Learning Objectives:
-
Define ICT risk management and explain its strategic importance for central banks and financial institutions.
-
Understand the key principles and components of ICT risk management frameworks.
-
Identify the governance structures required for effective ICT risk management.
-
Recognise the regulatory requirements for ICT risk management, including DORA, the RBI’s guidance, and national frameworks.
1.1 What is ICT Risk Management?
ICT risk management is the systematic process of identifying, assessing, and managing risks associated with the use of information and communication technologies (ICT). As financial services rapidly digitalise, the entire industry has become deeply intertwined with information and communication technologies . ICT-related risks are not only operational concerns but have become major business risks, capable of causing systemic failures, reputational damage, and even the collapse of institutions .
The SEACEN course on ICT Risk Management and Cybersecurity identifies that innovations such as mobile banking, artificial intelligence, and machine learning have significantly improved access to financial services, but they also introduce complex cyber and ICT-related risks alongside old ones that threaten financial stability . Cyber threats have become more sophisticated and borderless, fuelled by increased digitisation, third-party dependencies, and geopolitical tensions .
1.2 Key Principles of ICT Risk Management
The regulation on information systems and cyber risk management establishes that the risk management process should be executed repeatedly and regularly, including the following components: risk assessment, consisting of risk identification and analysis, addressing risk through the implementation of risk mitigation measures, and risk monitoring, review, and reporting .
The ICT Risk Management Lifecycle (Identify, Protect, Detect, Respond, Recover):
Financial institutions must have a comprehensive and well-documented ICT risk management framework as part of their overall risk management system, which is periodically reviewed and audited . The framework consists of five key stages:
Identify: The identification of all information and ICT assets, including computer software, hardware, servers, and relevant physical components and infrastructures such as premises, data centres, and sensitive designated areas . Financial entities should perform risk assessments upon each ‘major change’ in the network and information system infrastructure .
Protect: The implementation of appropriate safeguards to ensure the delivery of critical ICT services. This includes strategies, policies, procedures, ICT protocols, and tools that are necessary to duly and adequately protect all information assets and ICT assets .
Detect: The development and implementation of appropriate activities to identify the occurrence of ICT-related incidents. Financial entities must have procedures in place for collecting, logging and analysing security-relevant events in order to trigger actionable security alerts or initiate the security incident process .
Respond: The implementation of appropriate activities to take action regarding a detected ICT incident, including response planning, communications, analysis, mitigation, and improvements.
Recover: The implementation of activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to an ICT-related incident.
1.3 Governance Structures for ICT Risk Management
Responsibility for ICT risk management must be allocated to an independent control function, ensuring appropriate segregation of risk management duties . The management body is ultimately accountable for overseeing and approving the risk management strategy, ensuring alignment with business objectives . The Central Bank of Ireland’s ICT Self-Assessment Tool (ICT-SAT) is a structured framework which helps assess how well regulated entities manage ICT risks and protect their operations .
Key Governance Elements:
Management Body Accountability: Financial entities must have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system, which enables them to address ICT risk quickly, efficiently and comprehensively . The management body is ultimately accountable for overseeing and approving the risk management strategy, ensuring alignment with business objectives .
Independent Control Function: Responsibility for ICT risk management must be allocated to an independent control function, ensuring appropriate segregation of risk management duties . Regular audits by knowledgeable auditors are required to assess ICT risks and compliance, and a formal follow-up process must be in place to address any critical findings swiftly .
ICT Strategic Plan: Financial entities must have an ICT strategic plan aligned with the business strategy .
Sufficient Resources: Financial entities must ensure that sufficient ICT-related capabilities (human and technical resources) and budget are available to support the ICT strategy, the development of new projects, the recurrent maintenance, the ICT security and the risk management .
Clear Roles and Responsibilities: Financial entities must have clearly defined roles and responsibilities for ICT personnel, including the management body and its committees, considering the principle of independence .
1.4 Regulatory Requirements for ICT Risk Management
DORA (Digital Operational Resilience Act):
DORA, applicable from 17 January 2025, creates a single, comprehensive digital resilience framework for all financial entities across the EU . Financial entities are mandated to establish a robust and well-documented ICT risk management framework, integrating this framework within their overall risk management system to ensure prompt and effective responses to ICT risks . This framework should encompass necessary strategies, policies, and tools to adequately safeguard all information and ICT assets .
Key provisions include:
-
ICT risk management framework
-
ICT-related incident management, classification and reporting
-
Digital operational resilience testing
-
Management of ICT third-party risk
-
Information sharing arrangements
Reserve Bank of India (RBI) Guidance:
All regulated entities in India should implement a robust information and communication technology (ICT) risk management programme in alignment with their operational risk management framework . Regulated entities should manage their dependencies on relationships, including those of, but not limited to, third parties, for the delivery of critical operations .
National Frameworks:
Many central banks have developed their own ICT risk management frameworks. The regulation on information systems and cyber risk management establishes comprehensive requirements for risk management frameworks, including risk assessment, risk management, risk monitoring, and project management . Financial institutions should establish a risk management framework to effectively address ICT and cyber risks, with appropriate governance structures and processes, and well-defined roles, responsibilities and reporting lines across all different organisational functions .