ICT Supervision at Banks
Objective
As digital transformation progresses, information and communication technology (ICT) is becoming ever more important to the functioning of banks. At the same time, however, these technologies entail significant risks and potential for both internal and external abuse. Supervisors need to focus their attention on the risks associated with the use of information and communication technology.
This expert panel gives an overview of current practices with regard to ICT supervision at banks from both a regulatory and practical perspective. The course content will cover the general EU framework (especially DORA) and its transposition into German law and supervisory practices. The sessions will discuss typical ICT issues that banks face, shed light on the assessment techniques used by supervisors in their review and evaluation process (SREP) as well as in on-site inspections and highlight specific ICT problems.
Participants are expected to actively contribute during this panel, by presenting and discussing typical challenges and experiences faced in their own national ICT supervision. This is a key element of the expert panel.
Contents
- Overview of the European and German banking supervision systems, as well as the laws and regulations governing ICT supervision (DORA)
- Introduction to ICT security and IT supervision
- Minimum requirements for risk management with a focus on ICT and third-party risk requirements
- Setting up an on-site inspection of ICT and typical findings in Germany
- Deep dive on selected topics (e.g. user access rights, application development, outsourcing management, penetration testing)
- Gathering off-site information for the supervisory review and evaluation process for ICT (ICT SREP)
- Group work, e.g. evaluating an on-site inspection report for ICT
Target group
Policymakers in banking supervision, on-site and off-site supervisors, ICT auditors. Participants should have at least an intermediate understanding of banking supervision and ICT and be prepared to share their knowledge with other participants in the group. Active participation, among others in the form of a short presentation on a national aspect of ICT supervision, is mandatory.