2025-12-17

Added · Updated

Regulation on the Management of Information Technology by Rural Banks and Sharia Rural Banks

This Regulation of the Board of Commissioners of the Financial Services Authority establishes minimum standards and guidelines for the implementation of Information Technology (IT) by Rural Banks (BPR) and Sharia Rural Banks (BPR Syariah). It requires these banks to adjust and implement IT policies and procedures, including provisions for IT governance, architecture, risk management, cyber resilience and security, and data protection. The regulation mandates that BPR and BPR Syariah place their Electronic Systems, Data Centers, and Disaster Recovery Centers within Indonesia and conduct annual cyber security maturity level assessments. This regulation repeals OJK Circular Letter No. 15/SEOJK.03/2017 and becomes effective one year from its stipulation date of December 17, 2025.

Otoritas Jasa Keuangan (Financial Services Authority) logo

Indonesia

Otoritas Jasa Keuangan (Financial Services Authority)

Click to view thumbnail

COPY REGULATION OF THE BOARD OF COMMISSIONERS FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA NUMBER 43/PADK.03/2025 CONCERNING THE IMPLEMENTATION OF INFORMATION TECHNOLOGY BY RURAL BANKS AND SHARIA RURAL BANKS BY THE GRACE OF GOD ALMIGHTY THE MEMBER OF THE BOARD OF COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY, Considering: that to implement the provisions as referred to in Article 8, Article 12, Article 21, Article 25, Article 29, Article 33, Article 37, Article 41, and Article 48 of Financial Services Authority Regulation Number 34 of 2025 concerning the Implementation of Information Technology by Rural Banks and Sharia Rural Banks, and to realize the increase in the utilization of information technology and the strengthening of governance, risk management, as well as cyber resilience and security in the implementation of information technology by rural banks and sharia rural banks, it is necessary to stipulate the Regulation of the Member of the Board of Commissioners of the Financial Services Authority concerning the Implementation of Information Technology by Rural Banks and Sharia Rural Banks; Recalling: 1. Law Number 21 of 2011 concerning the Financial Services Authority (State Gazette of the Republic of Indonesia Year 2011 Number 111, Supplement to the State Gazette of the Republic of Indonesia Number 5253) as amended by Law Number 4 of 2023 concerning the Development and Strengthening of the Financial Sector (State Gazette of the Republic of Indonesia Year 2023 Number 4, Supplement to the State Gazette of the Republic of Indonesia Number 6845); 2. Financial Services Authority Regulation Number 34 of 2025 concerning the Implementation of Information Technology by Rural Banks and Sharia Rural Banks (State Gazette of the Republic of Indonesia Year 2025 Number 46/OJK, Supplement to the State Gazette of the Republic of Indonesia Number 175/OJK);

  • 2 - DECIDES: Stipulates: THE REGULATION OF THE MEMBER OF THE BOARD OF COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY CONCERNING THE IMPLEMENTATION OF INFORMATION TECHNOLOGY BY RURAL BANKS AND SHARIA RURAL BANKS. Article 1 In this Regulation of the Member of the Board of Commissioners of the Financial Services Authority, what is meant by:
  1. Rural Bank, hereinafter abbreviated as BPR, is a type of conventional bank that in its activities does not directly provide services in giro traffic.
  2. Sharia Rural Bank, hereinafter referred to as BPR Syariah, is a type of sharia bank that in its activities does not directly provide services in giro traffic.
  3. Information Technology, hereinafter abbreviated as IT, is a technique for collecting, preparing, storing, processing, publishing, analyzing, and/or disseminating information. Article 2 This Regulation of the Member of the Board of Commissioners of the Financial Services Authority regulates guidelines for the implementation of IT by BPR and BPR Syariah as a reference for the minimum standards that must be met by BPR and BPR Syariah in the implementation of IT. Article 3 The guidelines for the implementation of IT by BPR and BPR Syariah as referred to in Article 2 are contained in: a. Annex I which contains provisions regarding the implementation of IT by BPR and BPR Syariah; b. Annex II which contains provisions regarding the application of governance and policies and procedures for IT implementation by BPR and BPR Syariah; c. Annex III which contains provisions regarding IT implementation risk management by BPR and BPR Syariah; d. Annex IV which contains guidelines for cyber resilience and security of BPR and BPR Syariah; e. Annex V which contains provisions regarding data management and personal data protection of BPR and BPR Syariah; and f. Annex VI which contains the format for IT implementation reports by BPR and BPR Syariah, which are an inseparable part of this Regulation of the Member of the Board of Commissioners of the Financial Services Authority. Article 4 BPR and BPR Syariah shall adjust, refine, and implement policies, procedures, and the execution of IT implementation in accordance with this Regulation of the Member of the Board of Commissioners of the Financial Services Authority.
  • 3 - This copy is in accordance with the original Head of Legal Development Directorate Legal Department signed. Aat Windradi Article 5 BPR and BPR Syariah shall formulate and develop IT implementation guidelines in accordance with the needs and operational complexity of their business, strategies, and vision and mission, referring to the guidelines as referred to in Article 2. Article 6 When this Regulation of the Member of the Board of Commissioners of the Financial Services Authority comes into force, Financial Services Authority Circular Letter Number 15/SEOJK.03/2017 concerning Standards for Information Technology Implementation for Rural Credit Banks and Sharia Financing Banks, is revoked and declared invalid. Article 7 This Regulation of the Member of the Board of Commissioners of the Financial Services Authority shall come into force 1 (one) year from the date of its stipulation. Stipulated in Jakarta on December 17, 2025 CHIEF EXECUTIVE OF BANKING SUPERVISION FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA, signed. DIAN EDIANA RAE

ANNEX I REGULATION OF THE BOARD OF COMMISSIONERS FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA NUMBER 43/PADK.03/2025 CONCERNING THE IMPLEMENTATION OF INFORMATION TECHNOLOGY BY RURAL BANKS AND SHARIA RURAL BANKS

  • 1 - PROVISIONS REGARDING THE IMPLEMENTATION OF INFORMATION TECHNOLOGY BY RURAL BANKS AND SHARIA RURAL BANKS

  • 2 - TABLE OF CONTENTS I. IT GOVERNANCE OF BPR AND BPR SYARIAH 3 II. IT ARCHITECTURE OF BPR AND BPR SYARIAH 4 III. APPLICATION OF IT RISK MANAGEMENT OF BPR AND BPR SYARIAH 5 IV. CYBER RESILIENCE AND SECURITY OF BPR AND BPR SYARIAH 5 V. USE OF THIRD-PARTY IT SERVICE PROVIDERS IN IT IMPLEMENTATION OF BPR AND BPR SYARIAH 8 VI. CORE BANKING APPLICATIONS AND PLACEMENT OF ELECTRONIC SYSTEMS 8 VII. DATA MANAGEMENT AND PERSONAL DATA PROTECTION IN IT IMPLEMENTATION OF BPR AND BPR SYARIAH 9 VIII. INTERNAL CONTROL AND AUDIT OF BPR AND BPR SYARIAH IN IT IMPLEMENTATION OF BPR AND BPR SYARIAH 9 IX. REPORTING 10

  • 3 - I. IT GOVERNANCE OF BPR AND BPR SYARIAH

  1. Implementation of Good IT Governance a. In accordance with Article 2 of the OJK Regulation on IT Implementation for BPR and BPR Syariah, BPR and BPR Syariah are obliged to implement good IT governance. b. In implementing good IT governance as referred to in letter a, BPR and BPR Syariah shall consider at least the following factors:
  1. business strategy and objectives of BPR and BPR Syariah;
  2. business scale and complexity of BPR and BPR Syariah;
  3. the role of IT for BPR and BPR Syariah;
  4. methods of IT resource procurement;
  5. IT-related risks and issues;
  6. nationally and internationally applicable practices or standards; and
  7. provisions of laws and regulations.
  1. IT Implementation Policies and Procedures a. In formulating IT implementation policies and procedures, BPR and BPR Syariah shall refer to the IT implementation strategy. b. The IT implementation strategy shall include, among others, plans for IT development and procurement, as well as human resource development related to IT implementation in accordance with the Financial Services Authority Regulation concerning business plans for rural credit banks and sharia financing banks. c. The formulation of IT implementation policies and procedures shall be carried out in accordance with the needs and business complexity of BPR and BPR Syariah, covering at least those listed in Annex II, which is an inseparable part of this Regulation of the Member of the Board of Commissioners of the Financial Services Authority. d. IT implementation policies and procedures shall cover at least:
  1. authority and responsibility of the Board of Directors, Board of Commissioners, and work units or employees responsible for IT implementation;
  2. development and procurement;
  3. IT operations;
  4. communication networks;
  5. information security;
  6. disaster recovery plan;
  7. IT internal audit; and
  8. use of third-party IT service providers (PPJTI). e. BPR and BPR Syariah shall review and update IT implementation policies and procedures as referred to in letter d periodically in accordance with needs, current conditions, and compliance with laws and regulations. f. In accordance with Article 58 paragraph (2) of OJK Regulation Number 9 of 2024 concerning the Implementation of Governance for BPR and BPR Syariah, the Board of Directors may form other committees adjusted to the issues, business scale, and/or complexity of BPR and BPR Syariah, for example, if BPR and BPR Syariah provide digital services and consider the results of cyber security maturity level assessment. Such other committees include, among others, the IT steering committee.
  • 4 - g. The IT steering committee shall consist of:
  1. a member of the Board of Directors who oversees the IT implementation work unit or function;
  2. a member of the Board of Directors who oversees the risk management function;
  3. the highest official leading the work unit or function responsible for IT implementation; and
  4. the highest official leading the IT user work unit or function. h. The IT steering committee shall be chaired by one of the members of the Board of Directors who also serves as a member. The authority and responsibility of the IT steering committee are listed in Annex II, which is an inseparable part of this Regulation of the Member of the Board of Commissioners of the Financial Services Authority. II. IT ARCHITECTURE OF BPR AND BPR SYARIAH
  1. BPR and BPR Syariah that provide digital services shall formulate IT architecture in a written document accompanied by explanations for each domain.
  2. IT architecture is a documentation of BPR and BPR Syariah that describes the network topology and applications owned and/or managed by BPR and BPR Syariah.
  3. BPR and BPR Syariah that provide digital services shall formulate comprehensive IT architecture covering the following processes: a. Planning BPR and BPR Syariah shall determine the direction of IT implementation development, including vision, objectives, and scope of IT implementation aligned with business strategy. b. Design BPR and BPR Syariah shall formulate the desired IT architecture design, including a transition plan from the current IT architecture to the desired IT architecture. In formulating the IT architecture design, factors such as business strategy and needs, gap analysis, and implementation phase plans need to be considered. c. Implementation BPR and BPR Syariah shall implement the implementation phases in accordance with the IT architecture design and ensure that each phase is aligned with the formulated IT architecture. d. Control BPR and BPR Syariah shall ensure compliance with the vision, objectives, and scope of the IT architecture and evaluate constraints during the implementation phases, including reporting deviations and formulating recommendations for improvement.
  4. The formulation of IT architecture shall consider 3 (three) domains, namely: a. Data architecture Data architecture defines data types, data processing needs, and data and information flows required. b. Application architecture Application architecture defines the development of each application, interactions between applications, and the relationship of applications with key business processes in BPR and BPR Syariah.
  • 5 - c. Technology architecture Technology architecture defines the capabilities of hardware and software to support data architecture and application architecture. Technology architecture includes, among others, IT infrastructure, middleware, networks, communication, processing, and standards.
  1. BPR and BPR Syariah that provide digital services shall update their IT architecture periodically, considering needs, current conditions, and compliance with laws and regulations, in accordance with the procedures and policies of BPR and BPR Syariah. III. APPLICATION OF IT RISK MANAGEMENT OF BPR AND BPR SYARIAH
  2. BPR and BPR Syariah shall implement risk management for all IT implementation, in accordance with IT implementation policies and procedures.
  3. The IT implementation policies and procedures as referred to in point 1 shall be applied by BPR and BPR Syariah to mitigate risks related to IT implementation.
  4. The application of IT implementation risk management shall refer to the guidelines as listed in Annex III, which is an inseparable part of this Regulation of the Member of the Board of Commissioners of the Financial Services Authority. IV. CYBER RESILIENCE AND SECURITY OF BPR AND BPR SYARIAH
  5. BPR and BPR Syariah shall implement cyber resilience and security for all IT implementation.
  6. Cyber Resilience and Security a. Cyber resilience is the ability of BPR and BPR Syariah to maintain business continuity by taking anticipatory and adaptive actions against cyber threats. b. Cyber security is the condition of maintaining the confidentiality, integrity, and availability of information and/or information systems that are interconnected through cyber media from cyber attacks. Cyber security includes aspects such as authenticity, accountability, non-repudiation, and reliability. c. BPR and BPR Syariah shall maintain cyber resilience and security by carrying out the following processes:
  1. Identification of assets, threats, and vulnerabilities BPR and BPR Syariah shall at least: a) implement asset management through effective inventory and assessment of IT assets (including hardware, software, networks, and infrastructure) and configuration recording; b) identify vulnerabilities and monitor current cyber developments to identify cyber threats; and c) conduct periodic cyber security testing.
  2. Asset protection BPR and BPR Syariah shall at least: a) implement comprehensive security controls in accordance with the results of asset, threat, and vulnerability identification;
  • 6 - b) perform maintenance and repair of security controls over IT assets; c) implement a well-managed security system; d) periodically update security controls to ensure the adequacy of security controls used in accordance with the latest results of the identification process; e) implement data and information security management and ensure that data and/or information are managed in accordance with the organization's risk management strategy to protect the confidentiality, integrity, and availability of data and information; f) implement protection management for networks, hardware, and software; g) implement protection management for access and users to prevent unauthorized actions on devices, network infrastructure, and system components managed by BPR and BPR Syariah; h) implement adequate protection in cooperation between BPR and BPR Syariah and third-party IT service providers (PPJTI), including in the use of cloud; i) ensure the implementation of secure coding in system and application development to minimize system and application vulnerabilities; and j) ensure that patching runs well and ensure the reliability and up-to-dateness of software components, communication networks, databases, and operating systems of BPR and BPR Syariah.
  1. Detection of cyber incidents BPR and BPR Syariah shall at least: a) ensure the availability of baseline performance documentation for critical functions of BPR and BPR Syariah and supporting systems so that deviations are detected in a timely manner and anomalous activities can be flagged for follow-up; b) monitor suspicious activities and manage and test detection processes and procedures to ensure anomalous activities are detected in a timely manner; and c) conduct threat and vulnerability analysis of a cyber incident to ensure effective incident handling to prevent disruptions to services and/or operations of BPR and BPR Syariah.
  2. Cyber incident response and recovery BPR and BPR Syariah shall at least: a) establish a cyber incident response and recovery plan to ensure timely response and restoration of services in accordance with the risks posed, with minimal impact; b) establish the roles, duties, and responsibilities of the cyber incident response team to ensure cyber incident response and recovery are carried out with minimal impact on the services and operations of BPR and BPR Syariah; c) implement recovery procedures and efforts to prevent the spread of the impact of cyber incidents by mitigating the impact and responding to the cyber incident; d) conduct analysis to ensure that cyber incident response and recovery steps are carried out correctly; e) escalate and report cyber incidents in accordance with established communication channels; and f) conduct post-incident analysis as lessons learned in cyber incident response and recovery for continuous improvement. d. BPR and BPR Syariah shall conduct periodic cyber security testing on network, system, and data security as a step to maximize efforts to maintain the cyber security of BPR and BPR Syariah. Cyber security testing is divided into 2 (two), namely cyber security testing based on:
  3. vulnerability analysis; and
  4. scenarios. e. Cyber security testing based on vulnerability analysis is carried out by looking at the weak points of the BPR and BPR Syariah systems. f. Cyber security testing based on scenarios is carried out to validate the cyber incident response and recovery process at BPR and BPR Syariah, including the communication plan of BPR and BPR Syariah in facing cyber threats. g. The mechanism for cyber security testing shall refer to the guidelines as listed in Annex IV, which is an inseparable part of this Regulation of the Member of the Board of Commissioners of the Financial Services Authority. h. BPR and BPR Syariah may conduct cyber security testing independently or use a third party. In the event that cyber security testing uses a third party, BPR and BPR Syariah must:
  5. ensure that the third party has adequate competence in accordance with the needs of cyber security testing. The competence of the third party is evidenced, among others, by certification and/or recognition from authorized institutions in Indonesia or abroad; and
  6. remain responsible for the implementation of cyber security testing. i. BPR and BPR Syariah shall adequately document and secure the results of cyber security testing that has been carried out to maintain the confidentiality of the cyber security testing results.
  1. Function Handling Cyber Resilience and Security a. BPR and BPR Syariah shall establish a function tasked with handling the cyber resilience and security of BPR and BPR Syariah.
  • 8 - b. The function handling cyber resilience and security has the task of implementing and/or coordinating:
  1. cyber resilience processes;
  2. assessment of the cyber security maturity level and reporting periodically to the Board of Directors;
  3. cyber security testing; and
  4. the cyber response team, including its initiation.
  1. Cyber Security Maturity Level Assessment a. BPR and BPR Syariah shall conduct a cyber security maturity level assessment. This assessment shall be carried out annually for the position at the end of December. BPR and BPR Syariah may update this assessment at any time if necessary. b. BPR and BPR Syariah shall document the results of the cyber security maturity assessment. c. The Financial Services Authority may at any time request the results of the cyber security maturity level assessment as referred to in letter a. d. The results of the cyber security maturity level assessment may be considered in the operational risk management assessment of BPR and BPR Syariah. e. The procedure for cyber security maturity level assessment shall refer to the guidelines as listed in Annex IV, which is an inseparable part of this Regulation of the Member of the Board of Commissioners of the Financial Services Authority. V. USE OF THIRD-PARTY IT SERVICE PROVIDERS IN IT IMPLEMENTATION OF BPR AND BPR SYARIAH
  2. BPR and BPR Syariah may use third-party IT service providers (PPJTI) in IT implementation.
  3. The mechanism for using PPJTI shall refer to the guidelines as listed in Annex II, which is an inseparable part of this Regulation of the Member of the Board of Commissioners of the Financial Services Authority. VI. CORE BANKING APPLICATIONS AND PLACEMENT OF ELECTRONIC SYSTEMS
  4. In the development and maintenance of Electronic Systems, including Core Banking Applications, BPR and BPR Syariah shall carry out the stages as referred to in Annex II, which is an inseparable part of this Regulation of the Member of the Board of Commissioners of the Financial Services Authority.
  5. BPR and BPR Syariah shall place Electronic Systems in the form of Data Centers and Disaster Recovery Centers within the territory of Indonesia.
  6. BPR and BPR Syariah shall ensure that Data Centers and Disaster Recovery Centers guarantee the business continuity of BPR and BPR Syariah. What is meant by “guaranteeing business continuity” is ensuring that business continuity can proceed as it should in the event of a disaster or disruption, including ensuring the readiness of Electronic Systems located at Data Centers and Disaster Recovery Centers. Examples of steps that can be taken to guarantee the business continuity of BPR and BPR Syariah include BPR and BPR Syariah conducting risk assessments of Data Centers and Disaster Recovery Centers, including by considering the different risk exposures of each Data Center and Disaster Recovery Center. Disaster Recovery Centers include Data Centers that operate concurrently with other Data Centers so that they can replace each other. VII. DATA MANAGEMENT AND PERSONAL DATA PROTECTION IN IT IMPLEMENTATION OF BPR AND BPR SYARIAH
  7. Data Management Data management shall consider at least: a. data quality; b. data management system; and c. supporting resources for data management. The implementation of data management shall refer to the guidelines as listed in Annex V, which is an inseparable part of this Regulation of the Member of the Board of Commissioners of the Financial Services Authority.
  8. Personal Data Protection BPR and BPR Syariah shall implement personal data protection principles in processing personal data, which includes activities such as: a. acquisition and collection; b. processing; c. storage; d. transfer or dissemination; and/or e. deletion or destruction. The implementation of personal data protection shall refer to the guidelines as listed in Annex V, which is an inseparable part of this Regulation of the Member of the Board of Commissioners of the Financial Services Authority. VIII. INTERNAL CONTROL AND AUDIT OF BPR AND BPR SYARIAH IN IT IMPLEMENTATION OF BPR AND BPR SYARIAH
  9. BPR and BPR Syariah shall implement an effective internal control system in IT implementation.
  10. Internal control is carried out to ensure compliance of BPR and BPR Syariah with internal provisions and laws and regulations, effectiveness and efficiency of operational activities, availability of complete, accurate, current, and intact risk management information, and effectiveness of risk management culture.
  11. The implementation of internal control over IT implementation shall be in accordance with the Financial Services Authority Regulation concerning the application of risk management for rural credit banks and the Financial Services Authority Regulation concerning the application of risk management for sharia financing banks.
  12. In the event that IT implementation is carried out by a third-party IT service provider (PPJTI), BPR and BPR Syariah must have a monitoring mechanism to ensure that the PPJTI has carried out the work or provided services in accordance with the agreement.
  13. BPR and BPR Syariah shall ensure that the work of the PPJTI is carried out in accordance with policies and procedures.
  14. BPR and BPR

[RegAlert note: the English text above is a translation of the first 24,000 characters of a 470,719-character original (5% of the document). The remainder was not translated. The complete original-language text is stored with this document.]

More like this from OJK

OJK published 1 document in the last 30 days. We email you each new one the day it's published.

Topics
Share