EBA narrows existing ICT guidelines

DORA ICT risk management requirements apply to financial entities in their place.

The amendments by the European Banking Authority (EBA) are intended to provide legal clarity and also avoid confusing duplication in guidelines applying to ICT risk management.

Paragraphs 1-91, which are contained in Section 3.1 to 3.7 of the EBA’s Guidelines on ICT and security risk management are being repealed, along

The

Free Trial

Register for free to keep reading.

To continue reading this article and unlock full access to GRIP, register now. You’ll enjoy free access to all content until our subscription service launches in early 2026.

  • Unlimited access to industry insights
  • Stay on top of key rules and regulatory changes with our Rules Navigator
  • Ad-free experience with no distractions
  • Regular podcasts from trusted external experts
  • Fresh compliance and regulatory content every day
Register for free Already a member? Sign in