Standards
EBA/GL/2019/04EBA

Guidelines on ICT and security risk management

The text that prefigured DORA for the European banking sector. It details ICT risk governance, information security, operations management, project and change management, and ICT business continuity — at a granularity DORA largely inherited.

Official text

Who it applies to

  • EU banks and PSPs
  • Banking compliance teams
  • Financial sector internal audit

Structuring points

  • The business impact analysis must feed ICT continuity plans directly
  • Test scenarios must include severe but plausible cases
  • The guidelines remain applicable alongside DORA where not superseded

EU credit institutions, investment firms and payment service providers.