This final report presents amendments to the guidelines on ICT risk and security management, initially published by the EBA in 2019. These guidelines aim to establish requirements for financial institutions to effectively manage ICT and security risks, in compliance with the DORA directive that will come into effect in January 2025. The entities concerned include credit institutions, payment institutions, and other…
- Document: Final report on the amendment of EBA/GL/2019/04 guidelines on ICT and security risk management.
- Author: European Banking Authority (EBA).
- Date: 11 February 2025.
- Type: regulatory guide.
- Scope: credit institutions, investment firms, payment service providers (PSPs) within the European Union.
- Context: integration of the Digital Operational Resilience Act (DORA) applicable from 17 January 2025, impacting ICT and security risk management requirements.
- Objective: adapt existing EBA guidelines to ensure consistency and compliance with DORA, specifying the scope and applicable requirements.
The EBA final report amends the EBA/GL/2019/04 guidelines on ICT and security risk management to align these requirements with the new regulatory framework introduced by DORA, applicable from 17 January 2025 (p. 3). These guidelines aimed to harmonize practices of financial institutions, notably credit institutions, investment firms, and PSPs, regarding ICT and security risk management (p. 3). With the entry into force of DORA, which covers a wide range of financial entities and introduces harmonized requirements on ICT risk management, most provisions of the EBA guidelines become redundant or obsolete (p. 3-4). The EBA therefore decided to reduce the scope of the amended guidelines, retaining only Guideline 3.8 concerning the management of relationships with payment service users, which is not covered by DORA (p. 4). Other parts of the guidelines are repealed, notably those relating to authentication methods, information security policy, and ICT operations management, now covered by DORA (p. 5). Post office giro institutions, excluded from DORA’s scope, remain subject to the EBA guidelines, although their number and market share are very limited (11 institutions in 11 Member States, often without significant weight) (p. 4). Competent national authorities may also apply additional national requirements to PSPs not covered by DORA (p. 4). Implementation of the amended guidelines is scheduled for 20 May 2025, with an obligation for competent authorities to notify their compliance to the EBA (p. 8-9). In conclusion, this report clarifies and simplifies the regulatory framework applicable to ICT and security risks in the financial sector, avoiding overlaps between DORA and the EBA guidelines, while maintaining specific requirements for certain actors not covered by DORA. Authorities are recommended to integrate these changes into their practices and notify their compliance within the prescribed deadlines.
The initial EBA/GL/2019/04 guidelines, published in November 2019, aimed to harmonize ICT and security risk management for credit institutions, investment firms, and PSPs in accordance with the CRD and PSD2 directives (p. 3). Since then, the entry into force of DORA in January 2023, applicable from 17 January 2025, introduced a harmonized regulatory framework for digital operational resilience covering 21 types of financial entities, including a large part of the PSPs targeted by the EBA guidelines (p. 3). This overlap created legal uncertainty regarding the simultaneous application of the EBA guidelines and DORA requirements. This report therefore aims to clarify the scope of application of the EBA guidelines by adapting them to DORA, reducing their scope to aspects not covered by DORA, notably the management of relationships with payment service users and post office giro institutions excluded from DORA (p. 3-5). The objective is to ensure consistency, transparency, and legal certainty for the entities concerned and competent authorities, while avoiding redundant or conflicting requirements (p. 3-5).
Scope of the EBA guidelines:
- Initially applicable to credit institutions, investment firms, and PSPs according to CRD and PSD2 (p. 3).
- DORA now covers a large part of these entities, including credit institutions, payment institutions, electronic money institutions, account information service providers (AISPs), and certain exempted PSPs (p. 3).
- Post office giro institutions excluded from DORA remain under the EBA guidelines regime (p. 4).
- Their number is limited to 11 in 11 Member States, with a small market share (p. 4).
Impact of DORA on the EBA guidelines:
- DORA introduces harmonized requirements on ICT risk management, incident notification, third-party management, and testing, broadly covering aspects previously addressed by the EBA guidelines (p. 3-5).
- A gap analysis conducted in May 2024 showed that most EBA guideline requirements are now covered by DORA (p. 5).
- Only the management of relationships with payment service users is not addressed by DORA and must be retained in the EBA guidelines (p. 5).
Exemptions and national specificities:
- Competent national authorities may impose additional national requirements on PSPs not covered by DORA, independently of the EBA guidelines (p. 4).
- The PSD2 revision proposal to PSD3/PSR does not provide specific security requirements for post office giro institutions (p. 4).
Implementation and compliance:
- The amended guidelines will be published in all official EU languages and enter into force no later than 20 May 2025 (p. 6-9).
- Competent authorities must notify their compliance to the EBA before this date, under penalty of being considered non-compliant (p. 8).
- Notifications will be published on the EBA website (p. 8).
- Established facts: DORA covers the majority of entities and requirements previously targeted by the EBA guidelines, rendering most of their provisions obsolete (p. 3-5).
- Assumptions: The exclusion of post office giro institutions from DORA’s scope justifies the partial retention of the EBA guidelines for these entities (p. 4).
- Interpretations: The reduction of the EBA guidelines’ scope to the management of relationships with payment service users is proportionate and avoids unnecessary regulatory overlaps (p. 5).
- Uncertainties: The impact of future regulatory developments, notably the PSD2 revision to PSD3/PSR, on the applicable framework for post office giro institutions remains to be observed (p. 4).
- The possibility for national authorities to impose additional requirements ensures local regulatory flexibility (p. 4).
The EBA concludes that the EBA/GL/2019/04 guidelines must be amended to take into account the entry into force of DORA, reducing their scope to the sole management of relationships with payment service users, not covered by DORA (p. 5-6). Other parts of the guidelines are repealed to avoid overlaps and ensure regulatory consistency (p. 5-6). Post office giro institutions, excluded from DORA, remain subject to the EBA guidelines, but their limited number and low market weight justify a proportionate approach (p. 4). Competent authorities must integrate these changes into their practices and notify their compliance to the EBA before 20 May 2025 (p. 8-9). The publication of the amended guidelines in all official EU languages will ensure harmonized application (p. 6). This approach aims to strengthen digital operational resilience while clarifying the responsibilities of financial actors and supervisory authorities.
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.