European supervisory baseline for ICT governance, information security, operations, continuity and incident management.
TL;DR:
- Sets EBA guidance on payment-service user relationship management.
- Complements the ICT risk framework introduced by DORA.
- Uses an amended scope rather than duplicating the original broad ICT-control framework.
Summary
The amended EBA guidelines address payment-service user relationship management alongside the wider ICT risk framework.
The guidelines were narrowed following DORA’s application. The amended text addresses the relationship between payment-service providers and their users, complementing the operational and security risk measures that apply under DORA and PSD2. This distinction matters when assessing the guidelines: the earlier, broader ICT framework should not be treated as the unchanged current scope.
The main requirements are to maintain ICT governance, security, operations, project, continuity and incident controls.
Operational resilience focuses on the continued delivery of important services through disruption. Technology availability is one input, alongside people, processes, data, facilities and third parties. Mapping those dependencies exposes situations in which an apparently healthy component still cannot deliver the end-to-end service that customers or other institutions rely on.
Risk management seeks to prevent failures; continuity and recovery planning deal with failures that still occur. Scenario testing examines whether those arrangements work under severe but plausible conditions, including the loss of an important supplier or a shared dependency. Recovery objectives, communication and decision-making responsibilities need to be connected to the affected service rather than considered only as technical system settings.
For payment activity, disruption can affect initiation, authentication, processing, settlement support and access to funds in different ways. Evidence from incidents and tests helps identify weaknesses and track remediation. The instrument's scope determines which institutions or infrastructures are covered and how its governance, reporting and assurance expectations interact with other financial-sector rules.
The instrument also addresses reporting and evidence: document controls, incidents and supervisory evidence.
Keywords
- EBA ICT and Security Risk Management Guidelines
- EBA ICT Guidelines
- EBA/GL/2019/04
- EBA ICT and Security Risk Management Guidelines summary
- EBA ICT and Security Risk Management Guidelines requirements
- EBA ICT and Security Risk Management Guidelines compliance
- European Union payment regulation
- European Union financial regulation
- European Banking Authority regulation
- operational resilience