2026-07-03

Added · Updated

Regulation on information and communication technologies and security risk management

The Central Bank of the Republic of Kosovo establishes requirements for financial institutions, including payment service providers, banks, and microfinance institutions, to manage operational and security risks related to Information and Communication Technologies. The regulation mandates that management bodies ensure adequate governance, define ICT strategies aligned with business objectives, and implement risk management frameworks that include annual risk assessments and independent audits. It further requires specific controls for third-party outsourcing, logical and physical security, access management, and staff training to protect information assets and ensure service continuity.

Central Bank of the Republic of Kosovo logo

Kosovo

Central Bank of the Republic of Kosovo

Scan of the document's first page
Share

CBK published 3 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: In force

Ligji Nr. 03/L-209 për Bankën Q…2010Ligji Nr. 03/L-209 për Bankën Qendrore të Republikës së Kosovës (Law No. 03/L-209 on the Central Bank of the Republic of Kosovo) (2010-08-16)Law No. 05/L-150 dated 2017-04-…Law No. 05/L-150 dated 2017-04-03Law No. 10/L-026 dated 2026-05-…Law No. 10/L-026 dated 2026-05-14Regulation on information andcommunication technologies an…2026-07-03 · this documentRegulation on information and communication technologies and security risk management (2026-07-03)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Central Bank of the Republic of Kosovo — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from CBK

CBK published 3 documents in the last 30 days. We email you each new one the day it's published.