyber resilience as referred to in paragraph (2) are supported by adequate cyber resilience information systems.
Article 22
(1) Banks are required to conduct self-assessments of cyber security maturity levels.
(2) Self-assessments of cyber security maturity levels as referred to in paragraph (1) are carried out annually for the position at the end of December.
(3) Banks may revise self-assessments of cyber security maturity levels at any time if necessary.
(4) Banks are required to submit the results of self-assessments of cyber security maturity levels as referred to in paragraph (1) to the Financial Services Authority as part of the current condition report of the Bank's IT management.
Article 23
Banks are required to conduct cyber security testing based on:
a. vulnerability analysis; and b. scenarios.
Article 24
(1) Cyber security testing based on vulnerability analysis as referred to in Article 23 letter a is required to be carried out periodically.
(2) Banks are required to submit the results of cyber security testing based on vulnerability analysis as referred to in paragraph (1) to the Financial Services Authority as part of the current condition report of the Bank's IT management.
Article 25
(1) Cyber security testing based on scenarios as referred to in Article 23 letter b is required to be carried out at least 1 (one) time in 1 (one) year.
(2) Cyber security testing based on scenarios as referred to in paragraph (1) includes at least:
a. setting objectives, scope, and testing scenarios; b. implementation of testing;
c. evaluation of test results; and
d. assessment of the effectiveness of the Bank's mitigation efforts, response, and recovery actions against cyber attacks.
(3) Banks are required to submit reports on the results of cyber security testing based on scenarios as referred to in paragraph (1) to the Financial Services Authority at the latest 10 (ten) working days after the cyber security testing is completed. (4) Reports on the results of cyber security testing as referred to in paragraph (3) include at least:
a. summary of testing implementation; b. lessons learned or observation results from the testing; and
c. plans or improvements that have been made.
Article 26
(1) Banks are required to form a unit or function tasked with handling the Bank's cyber resilience and security.
(2) The unit or function as referred to in paragraph (1) is independent from the IT management function.
Article 27
(1) Banks violating the provisions as referred to in Article 21 paragraph (1), Article 22 paragraph (1), paragraph (4), Article 23, Article 24, Article 25 paragraph (1), and/or Article 26 paragraph (1), are subject to administrative sanctions in the form of written reprimands. (2) In the event that a Bank has been subject to administrative sanctions as referred to in paragraph (1) and has not fulfilled the provisions as referred to in Article 21 paragraph (1), Article 22 paragraph (1), paragraph (4), Article 23, Article 24, Article 25 paragraph (1), and/or Article 26 paragraph (1), the Bank is subject to administrative sanctions in the form of:
a. prohibition on issuing new Bank products; b. suspension of certain business activities; and/or
c. downgrade of the governance factor assessment in the Bank's health level assessment.
Article 28
Further provisions regarding Bank cyber resilience and security are established by the Financial Services Authority.
CHAPTER VI
USE OF THIRD-PARTY IT SERVICE PROVIDERS IN
BANK IT MANAGEMENT
Article 29
(1) Banks may use third-party IT service providers in IT management.
(2) Banks using third-party IT service providers as referred to in paragraph (1) are required to have the capability to supervise the implementation of Bank activities carried out by third-party IT service providers. (3) Banks are required to have policies and procedures in the use of third-party IT service providers as referred to in paragraph (1) at least containing:
a. the process of identifying the need to use third-party IT service providers; b. the process of selecting third-party IT service providers;
c. procedures for establishing cooperative relationships with third-party IT service providers;
d. the risk management process for using third-party IT service providers; and e. procedures for evaluating the performance and compliance of third-party IT service providers.
Article 30
(1) Banks in carrying out the process of identifying the need to use third-party IT service providers as referred to in Article 29 paragraph (3) letter a include at least:
a. researching potential candidate third-party IT service providers; and b. formulating criteria for the required third-party IT service providers.
(2) Banks in carrying out the process of selecting third-party IT service providers as referred to in Article 29 paragraph (3) letter b pay attention to at least:
a. the qualifications and competencies of third-party IT service providers, including the human resources they possess; b. cost-benefit analysis involving the Bank's IT management work unit;
c. the principle of prudence and risk management; and
d. the principle of fair cooperative relationships if the third-party IT service provider is a related party to the Bank.
(3) Banks in establishing cooperative relationships with third-party IT service providers as referred to in Article 29 paragraph (3) letter c are required to have a cooperative agreement with the third-party IT service provider, paying attention to at least:
a. the qualifications and competencies of the human resources owned by the third-party IT service provider; b. the third-party IT service provider's commitment to maintaining the confidentiality of the Bank's and Bank customers' data and/or information;
c. the third-party IT service provider's commitment to periodically submit IT audit results conducted by independent auditors on the provision of IT services to the Bank;
d. the transfer of some activities or subcontracting by the third-party IT service provider is carried out with the Bank's approval evidenced by written documents; e. the mechanism for reporting critical incidents by the third-party IT service provider to the Bank; f. the mechanism for terminating the cooperative agreement if there is termination of the agreement before the agreement period ends;
g. compliance with statutory regulations regarding the provision of IT services by the IT service provider; h. the IT service provider's willingness to fulfill obligations and/or requirements contained in the cooperation agreement; and
i. the IT service provider's willingness to provide access to the Financial Services Authority (OJK) and/or other competent parties to conduct examinations of the IT service provision activities in accordance with statutory regulations.
(4) The risk management process for the use of third-party IT service providers as referred to in Article 29 paragraph (3) letter d includes:
a. the Bank's responsibility for applying risk management related to the use of third-party IT service providers; b. the provision of tested and adequate Disaster Recovery Plans; and
c. the determination and monitoring of compliance with data and/or information security requirements in internal policies and procedures as well as in cooperation agreements.
(5) In conducting performance and compliance assessments of third-party IT service providers as referred to in Article 29 paragraph (3) letter e, the Bank must pay attention to at least:
a. periodic monitoring and evaluation of the reliability of the IT service provider regarding performance, reputation, and continuity of service provision; b. the application of adequate IT controls by the IT service provider, evidenced by audit results and/or assessments conducted by independent parties; and
c. fulfillment of service levels in accordance with the Service Level Agreement between the Bank and the IT service provider.
Article 31
In the event of significant changes to the organization of the IT service provider, the Bank is required to conduct a re-assessment of the materiality of the IT service provider.
Article 32
(1) In the event of conditions such as:
a. the results of the materiality re-assessment as referred to in Article 31 indicate that the performance of the IT service provider is potentially ineffective; b. deterioration in the IT management performance of the IT service provider that potentially causes and/or results in significant impacts on the Bank's business activities and/or operations;
c. the IT service provider becomes insolvent, is in the process of liquidation, or is declared bankrupt by a court;
d. violations by the IT service provider against statutory regulations regarding Bank confidentiality and/or customer personal data; e. conditions that cause the Bank to be unable to provide data required for supervision by the Financial Services Authority; and/or f. other conditions that cause disruption or cessation of IT service provision from the IT service provider to the Bank, the Bank is required to take specific actions.
(2) Specific actions as referred to in paragraph (1) include at least:
a. reporting to the Financial Services Authority no later than 3 (three) working days after the Bank becomes aware of the conditions as referred to in paragraph (1); b. deciding on follow-up actions to address the issues, including the cessation of the use of the IT service provider if necessary; and
c. reporting to the Financial Services Authority no later than 3 (three) working days after the Bank ceases the use of the IT service provider before the end of the agreement term, in the event the Bank decides to cease the use of the IT service provider.
(3) In the event that the use of a third-party IT service provider or the plan to use a third-party IT service provider causes or is indicated to cause supervisory difficulties for the Financial Services Authority, the Financial Services Authority may:
a. order the Bank to cease the use of the IT service provider before the end of the agreement term; or b. prohibit the plan to use the IT service provider by the Bank.
(4) In the event the Bank will cease the use of the IT service provider, the Bank is required to:
a. prepare a plan for the cessation of the use of the IT service provider; b. assess the continuity of services and data related to activities entrusted to the IT service provider, as well as test or simulate the continuity of the Bank's business activities and/or operations; and
c. ensure that the cessation of the use of the IT service provider does not cause disruption to the Bank's business activities and/or operations.
Article 33
(1) Banks that violate the provisions as referred to in Article 29 paragraph (2), paragraph (3), Article 30 paragraph (3), Article 31, Article 32 paragraph (1), and/or paragraph (4) shall be subject to administrative sanctions in the form of written reprimands.
(2) In the event that a Bank has been subject to administrative sanctions as referred to in paragraph (1) and has not fulfilled the provisions as referred to in Article 29 paragraph (2), paragraph (3), Article 30 paragraph (3), Article 31, Article 32 paragraph (1), and/or paragraph (4), the Bank shall be subject to administrative sanctions in the form of:
a. prohibition on issuing new Bank products; b. freezing of certain business activities; and/or
c. reduction of the governance factor assessment in the Bank's health level assessment.
Article 34
Further provisions regarding the use of third-party IT service providers in the management of IT by Banks shall be determined by the Financial Services Authority.
CHAPTER VII
PLACEMENT OF ELECTRONIC SYSTEMS AND IT-BASED TRANSACTION PROCESSING First Section Placement of Electronic Systems
Article 35
(1) Banks are required to place Electronic Systems in Data Centers and Disaster Recovery Centers within the territory of Indonesia.
(2) Banks may place Electronic Systems in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia provided they obtain permission from the Financial Services Authority.
(3) Criteria for Electronic Systems that may be placed in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia as referred to in paragraph (2) include:
a. Electronic Systems used to support integrated analysis to meet regulations issued by the home country authority of the Bank that are global, including cross-border; b. Electronic Systems used for integrated risk management with the Bank's headquarters or parent office or main entity office outside the territory of Indonesia;
c. Electronic Systems used for the application of anti-money laundering and counter-terrorism financing integrated with the Bank's headquarters or parent office outside the territory of Indonesia;
d. Electronic Systems used for global customer service, which require integration with Electronic Systems belonging to the Bank's group outside the territory of Indonesia; e. Electronic Systems used for communication management between the Bank's headquarters and branches, or between subsidiaries and parent companies; and/or f. Electronic Systems used for the Bank's internal management.
(4) In the event of conditions that significantly disrupt Bank operations, the Financial Services Authority may determine the placement of Electronic Systems in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia other than the criteria as referred to in paragraph (3) for a temporary period.
Article 36
(1) Banks may submit permission applications as referred to in Article 35 paragraph (2) provided that the Bank:
a. fulfills the provisions as referred to in Article 29 and Article 30; b. submits the results of country risk analysis;
c. ensures that the placement of Electronic Systems in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia does not reduce the effectiveness of supervision by the Financial Services Authority, evidenced by a statement letter;
d. ensures that information regarding Bank confidentiality is only disclosed in accordance with statutory regulations in Indonesia, evidenced by a cooperation agreement between the Bank and the IT service provider; e. ensures that written agreements with the IT service provider contain choice of law clauses; f. submits a statement letter of non-objection from the supervisory authority of the IT service provider outside the territory of Indonesia that the Financial Services Authority can conduct examinations of the IT service provider; g. submits a statement letter that the Bank periodically submits the results of assessments conducted by the Bank's offices outside the territory of Indonesia regarding the application of risk management to the IT service provider; h. ensures that the benefits of the plan to place Electronic Systems in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia for the Bank are greater than the burdens borne by the Bank;
i. submits the Bank's plan to improve the Bank's human resource capabilities, both related to IT management and business transactions or products offered; and
j. submits the Bank's plan for the placement of Electronic Systems in Data Centers and/or Disaster Recovery Centers within the territory of Indonesia for Banks that will place Electronic Systems in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia as referred to in Article 35 paragraph (4).
(2) The Financial Services Authority grants or rejects permission applications for the placement of Electronic Systems in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia as referred to in Article 35 paragraph (2) no later than 3 (three) months after all requirements are fulfilled by the Bank and the application documents are received completely by the Financial Services Authority.
(3) Banks are required to ensure that data used in Electronic Systems placed in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia is not used for purposes other than those referred to in Article 35 paragraph (3) or Article 35 paragraph (4).
(4) In the event that, based on the Financial Services Authority's assessment, the placement of Electronic Systems in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia:
a. does not match the permission application for the placement of Electronic Systems in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia submitted to the Financial Services Authority; b. potentially reduces the effectiveness of supervision by the Financial Services Authority;
c. potentially has a negative impact on the Bank's performance; and/or
d. does not comply with statutory regulations, the Financial Services Authority may request the Bank to place Electronic Systems in Data Centers and/or Disaster Recovery Centers within the territory of Indonesia.
Article 37
Banks are required to ensure that Data Centers and Disaster Recovery Centers as referred to in Article 35 guarantee the continuity of the Bank's business.
Article 38
Further provisions regarding the placement of Electronic Systems in Data Centers and Disaster Recovery Centers shall be determined by the Financial Services Authority.
Second Section
IT-Based Transaction Processing
Article 39
(1) Banks are required to conduct IT-based transaction processing within the territory of Indonesia.
(2) IT-based transaction processing may be conducted by IT service providers within the territory of Indonesia.
(3) The management of IT-based transaction processing by IT service providers as referred to in paragraph (2) may be conducted provided that:
a. it adheres to the principle of prudence; b. it fulfills the provisions as referred to in Article 29 and Article 30; and
c. it considers customer protection aspects.
(4) IT-based transaction processing by IT service providers outside the territory of Indonesia may be conducted provided that the Bank obtains permission from the Financial Services Authority.
(5) Banks may submit permission applications as referred to in paragraph (4) provided that:
a. the Bank fulfills the requirements as referred to in paragraph (3); b. supporting administrative financial documents for transactions conducted at the Bank's offices in Indonesia are accounted for at the Bank's offices in Indonesia; and
c. the Bank's business plan shows efforts to increase the Bank's role in the development of the Indonesian economy.
(6) The Financial Services Authority grants or rejects permission applications for IT-based transaction processing by IT service providers outside the territory of Indonesia as referred to in paragraph (4) no later than 3 (three) months after all requirements are fulfilled by the Bank and the application documents are received completely by the Financial Services Authority.
(7) Further provisions regarding IT-based transaction processing shall be determined by the Financial Services Authority.
Third Section
Procedure for Permission Applications and Time Limits for Implementation After Obtaining Permission
Article 40
(1) Permission applications as referred to in Article 35 paragraph (2) and/or Article 39 paragraph (4) are submitted to the Financial Services Authority online through the integrated licensing and registration system of the Financial Services Authority.
(2) In the event that the submission facility as referred to in paragraph (1) is not yet available, submission is conducted through the Financial Services Authority's reporting system for unstructured reports to:
a. the Department of Supervision for the relevant Bank or the Regional Office of the Financial Services Authority in Jakarta, for Banks headquartered in the Special Capital Region of Jakarta Province or Banten Province; or b. the Regional Office of the Financial Services Authority or the local Office of the Financial Services Authority, for Banks headquartered outside the Special Capital Region of Jakarta Province or Banten Province.
Article 41
(1) Banks must:
a. place Electronic Systems in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia as referred to in Article 35 paragraph (2); and/or b. implement IT-based transaction processing by IT service providers outside the territory of Indonesia as referred to in Article 39 paragraph (4), no later than 6 (six) months from obtaining permission from the Financial Services Authority.
(2) If the Bank does not implement the provisions as referred to in paragraph (1) within a period of 6 (six) months from obtaining permission from the Financial Services Authority, the Financial Services Authority's permission becomes invalid.
Article 42
(1) Banks that violate the provisions as referred to in Article 35 paragraph (1), Article 36 paragraph (3), Article 37, and/or Article 39 paragraph (1) shall be subject to administrative sanctions in the form of written reprimands.
(2) In the event that a Bank has been subject to administrative sanctions as referred to in paragraph (1) and has not fulfilled the provisions as referred to in Article 35 paragraph (1), Article 36 paragraph (3), Article 37, and/or Article 39 paragraph (1), the Bank shall be subject to administrative sanctions in the form of:
a. prohibition on issuing new Bank products; b. freezing of certain business activities; and/or
c. reduction of the governance factor assessment in the Bank's health level assessment.
CHAPTER VIII
DATA MANAGEMENT AND PERSONAL DATA PROTECTION IN THE MANAGEMENT OF BANK IT First Section Data Management by Banks
Article 43
(1) Banks are required to manage data effectively in the processing of Bank data to support the achievement of the Bank's business objectives.
(2) Effective data management as referred to in paragraph (1) pays attention to at least:
a. data ownership and governance; b. data quality;
c. data management systems; and
d. supporting resources for data management.
(3) Further provisions regarding data management by Banks shall be determined by the Financial Services Authority.
Second Section
Personal Data Protection by Banks
Article 44
(1) Banks are required to implement personal data protection principles in conducting personal data processing.
(2) In the event of specific conditions that potentially increase risks for personal data owners, Banks are required to conduct an impact assessment on the application of personal data protection principles as referred to in paragraph (1).
Article 45
(1) In applying personal data protection in data exchange activities, Banks are required to determine at least:
a. classification of data that constitutes personal data; b. rights and obligations of parties involved in personal data exchange;
c. personal data exchange agreements;
d. means of personal data exchange; and e. personal data security.
(2) Personal data exchange as referred to in paragraph (1) is conducted with consideration of customer and/or prospective customer consent, implemented in accordance with statutory regulations.
Article 46
(1) Banks that violate the provisions as referred to in Article 43 paragraph (1), Article 44, and/or Article 45 paragraph (1) shall be subject to administrative sanctions in the form of written reprimands.
(2) In the event that a Bank has been subject to administrative sanctions as referred to in paragraph (1) and has not fulfilled the provisions as referred to in Article 43 paragraph (1), Article 44, and/or Article 45 paragraph (1), the Bank shall be subject to administrative sanctions in the form of:
a. prohibition on issuing new Bank products; b. freezing of certain business activities; and/or
c. reduction of the governance factor assessment in the Bank's health level assessment.
Article 47
Further provisions regarding personal data protection by Banks shall be determined by the Financial Services Authority.
CHAPTER IX
PROVISION OF IT SERVICES BY BANKS
Article 48
(1) Banks may only provide IT services to other financial service institutions:
a. that are supervised by the Financial Services Authority; and/or b. outside the territory of Indonesia that are supervised by the local supervisory and regulatory authority for financial service institutions.
(2) Banks that will provide IT services as referred to in paragraph (1) are required to:
a. fulfill the requirements that the provision of IT services does not become one of the Bank's main activities; b. adhere to the principle of prudence;
c. consider cost-benefit analysis;
d. fulfill the principle of fair cooperative relationships; and e. comply with statutory regulations.
(3) Banks are required to obtain permission from the Financial Services Authority for every plan to provide IT services as referred to in paragraph (1).
(4) The provision of IT services in the form of applications to financial service institutions other than banks may be conducted provided that:
a. the financial service institution using the IT service is within the same group or cluster as the Bank; and b. the use of the application is intended to support general operational activities.
Article 49
(1) Permission applications as referred to in Article 48 paragraph (3) are submitted to the Financial Services Authority online through the integrated licensing and registration system of the Financial Services Authority.
(2) In the event that the submission facility as referred to in paragraph (1) is not yet available, submission is conducted through the Financial Services Authority's reporting system for unstructured reports to:
a. the Department of Supervision for the relevant Bank or the Regional Office of the Financial Services Authority in Jakarta, for Banks headquartered in the Special Capital Region of Jakarta Province or Banten Province; or b. the Regional Office of the Financial Services Authority or the local Office of the Financial Services Authority, for Banks headquartered outside the Special Capital Region of Jakarta Province or Banten Province.
Article 50
(1) Banks must implement the plan to provide IT services as referred to in Article 48 paragraph (3) no later than 6 (six) months from obtaining permission from the Financial Services Authority.
(2) If the Bank does not implement the plan to provide IT services as referred to in Article 48 paragraph (3) within a period of 6 (six) months from obtaining permission from the Financial Services Authority, the Financial Services Authority's permission becomes invalid.
Article 51
(1) Banks that violate the provisions as referred to in Article 48 paragraph (2) and/or paragraph (3) shall be subject to administrative sanctions in the form of written reprimands.
(2) In the event that a Bank has been subject to administrative sanctions as referred to in paragraph (1) and has not fulfilled the provisions as referred to in Article 48 paragraph (2) and/or paragraph (3), the Bank shall be subject to administrative sanctions in the form of:
a. prohibition on issuing new Bank products; b. freezing of certain business activities; and/or
c. reduction of the governance factor assessment in the Bank's health level assessment.
Article 52
Further provisions regarding the provision of IT services by Banks shall be determined by the Financial Services Authority.
CHAPTER X
INTERNAL CONTROL AND AUDIT IN THE MANAGEMENT OF BANK IT First Section Bank's Internal Control in IT Management
Article 53
(1) Banks are required to implement an effective internal control system in the management of IT.
(2) An effective internal control system as referred to in paragraph (1) includes at least:
a. supervision by management and the application of a control culture; b. identification and assessment of risks;
c. control activities and segregation of functions;
d. support from information systems, accounting systems, and communication systems; and e. monitoring activities and corrective actions for deviations, conducted by operational units, internal audit units, or other parties.
(3) Information systems, accounting systems, and communication systems as referred to in paragraph (2) letter d must be supported by adequate technology, human resources, and the Bank's organizational structure.
(4) Monitoring activities and corrective actions for deviations as referred to in paragraph (2) letter d include at least:
a. continuous monitoring activities; b. implementation of effective and comprehensive internal audit functions; and
c. improvements to identified deviations.
Second Section
Internal Audit in IT Management
Article 54
(1) Banks implement effective and comprehensive IT internal audit functions as referred to in Article 53 paragraph (4) letter b in accordance with Financial Services Authority Regulations regarding the application of internal audit functions for general banks.
(2) To ensure the implementation of effective and comprehensive IT internal audits as referred to in Article 53 paragraph (4) letter b, Banks are required to ensure the availability of audit trails for all IT management activities for supervision, law enforcement, dispute resolution, verification, testing, and other examinations.
(3) In the event that Banks use external parties' services in the implementation of IT internal audits, the use of external parties' services is conducted in accordance with Financial Services Authority Regulations regarding the application of internal audit functions for general banks.
(4) Banks are required to conduct internal audits on IT management according to needs, priorities, and risk analysis results of IT management, at least 1 (one) time in 1 (one) year.
Article 55
(1) Banks are required to have internal audit guidelines for IT management.
(2) Banks are required to review the internal audit function for IT management at least 1 (one) time in 3 (three) years using independent external parties' services.
(3) Banks are required to submit to the Financial Services Authority:
a. the results of the review as referred to in paragraph (2) as part of the review results report from independent external parties; and b. the results of IT internal audits as part of the implementation report and key points of internal audit results, in accordance with Financial Services Authority Regulations regarding the application of internal audit functions for general banks.
Article 56
(1) Banks that violate the provisions as referred to in Article 53 paragraph (1), Article 54 paragraph (2), paragraph (4), and/or Article 55 shall be subject to administrative sanctions in the form of written reprimands.
(2) In the event that a Bank has been subject to administrative sanctions as referred to in paragraph (1) and has not fulfilled the provisions as referred to in Article 53 paragraph (1), Article 54 paragraph (2), paragraph (4), and/or Article 55, the Bank shall be subject to administrative sanctions in the form of:
a. prohibition on issuing new Bank products; b. freezing of certain business activities; and/or
c. reduction of the governance factor assessment in the Bank's health level assessment.
Article 57
Further provisions regarding internal control and internal audit in the management of Bank IT shall be determined by the Financial Services Authority.
CHAPTER XI
REPORTING
First Section
IT Management Reports
Article 58
(1) Banks are required to report their IT development plans to be implemented within the next 1 (one) year no later than the end of November preceding the year of the IT development plan. (2) Banks may change the IT development plan previously submitted as referred to in paragraph (1) at most 1 (one) time, no later than the end of June of the current year. (3) Banks may submit changes to the IT development plan outside the time frame referred to in paragraph (2) provided that specific considerations are met and approval is obtained from the Financial Services Authority. (4) The Financial Services Authority may request Banks to make adjustments to the changes in the IT development plan as referred to in paragraph (2).
Article 59
Banks are required to report the current status of IT management no later than 15 (fifteen) working days after the end of the reporting year.
Second Section
Incidental Reports
Article 60
(1) In the event of an IT incident that has the potential to and/or has caused significant losses and/or disrupted the smooth operation of the Bank, the Bank is required to submit:
a. an initial notification no later than 24 (twenty-four) hours after the IT incident is known; and b. an IT incident report no later than 5 (five) working days after the IT incident is known. (2) The initial notification as referred to in paragraph (1) letter a is submitted in writing via electronic media to the Financial Services Authority based on available initial information. (3) The IT incident report as referred to in paragraph (1) letter b is part of the status report that has the potential to cause significant losses to the Bank's financial condition in accordance with:
a. Financial Services Authority Regulation regarding the implementation of risk management for general banks; or b. Financial Services Authority Regulation regarding the implementation of risk management for Sharia general banks and Sharia business units. (4) In the event that there are regulations from other authorities regarding the submission of initial notifications and/or IT incident reports within a shorter time frame than the time frame referred to in paragraph (1), the Bank is required to submit the initial notification and/or IT incident report to the Financial Services Authority simultaneously in accordance with the provisions of the regulations of the other authorities concerned. (5) Banks that have submitted the initial notification and/or IT incident report as referred to in paragraph (4) are deemed to have fulfilled the provisions as referred to in paragraph (1) letter a and/or letter b.
Third Section
Report on the Realization of Bank IT Management
Article 61
(1) Banks are required to submit realization reports on:
a. the placement of Electronic Systems at Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia; b. the processing of IT-based transactions outside the territory of Indonesia; and/or
c. activities as an IT service provider.
(2) The realization report as referred to in paragraph (1) is submitted no later than 3 (three) months after implementation.
Fourth Section
Procedures for Submission of Reports
Article 62
(1) Banks submit reports on:
a. the results of cybersecurity testing based on scenarios as referred to in Article 25 paragraph (3); b. the IT development plan as referred to in Article 58 paragraph (1);
c. the current status of IT management as referred to in Article 59;
d. IT incidents as referred to in Article 60 paragraph (1) letter b or paragraph (4); and/or e. realization as referred to in Article 61, via online through the Financial Services Authority's reporting system. (2) Banks that commit violations related to the submission of reports as referred to in paragraph (1) are subject to administrative sanctions. (3) The procedure for online submission of reports as referred to in paragraph (1) and the imposition of administrative sanctions as referred to in paragraph (2) are implemented in accordance with the Financial Services Authority Regulation regarding bank reporting through the Financial Services Authority's reporting system.
Article 63
(1) Banks that are late in submitting the initial notification of IT incidents as referred to in Article 60 paragraph (1) letter a or paragraph (4) are subject to administrative sanctions in the form of a written warning. (2) In the event that a Bank has been subject to administrative sanctions as referred to in paragraph (1) and has not fulfilled the provisions as referred to in Article 60 paragraph (1) letter a or paragraph (4), the Bank is subject to administrative sanctions in the form of:
a. prohibition on issuing new Bank products; b. freezing of certain business activities; and/or
c. reduction of the governance factor assessment in the Bank's health level assessment.
Article 64
Banks that submit reports incompletely are subject to administrative sanctions for incorrect information in accordance with the Financial Services Authority Regulation regarding bank reporting through the Financial Services Authority's reporting system.
Article 65
Further provisions regarding reporting formats and procedures for report submission are determined by the Financial Services Authority.
CHAPTER XII
ASSESSMENT OF THE DIGITAL MATURITY LEVEL OF BANKS
Article 66
(1) Banks are required to conduct self-assessments of the Bank's digital maturity level periodically, at least 1 (one) time in 1 (one) year.
(2) The Bank's digital maturity level as referred to in paragraph (1) considers all aspects in IT management.
(3) Banks are required to submit reports on the results of self-assessments of the Bank's digital maturity level as referred to in paragraph (1) as part of the report on the current status of the Bank's IT management. (4) Banks that violate the provisions as referred to in paragraph (1) and/or paragraph (3) are subject to administrative sanctions in the form of a written warning. (5) In the event that a Bank has been subject to administrative sanctions as referred to in paragraph (4) and has not fulfilled the provisions as referred to in paragraph (1) and/or paragraph (3), the Bank is subject to administrative sanctions in the form of:
a. prohibition on issuing new Bank products; b. freezing of certain business activities; and/or
c. reduction of the governance factor assessment in the Bank's health level assessment.
(6) Further provisions regarding the self-assessment of the Bank's digital maturity level as referred to in paragraph (1) are determined by the Financial Services Authority.
CHAPTER XIII
TRANSITIONAL PROVISIONS
Article 67
Banks that already have policies, standards, and procedures in IT management and IT management risk management guidelines must adjust to the provisions in this Financial Services Authority Regulation no later than 6 (six) months from the effective date of this Financial Services Authority Regulation.
Article 68
Banks that have used third-party IT service providers before the effective date of this Financial Services Authority Regulation must adjust the agreements made in accordance with the provisions in this Financial Services Authority Regulation.
Article 69
Banks must adjust their IT strategic plans in accordance with the provisions in this Financial Services Authority Regulation no later than the end of November 2022.
CHAPTER XIV
CLOSING PROVISIONS
Article 70
Banks implement provisions related to:
a. self-assessment of cybersecurity maturity levels as referred to in Article 22; b. cybersecurity testing based on vulnerability analysis as referred to in Article 24;
c. cybersecurity testing based on scenarios as referred to in Article 25; and
d. self-assessment of the Bank's digital maturity level as referred to in Article 66, for the first time after being determined by the Financial Services Authority.
Article 71
Upon the effective date of this Financial Services Authority Regulation, the implementation provisions of Financial Services Authority Regulation Number 38/POJK.03/2016 regarding the Implementation of Risk Management in the Use of Information Technology by General Banks (State Gazette of the Republic of Indonesia Year 2016 Number 267, Supplement to the State Gazette of the Republic of Indonesia Number 5963) as amended by Financial Services Authority Regulation Number 13/POJK.03/2020 regarding Amendments to Financial Services Authority Regulation Number 38/POJK.03/2016 regarding the Implementation of Risk Management in the Use of Information Technology by General Banks (State Gazette of the Republic of Indonesia Year 2020 Number 88, Supplement to the State Gazette of the Republic of Indonesia Number 6486), remain in force insofar as they do not conflict with the provisions in this Financial Services Authority Regulation.
Article 72
Upon the effective date of this Financial Services Authority Regulation, Financial Services Authority Regulation Number 38/POJK.03/2016 regarding the Implementation of Risk Management in the Use of Information Technology by General Banks (State Gazette of the Republic of Indonesia Year 2016 Number 267, Supplement to the State Gazette of the Republic of Indonesia Number 5963) as amended by Financial Services Authority Regulation Number 13/POJK.03/2020 regarding Amendments to Financial Services Authority Regulation Number 38/POJK.03/2016 regarding the Implementation of Risk Management in the Use of Information Technology by General Banks (State Gazette of the Republic of Indonesia Year 2020 Number 88, Supplement to the State Gazette of the Republic of Indonesia Number 6486), are repealed and declared invalid.
Article 73
This Financial Services Authority Regulation comes into force 3 (three) months after the date of its promulgation.
This copy is in accordance with the original
Director of Law 1
Legal Department signed
Mufli Asmawidjaja
To ensure everyone knows, ordering the promulgation of this Financial Services Authority Regulation by placing it in the State Gazette of the Republic of Indonesia.
Established in Jakarta on 6 July 2022
CHAIRMAN OF THE COMMISSIONERS BOARD
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
WIMBOH SANTOSO
Promulgated in Jakarta on 7 July 2022
MINISTER OF LAW AND HUMAN RIGHTS
REPUBLIC OF INDONESIA, signed
YASONNA H. LAOLY
STATE GAZETTE OF THE REPUBLIC OF INDONESIA YEAR 2022 NUMBER 5/OJK
EXPLANATION
OF
FINANCIAL SERVICES AUTHORITY REGULATION
OF THE REPUBLIC OF INDONESIA
NUMBER 11 /POJK.03/2022
REGARDING
THE MANAGEMENT OF INFORMATION TECHNOLOGY
BY GENERAL BANKS
I. GENERAL
The utilization of IT by Banks is a necessity to support the continuity of Bank operations and services effectively and efficiently. One form of IT support in Bank operations is the automation of work processes through the use of specific hardware and software. From the perspective of services to the public, the utilization of IT is manifested through the emergence of banking service innovations, such as mobile banking and internet banking, which have facilitated the public in conducting transactions.
On the other hand, along with the development of IT, the Indonesian banking industry faces new challenges with the emergence of financial service industries that emphasize the provision of easy financial services by utilizing IT. This causes competition in the financial service industry to become increasingly intense. Thus, Banks are increasingly required to improve services to the public through digital transformation.
With the demand for digital transformation, the utilization of IT to support Bank operational activities and the provision of services to the public is also increasing. The increased utilization of IT certainly leads to an increase in the complexity of IT management in various aspects.
This has the potential to create new risk exposures for the banking industry.
Some examples of increased risk exposures faced by the banking industry with increased IT utilization are:
a. increased cooperation with third parties leads to a high number of connections between Bank systems and third-party systems, potentially increasing security gaps originating from third parties, thereby increasing the risk of Bank cyber incidents; and b. increased provision of services emphasizing personalization leads to a high need for Bank processing data, including customer personal data, thereby potentially increasing the risk of customer personal data leaks.
In relation to the increased risks that may be faced, Banks need to increase maturity in IT management through the implementation of good IT governance. This aims to ensure that IT management can add value from the investments made by Banks to support Bank business objectives. To be able to provide optimal added value, Banks must be able to handle risks that may arise from the utilization of IT and manage their resources appropriately.
Furthermore, the rapid and dynamic development of IT also affects changes in regulations and standards related to IT management, both nationally and internationally. Thus, Banks need to adapt to the development of such regulations and standards in accordance with the needs and complexity of the Bank's IT management.
In relation to this and to strengthen all aspects in IT management and mitigate potential risks, it is necessary to formulate regulations regarding the management of information technology by general banks.
II. ARTICLE BY ARTICLE
Article 1
It is clear enough.
Article 2
Paragraph (1)
The implementation of IT governance is part of the implementation of general Bank governance. Good governance is implemented in accordance with Financial Services Authority Regulations regarding the implementation of governance for general banks or provisions of legislation regarding the implementation of good corporate governance for Sharia general banks and Sharia business units.
IT governance is applied to all activities related to IT management, including risk management, IT and cyber resilience and security, data management, use of third-party IT service providers, provision of IT services by Banks, internal control, and IT development and change.
Paragraph (2)
Letter a
The Bank's business strategy and objectives reflect among other things the business direction and needs of stakeholders.
Letter b
It is clear enough.
Letter c
It is clear enough.
Letter d
The method of procuring IT resources is adjusted to the Bank's needs and capabilities, including procurement independently, procurement using third-party IT service providers, and a combination of both.
Letter e
It is clear enough.
Letter f
It is clear enough.
Letter g
It is clear enough.
Paragraph (3)
It is clear enough.
Paragraph (4)
It is clear enough.
Article 3
Paragraph (1)
Letter a
In every activity related to IT management, the Bank determines the business processes that must be undergone to achieve the Bank's strategic objectives.
Letter b
The Bank assigns tasks and responsibilities in every position related to each business process owned by the Bank in IT management in accordance with the Bank's organizational structure.
Letter c
Policies, standards, and procedures are established for all business processes owned by the Bank in IT management.
Letter d
It is clear enough.
Letter e
The Bank establishes sufficient human resource support with appropriate expertise and competence in IT management.
Letter f
The Bank establishes a culture appropriate to achieving IT governance objectives.
Letter g
It is clear enough.
Paragraph (2)
It is clear enough.
Paragraph (3)
It is clear enough.
Paragraph (4)
The Bank establishes the time frame for review and revision of policies, standards, and procedures in accordance with the Bank's needs, considering the Bank's internal and external conditions.
Article 4
It is clear enough.
Article 5
Letter a
The IT strategic plan is a document that among other things describes the IT vision and mission, strategies supporting the IT vision and mission, and main principles serving as guidelines in IT management to meet business needs and support corporate plans.
Letter b
It is clear enough.
Number 1
The implementation of IT governance in accordance with the Bank's needs and characteristics is manifested among other things by:
a) IT policies, standards, and procedures applied effectively at IT user and management work units; and b) the availability of a system for measuring IT management process performance that among other things can support the monitoring process of strategy implementation, support the completion of IT development projects, optimize the utilization of human resources and investments in IT infrastructure, and improve IT management process performance and service quality in delivering process results to IT users.
Number 2
What is meant by "providing optimal benefits" is that the IT managed by the Bank can support the Bank's business development, achievement of Bank business objectives, and continuity of services to Bank customers.
Number 3
The risk management process in IT management includes cyber risk management.
Number 4
The availability of adequate resources can be demonstrated among other things by the existence of:
a) activities to improve the competence of human resources related to IT management; and b) an effective information security management system communicated to IT user and management work units.
Number 5
Examples of stakeholder involvement can include surveys on IT usage from IT user work units.
Article 6
It is clear enough.
Article 7
Paragraph (1)
It is clear enough.
Paragraph (2)
Letter a
It is clear enough.
Letter b
It is clear enough.
Letter c
The alignment between the IT development plan and the IT strategic plan, including the steps to mitigate risks.
Letter d
It is clear enough.
Letter e
It is clear enough.
Letter f
It is clear enough.
Letter g
It is clear enough.
Letter h
It is clear enough.
Paragraph (3)
The structure of the IT steering committee can be adjusted among other things to the size, business complexity, ownership structure, and legal form of the Bank.
Paragraph (4)
It is clear enough.
Article 8
It is clear enough.
Article 9
It is clear enough.
Article 10
It is clear enough.
Article 11
Paragraph (1)
What is meant by "IT architecture" is the strategic documentation of the Bank's IT resources that are organized and integrated to achieve and support the Bank's business objectives. IT architecture includes among other things data, applications, and technology.
Paragraph (2)
Letter a
It is clear enough.
Letter b
It is clear enough.
Letter c
It is clear enough.
Letter d
It is clear enough.
Letter e
It is clear enough.
Letter f
It is clear enough.
Letter g
It is clear enough.
Letter h
It is clear enough.
Letter i
Examples of legislation provisions are provisions of legislation regarding electronic information and transactions.
Paragraph (3)
It is clear enough.
Paragraph (4)
It is clear enough.
Paragraph (5)
It is clear enough.
Article 12
Paragraph (1)
It is clear enough.
Paragraph (2)
The period of the Bank's corporate plan is in accordance with Financial Services Authority Regulations regarding general banks and Financial Services Authority Regulations regarding Sharia general banks.
Paragraph (3)
It is clear enough.
Article 13
Paragraph (1)
Example:
The IT strategic plan for the period 2023 to 2027 is submitted to the OJK no later than the end of November 2022.
Paragraph (2)
Conditions that can affect the Bank's IT objectives and strategy include changes in the Bank's corporate plan or changes in legislation provisions regarding the management of information technology by banks.
Paragraph (3)
It is clear enough.
Article 14
It is clear enough.
Article 15
Paragraph (1)
The scope of effective implementation of risk management is implemented in accordance with Financial Services Authority Regulations regarding the implementation of risk management for general banks or Financial Services Authority Regulations regarding the implementation of risk management for Sharia general banks and Sharia business units. Risk management applies to all IT management, including:
a. cybersecurity; b. data management;
c. use of third-party IT service providers; and
d. general IT usage.
Paragraph (2)
Stages of IT management include among other things the planning, procurement, development, operation, maintenance, termination, and deletion of IT resources stages. IT resources include among other things hardware, software, networks, human resources, data, and information.
Paragraph (3)
It is clear enough.
Paragraph (4)
It is clear enough.
Paragraph (5)
It is clear enough.
Article 16
Paragraph (1)
Information security is aimed at maintaining the confidentiality, integrity, and availability of managed information.
Examples of ensuring that information security is implemented effectively and efficiently include building and maintaining an information security management system.
Paragraph (2)
It is clear enough.
Paragraph (3)
With the assessment of risks, Banks can apply different information security measures in accordance with the risks associated with the information.
Paragraph (4)
It is clear enough.
Article 17
It is clear enough.
Article 18
Paragraph (1)
It is clear enough.
Paragraph (2)
The Disaster Recovery Plan includes recovery plans at various levels of disasters and disruptions such as:
a. minor disaster that has a small impact and does not require large costs and can be resolved in a short time frame; b. major disaster that has a large impact and can become more severe if not addressed immediately; and/or
c. catastrophic that has an impact causing permanent damage, requiring relocation or replacement with large costs.
Paragraph (3)
The result of business impact analysis is known as business impact analysis.
Paragraph (4)
It is clear enough.
Paragraph (5)
It is clear enough.
Article 19
What is meant by "a system that can generate separate reports" is a system that can identify the input, process, and output of transactions based on Sharia principles.
Article 20
It is clear enough.
Article 21
Paragraph (1)
It is clear enough.
Paragraph (2)
It is clear enough.
Paragraph (3)
What is meant by "adequate cyber resilience information system" is an information system that can support the entire process in maintaining cyber resilience, in accordance with the size and business complexity of the Bank.
Article 22
Paragraph (1)
In conducting self-assessments of cybersecurity maturity levels, Banks need to conduct comprehensive analysis, considering among other things the results of assessments of cybersecurity testing.
Paragraph (2)
It is clear enough.
Paragraph (3)
It is clear enough.
Paragraph (4)
It is clear enough.
Article 23
It is clear enough.
Article 24
Paragraph (1)
Examples of cybersecurity testing based on vulnerability analysis include penetration testing. The frequency of cybersecurity testing based on vulnerability analysis can be determined based on several factors, such as system criticality and cyber risk exposure to the system. Cybersecurity testing based on vulnerability analysis is conducted periodically in accordance with the Bank's needs.
Paragraph (2)
It is clear enough.
Article 25
Paragraph (1)
Examples of cybersecurity testing based on scenarios include cyber incident response, table-top exercises, and cyber range exercises.
Paragraph (2)
It is clear enough.
Paragraph (3)
It is clear enough.
Paragraph (4)
Letter a
It is clear enough.
Letter b
Lessons learned are known as lesson learned.
Letter c
It is clear enough.
Article 26
Paragraph (1)
The unit or function responsible for handling the Bank's cyber resilience and security is adjusted to the size and business complexity of the Bank, including the reporting line to the Board of Directors.
Paragraph (2)
It is clear enough.
Article 27
It is clear enough.
Article 28
It is clear enough.
Article 29
Paragraph (1)
What is meant by "using third-party IT service providers" is the use of other parties' services in the Bank's IT management on a continuous basis and/or for a certain period. What is meant by other parties includes:
a. headquarters and other banks' offices abroad or the Bank's business group, for branches of banks located abroad; or b. parent offices and the Bank's business group, for Banks owned by foreign parties.
Furthermore, even though the Bank entrusts IT management to third-party IT service providers, the Bank still acts as the manager of Electronic Systems for every Electronic System used by the Bank in conducting its business activities.
Examples of IT management using third-party IT service providers include the use of cloud computing as the Bank's Data Center and/or Disaster Recovery Center.
Paragraph (2)
Bank's ability to supervise the implementation of Bank activities organized by IT service providers is demonstrated, among other things, by the availability of human resources possessing knowledge or capabilities regarding the IT services provided by the IT service providers.
Paragraph (3)
Clearly stated.
Article 30
Paragraph (1)
Clearly stated.
Paragraph (2)
Letter a
The Bank ensures that the IT service provider has reliable expert personnel, supported by academic and/or professional expertise certificates as required for IT management.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
The term "related parties with the Bank" refers to related parties in accordance with the Financial Services Authority Regulation regarding maximum limits for credit provision and large fund provision for commercial banks or the Financial Services Authority Regulation regarding maximum limits for fund disbursement and large fund disbursement for Sharia commercial banks.
Paragraph (3)
Letter a
Clearly stated.
Letter b
Bank and Bank customer data and/or information are assets that must be secured by the IT service provider by being protected from threats that could interfere with the principles of confidentiality, integrity, and availability. Information in this context includes information regarding systems and devices used to process, store, and transmit information.
Letter c
The term "periodically" refers to the implementation of audits in accordance with the risk level (risk appetite) that the Bank will take against the services provided by the IT service provider. Examples of audit scope conducted by independent auditors include:
Letter d
Clearly stated.
Letter e
The term "critical incident" refers to an incident that can cause significant financial loss and/or disrupt the Bank's operational smoothness.
Letter f
Clearly stated.
Letter g
Includes provisions of legislation regarding work entrusted by the Bank.
Letter h
Clearly stated.
Letter i
Clearly stated.
Paragraph (4)
Letter a
The Bank's responsibility for the application of risk management is carried out, among other things, by ensuring that the IT service provider applies risk management to Bank activities organized by the IT service provider in accordance with this Financial Services Authority Regulation.
Letter b
The term "tested and adequate" means capable of maintaining the Bank's operational continuity in the event of a disaster and/or disruption to the IT infrastructure used by the Bank.
Letter c
Examples of data and/or information security coverage required by the Bank include:
Paragraph (5)
Letter a
The term "periodically" refers to the monitoring and evaluation of the reliability of the IT service provider in accordance with the risk level (risk appetite) that the Bank will take against the services provided by the IT service provider. The Bank uses effective control and monitoring procedures to monitor the performance of the IT service provider and manage risks related to activities entrusted by the Bank, especially if material activities are concentrated on a single IT service provider company.
Letter b
The adequate application of IT controls by the IT service provider considers, among other things, physical security and logical security. Independent parties, for IT service providers that are banks within the same group or business group, include internal auditors.
Letter c
Service level fulfillment is carried out, among other things, by ensuring that IT management can support Bank operations. The service level agreement is known as a service level agreement.
Article 31
Examples of significant changes include changes in ownership or financial conditions of the IT service provider, which can materially change the nature, scale, and complexity of risks inherent in the provision of IT services. Materiality reassessment is known as materiality reassessment.
Article 32
Paragraph (1)
Letter a
Examples of IT service provider performance potentially not running effectively include the IT service provider's inability to support the Bank's business needs.
Letter b
Clearly stated.
Letter c
The term "insolvent" means not having sufficient funds to pay off debts.
Letter d
Clearly stated.
Letter e
Clearly stated.
Letter f
Clearly stated.
Paragraph (2)
Clearly stated.
Paragraph (3)
Indications of supervisory difficulties include:
a. difficulty in obtaining access to data and/or information; b. difficulty in conducting examinations of the IT service provider; and
c. the IT service provider being used as a medium to manipulate Bank data and/or Bank financials.
Paragraph (4)
Letter a
Clearly stated.
Letter b
Clearly stated.
Letter c
The Bank ensures, among other things, that all customer and/or prospective customer data has been returned or destroyed by the IT service provider. Included in the Bank's business activities are services to customers while considering aspects of data confidentiality, integrity, and availability.
Article 33
Clearly stated.
Article 34
Clearly stated.
Article 35
Paragraph (1)
Clearly stated.
Paragraph (2)
Clearly stated.
Paragraph (3)
Letter a
Provisions issued by the authority of the Bank's home country for branch offices are in accordance with the position of the Bank's headquarters outside the territory of Indonesia, while for subsidiaries, it is in accordance with the position of the parent office or main entity office, which is a bank outside the territory of Indonesia.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
Global customer service refers to Front-end Electronic Systems used by the Bank or by customers to obtain Bank services provided globally to all customers, both within the territory of Indonesia and outside the territory of Indonesia, for example, a global cash management system. Meanwhile, Electronic Systems used to process reports to authorities and back-end systems that finally process individual, account, and/or customer transaction data, must remain located within the territory of Indonesia. Back-end systems include:
Letter e
Clearly stated.
Letter f
Electronic Systems used for internal management are systems used by the Bank for internal purposes, which are not directly related to customer service and/or Bank operations. Electronic Systems used for internal management include:
Paragraph (4)
Examples of conditions that significantly disrupt Bank operations include the cessation of services or services from the IT service provider and the absence of other IT service providers in the territory of Indonesia that can provide similar services or services. Before the expiration of the placement period of Electronic Systems at Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia, the Bank conducts an evaluation to determine the availability and reliability of Electronic System providers in the territory of Indonesia.
Article 36
Paragraph (1)
Letter a
Clearly stated.
Letter b
Country risk is known as country risk.
Letter c
The term "does not reduce the effectiveness of Financial Services Authority supervision" means not causing difficulties for the Financial Services Authority in obtaining data and/or information required, such as having access to databases and having a database structure for each application used.
Letter d
Legislation in Indonesia includes, among other things, legislation regarding requirements and procedures for issuing written orders or permits to open Bank secrecy.
Letter e
Clearly stated.
Letter f
Letters of statement are only submitted for IT service providers that have supervisory authority in the financial sector.
Letter g
Bank offices outside the territory of Indonesia:
Letter h
Expected benefits include improved quality of service to customers and the application of anti-money laundering and counter-terrorism financing programs.
Letter i
Clearly stated.
Letter j
Clearly stated.
Paragraph (2)
The term "application documents received completely" means the receipt of documents required in this Financial Services Authority Regulation.
Paragraph (3)
Clearly stated.
Paragraph (4)
Clearly stated.
Article 37
The term "ensuring business continuity" means ensuring that business continuity can continue as it should in the event of a disaster or disruption, including ensuring the readiness of Electronic Systems located in Data Centers and Disaster Recovery Centers. Examples of steps that can be taken to ensure Bank business continuity include the Bank conducting risk assessments of Data Centers and Disaster Recovery Centers, including considering different risk exposures of each Data Center and Disaster Recovery Center. Disaster Recovery Centers include Data Centers that operate simultaneously with other Data Centers so that they can replace each other.
Article 38
Clearly stated.
Article 39
Paragraph (1)
The term "IT-based transaction processing" refers to activities involving the addition, modification, deletion, and/or authorization of data performed on application systems used to process transactions.
Paragraph (2)
Clearly stated.
Paragraph (3)
The Bank is responsible for every transaction whose processing is entrusted to the IT service provider.
Letter a
The term "prudential principles" includes, among other things, risk management in accordance with the Financial Services Authority Regulation regarding the application of risk management for commercial banks or the Financial Services Authority Regulation regarding the application of risk management for Sharia commercial banks and Sharia business units.
Letter b
Clearly stated.
Letter c
The relationship between the Bank and customers is based on agreements while considering, among other things, the Financial Services Authority Regulation regarding consumer protection and the Financial Services Authority Regulation regarding consumer complaint services in the financial services sector.
Paragraph (4)
The management of IT-based transaction processing outside the territory of Indonesia includes that conducted at the headquarters or other bank offices for branch offices of banks headquartered abroad or parent offices for Banks owned by foreign financial institutions.
Paragraph (5)
Letter a
Clearly stated.
Letter b
The term "supporting financial administrative documents" refers to data that serves as evidence of rights and obligations and the business activities of a company and is used to support the preparation of financial reports. Examples include: credit or financing agreements and credit or financing disbursement documents, deal slips and deal confirmations from treasury transactions, and data transfer order documents via Society for Worldwide Interbank Financial Telecommunication (SWIFT).
Letter c
Efforts to increase the Bank's role in the development of the Indonesian economy are reflected, among other things, in plans to increase credit or financing provision and increase export-import financing.
Paragraph (6)
Clearly stated.
Paragraph (7)
Clearly stated.
Article 40
Clearly stated.
Article 41
Clearly stated.
Article 42
Clearly stated.
Article 43
Paragraph (1)
Forms of data processing include, among other things, acquisition, distribution, processing, maintenance, storage, and deletion of data.
Paragraph (2)
Letter a
Data ownership and data stewardship explain the roles and responsibilities of each part of the Bank organization involved in data management.
Letter b
The term "data quality" refers to the reliability and accuracy of data, among other things, for business analysis and risk reporting.
Letter c
Data management systems are adjusted to the needs and complexity of the Bank. Data management systems include:
Letter d
Supporting resources for data management include:
Paragraph (3)
Clearly stated.
Article 44
Paragraph (1)
Personal data and personal data protection principles are in accordance with legislation regarding personal data protection.
Paragraph (2)
Examples of specific conditions include:
a. use of new technology; b. tracking of customer location and behavior;
c. monitoring of public facility locations on a large scale; and
d. processing of sensitive personal data related to ethnicity, religion, race, and inter-ethnicity.
The term "owner of personal data" refers to Bank customers and/or prospective Bank customers.
Article 45
Paragraph (1)
Letter a
Clearly stated.
Letter b
The parties involved in the exchange of personal data include:
Letter c
The establishment of personal data exchange agreements is carried out, including for emergency conditions.
Letter d
Clearly stated.
Letter e
Clearly stated.
Paragraph (2)
Clearly stated.
Article 46
Clearly stated.
Article 47
Clearly stated.
Article 48
Paragraph (1)
The provision of IT services by the Bank, namely the provision of services involving the utilization of the Bank's IT infrastructure to financial service institutions, is based on a cooperation agreement and/or lease agreement between both parties. Examples of IT service provision include the management of Data Centers, Disaster Recovery Centers, and applications.
Paragraph (2)
Letter a
Clearly stated.
Letter b
Prudential principles are applied while considering, among other things:
Letter c
Clearly stated.
Letter d
Clearly stated.
Letter e
Clearly stated.
Paragraph (3)
Clearly stated.
Paragraph (4)
Letter a
The term "group or cluster" refers to financial service institutions that have ownership and/or control linkages. Examples: subsidiaries and sister companies.
Letter b
The provision of applications is not intended for Banks to build special applications for financial service institutions other than banks. Examples of applications intended to support general operational activities include remuneration systems and personnel systems.
Article 49
Clearly stated.
Article 50
Clearly stated.
Article 51
Clearly stated.
Article 52
Clearly stated.
Article 53
Paragraph (1)
The general principles for the implementation of IT internal control systems are carried out in accordance with:
a. Financial Services Authority Regulation regarding the application of risk management for commercial banks; b. Financial Services Authority Regulation regarding the application of risk management for Sharia commercial banks and Sharia business units; and/or
c. Financial Services Authority provisions regarding guidelines for standard internal control systems for commercial banks.
Paragraph (2)
Letter a
Clearly stated.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
Clearly stated.
Letter e
Includes monitoring and correction regarding the compliance of IT management with existing agreements and legislation. The term "other parties" refers to internal Bank parties such as the Bank's compliance unit or function.
Paragraph (3)
The term "adequate" includes, among other things, technology suitable for the Bank's operational activities, competent human resources, and an organizational structure that does not provide opportunities to commit and/or conceal errors or deviations.
Paragraph (4)
Clearly stated.
Article 54
Paragraph (1)
Clearly stated.
Paragraph (2)
Clearly stated.
Paragraph (3)
The use of external parties to perform internal IT audit functions does not reduce the responsibility of the head of the internal audit unit. Furthermore, the use of external parties must consider the size and complexity of the Bank's business. In using external parties to perform internal IT audit functions, the Bank considers the confidentiality of data and/or information at the Bank to be accessed by external parties.
Paragraph (4)
Clearly stated.
Article 55
Paragraph (1)
IT management includes that for Banks using IT service providers.
Paragraph (2)
Clearly stated.
Paragraph (3)
Letter a
Clearly stated.
Letter b
The term "IT internal audit results" refers to the complete report of IT internal audit results.
Article 56
Clearly stated.
Article 57
Clearly stated.
Article 58
Paragraph (1)
The IT development plan is a document detailing the IT development plan for a period of 1 (one) year as contained in the Bank's IT strategic plan.
Paragraph (2)
Clearly stated.
Paragraph (3)
Certain considerations include, among other things, supporting the implementation of policies and/or regulations in the financial services sector and/or government to encourage economic development.
Paragraph (4)
Clearly stated.
Article 59
This report contains the condition of the Bank's IT management, including changes made during the 1 (one) year reporting period.
Article 60
Paragraph (1)
IT incidents are critical incidents, misuse, and/or crimes in IT management, including:
a. cyber incidents; and b. non-cyber incidents.
The term "loss" refers to financial loss and/or non-financial loss. Examples of non-financial loss include negative news affecting the Bank's reputation. Cyber incidents are cyber threats, namely efforts, activities, and/or actions that cause Electronic Systems to not function as they should. Examples of cyber incidents include the failure of Electronic Systems to function as they should caused by cyber attacks such as hacking, viruses, malware, ransomware, web defacement, and distributed denial of service attacks.
Paragraph (2)
Initial notification is submitted to the Bank's supervisory unit. Examples of written electronic media include official email.
Paragraph (3)
Clearly stated.
Paragraph (4)
Clearly stated.
Paragraph (5)
Clearly stated.
Article 61
Paragraph (1)
The realization report includes post-implementation review.
Paragraph (2)
Clearly stated.
Article 62
Clearly stated.
Article 63
Clearly stated.
Article 64
Clearly stated.
Article 65
Clearly stated.
Article 66
Paragraph (1)
The Bank's digital maturity level reflects the fulfillment of all aspects in IT management in accordance with this Financial Services Authority Regulation and the Bank's readiness to support digital transformation. Self-assessment of the Bank's digital maturity level is carried out periodically while considering changes in the Bank's internal and external conditions. Examples of internal condition changes include changes in the Bank's business objectives and strategies. Examples of external condition changes include IT developments.
Paragraph (2)
Clearly stated.
Paragraph (3)
Clearly stated.
Paragraph (4)
Clearly stated.
Paragraph (5)
Clearly stated.
Paragraph (6)
Clearly stated.
Article 67
Clearly stated.
Article 68
Clearly stated.
Article 69
Clearly stated.
Article 70
Clearly stated.
Article 71
Clearly stated.
Article 72
Clearly stated.
Article 73
Clearly stated.
SUPPLEMENT TO THE STATE GAZETTE OF THE REPUBLIC OF INDONESIA NUMBER 5/OJK
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.