2026-07-03

Added

Regulation on information and communication technologies and security risk management

The Central Bank of the Republic of Kosovo establishes requirements for financial institutions, including payment service providers, banks, and microfinance institutions, to manage operational and security risks related to Information and Communication Technologies. The regulation mandates that management bodies ensure adequate governance, define ICT strategies aligned with business objectives, and implement risk management frameworks that include annual risk assessments and independent audits. It further requires specific controls for third-party outsourcing, logical and physical security, access management, and staff training to protect information assets and ensure service continuity.

Central Bank of the Republic of Kosovo logo

Kosovo

Central Bank of the Republic of Kosovo

Click to view full text