NewFintech
Requirements for Information Technology (IT) Management of Banks Directive No. 889/2022
National Bank Of Ethiopia889/2022
Summary
This directive establishes requirements for Information Technology (IT) management for banks operating in Ethiopia. It mandates the automation of core business processes, the implementation of robust IT strategies, risk management programs, and IT audit functions. The objective is to enhance efficiency, security, and soundness of individual banks and the banking sector as a whole.
Who's affected
All banks operating in Ethiopia, including their boards, senior management, IT departments, risk management, and internal audit functions.
Action required
Banks must develop and implement IT strategies, automate core business processes, establish IT risk management programs, and conduct regular IT audits in accordance with the directive's provisions.
Key points
6- Mandates automation of core banking processes and management information systems.
- Requires comprehensive IT risk management and cyber security measures.
- Establishes IT governance, policies, and procedures.
- Mandates IT audit functions and regular reporting to the National Bank.
- Includes transitional provisions for implementation timelines.
- Specifies penalties for non-compliance.
Show 3 more
Requirements
25- Banks must describe and include the role of IT in their business strategy.
- Banks must develop and implement an IT strategy aligned with business strategy.
- Banks must develop and implement IT governance, IT department structure, IT policies and procedures, and annual IT plans.
- Banks must allocate sufficient financial and human resources for IT strategy and risk management.
- Banks must develop and follow an effective project and IT vendor management framework.
- Board and senior management must quarterly review IT plan progress and take corrective measures.
- Banks must fully automate core business processes and management information systems.
- Automated core business processes must be interoperable.
- Management information systems must support various reporting and decision-making functions.
- Banks must implement an IT risk management program aligned with the institution's overall risk management program.
- IT risk management programs must cover risk identification, assessment, measurement, reporting, monitoring, and culture.
- Banks must consider cyber security risk management requirements from INSA.
- Banks must conduct quarterly IT risk assessments and submit reports to the National Bank.
- Banks must maintain and quarterly update an IT risk register.
- Banks must set up or build a disaster recovery site.
- Banks must develop and implement IT risk management strategies, plans, policies, procedures, and standards covering various security and operational aspects.
- Banks must periodically revise IT risk management strategies based on risk assessment findings.
- Banks must prepare and implement annual IT security awareness plans.
- Banks must develop and implement annual training plans for IT department staff.
- Banks must establish an IT audit function within their internal audit function.
- IT audit function must be adequately resourced.
- IT audit function must prepare and implement an annual audit plan.
- IT audits must be conducted at least quarterly and findings reported to the board audit committee and National Bank.
- Banks must notify the National Bank of significant IT incidents within two working days.
- Banks must quarterly submit reports on ongoing handling of IT incidents.
Show 22 more
Rights and permissions
1- Shareholders have the right to get necessary and relevant information through the management information system.
Restrictions
3- Core business processes and management information system automation must be completed within two years from the effective date.
- Disaster recovery site setup must be completed within two years from the effective date.
- Other provisions of the directive are effective after one year from the effective date.
Penalties
3- Violation of automation of core businesses and disaster recovery site requirements within the given period results in a penalty of Birr 10,000 per requirement per month until compliance.
- Additional two years of non-compliance may result in full or partial suspension of related core business.
- Violation of other provisions will be penalized as per relevant National Bank directives.
Objectives
4- Improve the efficiency, effectiveness, and competitiveness of banks through IT.
- Require banks to automate at least their core business processes and management information systems.
- Ensure risks related to IT usage are adequately and periodically identified and managed.
- Ensure the safety and soundness of individual banks and the banking sector as a whole.
Show 1 more
Organizations
2- National Bank of Ethiopia
- Information Network Security Agency (INSA)
Legal references
2- Banking Business Proclamation No. 592/2008
- Proclamation No. 1159/2019
Original sourcehttps://justice.gov.et/en/directives/requirements-for-information-technology-it-management-of-banks-directive-no-889-2022/
View source