This document presents the EBA guidelines on the management of information and communication technology and security risks. It establishes compliance and reporting obligations for competent authorities and financial institutions. The guidelines aim to enhance operational resilience and security of payment services within the European Union.
This document is the consolidated version of the European Banking Authority (EBA) guidelines on the management of risks related to information and communication technologies (ICT) and security. Published on 19 May 2026, it incorporates amendments adopted up to 20 May 2025. It is addressed to competent authorities and payment service providers within the European Union, in accordance with European regulations and directives such as Regulation (EU) No 1093/2010, Directive (EU) 2015/2366 (PSD2), and the Digital Operational Resilience Act (DORA). The scope covers the management of operational and security risks related to payment services, including the relationship with users of these services (p. 1-4).
The consolidated EBA guide on ICT risk management and security aims to harmonize practices of payment service providers and supervisory authorities within the European Union. It responds to the growing need to strengthen operational resilience and security of payment services against digital threats. The guidelines specify providers' obligations to establish, implement, and monitor appropriate security measures, complementing the requirements of DORA and PSD2. They notably emphasize managing the relationship with users, recommending processes to increase their risk awareness, provide continuous assistance, allow customization of payment features, adjust spending limits, and provide alerts on suspicious transactions. Competent authorities must notify their compliance to the EBA before 20 May 2025, under penalty of being considered non-compliant. These guidelines enhance electronic payment security by improving governance, risk management, and communication with users, thus contributing to the stability of the European financial sector (p. 1-6).
This document was developed under the mandate conferred to the EBA by Regulation (EU) No 1093/2010 and the PSD2 Directive to define appropriate supervisory practices regarding ICT risk management and security. The objective is to complement the measures provided by the Digital Operational Resilience Act (DORA) to ensure robust management of operational and security risks related to payment services. The guide aims to frame payment service providers and competent authorities by specifying requirements for implementing security measures, governance, and managing the relationship with users. The scope covers providers subject to PSD2, including some exempted, and European supervisory authorities. The document's limits lie in its exclusive focus on payment services and associated ICT risks, without addressing other financial sectors (p. 2-4).
Application and compliance: The guidelines apply no later than 20 May 2025. Competent authorities must notify their compliance to the EBA before this date via an official form, under penalty of being considered non-compliant. These notifications will be published on the EBA website (p. 2, 4).
Regulatory framework and scope: The guide is based on Regulation (EU) No 1093/2010, the PSD2 Directive, and DORA. It targets payment service providers defined by PSD2, including some exempted, as well as European competent authorities (p. 2-4).
ICT risk management and security: Although sections detailing governance, strategy, risk management, information security, ICT operations management, projects, and business continuity are removed in this version, they constitute the underlying regulatory foundation (p. 5).
Management of the relationship with payment service users: This theme is explicitly developed. Providers must implement processes to raise users' awareness of security risks, provide assistance and updated advice in response to new threats, allow disabling certain payment features when technology permits, offer the possibility to adjust spending limits within contractual agreements, send alerts on initiated or failed transactions to detect fraud, and inform users of updates to security procedures. Assistance must be accessible and clearly communicated to users (p. 6).
Established facts:
- The guidelines are legally binding for competent authorities and strongly recommended for payment service providers, with an application date set at 20 May 2025 (p. 2, 4).
- They complement the existing regulatory framework, notably PSD2 and DORA, emphasizing ICT risk management and security (p. 3).
- Managing the relationship with users is a key component, with precise measures to improve awareness, service customization, fraud detection, and assistance (p. 6).
Assumptions:
- The document assumes providers have the technical capabilities to implement the recommended features, such as disabling certain functions or sending alerts (p. 6).
Interpretations:
- The EBA considers that strengthening communication and interaction with users is essential to reduce risks related to electronic payments.
Uncertainties:
- The document does not detail precise technical modalities nor quantitative thresholds for certain measures, leaving room for interpretation by providers and authorities (p. 6).
The EBA concludes that rigorous implementation of these guidelines is essential to ensure operational resilience and security of payment services within the European Union. It recommends competent authorities ensure providers' compliance and update their supervisory frameworks accordingly. Providers must adopt robust processes to manage ICT risks, notably by strengthening the management of the relationship with users through concrete measures of assistance, awareness, feature customization, and fraud detection. Mandatory notification of compliance before 20 May 2025 is a key element of the framework. These measures are priorities to preserve user trust and the stability of the European financial sector (p. 2-6).
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.