The European Banking Authority (EBA) has announced that it has narrowed down the scope of its existing Guidelines on ICT and security risk management measures. This is to avoid duplication of requirements and to provide legal clarity to the market now that DORA (the EU Digital Operational Resilience Act) is in place.
DORA has introduced harmonised requirements on ICT risk management that apply to financial entities across the banking, securities/markets, insurance and pensions sectors. In response, the EBA has narrowed down its Guidelines on ICT and security risk management.
The Guidelines now apply to only those entities that are covered by DORA, namely credit institutions, payment institutions, account information service providers, exempted payment institutions and exempted e-money institutions.






