EBA GL/2019/04
Also known as: EBA/GL/2019/04, EBA ICT and security risk management guidelines, EBA ICT risk guidelines
EBA Guidelines on ICT and security risk management — European Banking Authority
The EBA's baseline for how credit institutions, investment firms and payment service providers govern ICT and security risk: governance and strategy, information security, ICT operations and change management, business continuity, and the management of relationships with payment service users. National competent authorities across the EU supervise against them, and they replaced the earlier guidelines on security measures for operational and security risks under PSD2.
Subscribe to EBA GL/2019/04 (RSS)
Timeline
No changes recorded yet — we are watching, and nothing has been published.
Monitoring
Watched by 1 official source. Watching since 20 September 2026.