EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)
Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
EBA GL 3.1/3.8: Proportionality and Payment Service User Relationship
Institutions shall apply the guidelines in a manner proportionate to their size, internal organisation, and the nature, scope, complexity and riskiness of the services and products they provide.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Payment service providers shall implement measures to assist and protect payment service users, including raising awareness of security risks and providing means to report fraud, suspicious incidents and security concerns.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
EBA GL 3.2: Governance and Strategy
The management body shall ensure adequate internal governance and control of ICT and security risk, with clear roles and responsibilities, and approve and oversee the ICT strategy and the ICT and security risk management framework.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall set out an ICT strategy aligned with the business strategy, defining how ICT should evolve to support and enable the business, with action plans and monitoring of implementation.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Where functions are outsourced or provided by third parties (including intragroup and ICT service providers), institutions shall ensure ICT and security risk is managed throughout the lifecycle, consistent with the EBA outsourcing guidelines.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
EBA GL 3.3: ICT and Security Risk Management Framework
Institutions shall identify and manage ICT and security risk within a documented ICT and security risk management framework, with defined risk appetite, objectives and an independent control function as appropriate.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall identify and maintain an up-to-date mapping of business functions, roles and supporting processes, and the information assets and ICT assets supporting them, and their interdependencies.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall classify the identified functions, processes and assets in terms of criticality, and perform and keep up to date a risk assessment of ICT and security risks to them.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall take measures to mitigate identified ICT and security risks, including the protection measures in the information security section, and address residual risk in line with their risk appetite.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall report on ICT and security risks and the status of mitigation to the management body in a timely manner.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
ICT and security risk management shall be subject to independent and periodic audit by staff with sufficient ICT and security knowledge, following a risk-based audit plan.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
EBA GL 3.4: Information Security
Institutions shall establish an information security policy approved by the management body, defining the high-level principles and rules to protect the confidentiality, integrity and availability of information.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall implement logical access controls on a need-to-know, least-privilege and segregation-of-duties basis, including user access management, privileged access, authentication, and logging/monitoring of access.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall implement physical security measures to protect premises, data centres and sensitive areas against unauthorised access and environmental hazards.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall implement security measures in ICT operations, including configuration and hardening, protection against malware, vulnerability and patch management, and encryption of data in transit and at rest as appropriate.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall continuously monitor and log security-relevant events to detect anomalous activities and potential information-security incidents, with appropriate alerting and response.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall perform a programme of information security reviews, assessments and testing (including vulnerability assessments, penetration testing and, where relevant, scenario-based testing) to verify the effectiveness of controls.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall establish an information-security training and awareness programme for all staff and contractors, including the management body.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
EBA GL 3.5: ICT Operations Management
Institutions shall manage ICT operations based on documented processes and procedures, maintaining an up-to-date inventory of ICT assets, capacity and performance management, and data/system backup and restoration.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall establish ICT incident and problem management processes to monitor, log, classify, respond to and learn from ICT operational and security incidents, including escalation, communication and root-cause analysis.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
EBA GL 3.6: ICT Project and Change Management
Institutions shall implement an ICT project management approach that adequately addresses ICT and security risk in projects and project governance.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall ensure ICT and security requirements are addressed in the acquisition, development and maintenance of ICT systems, including secure development practices, testing and separation of environments.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall manage changes to ICT systems through a documented change management process covering assessment, approval, testing and rollback, including emergency changes.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
EBA GL 3.7: Business Continuity Management
Institutions shall conduct business impact analyses to assess their exposure to severe business disruptions and the potential impacts, informing recovery objectives and priorities.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall establish business continuity plans to ensure they can continue to operate and limit losses in the event of severe business disruption, based on the business impact analysis.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall establish response and recovery plans, including ICT, to restore the operation of critical business functions within recovery time and point objectives.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall test their business continuity and response and recovery plans periodically, and update them based on test results, incidents and changes.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Institutions shall implement crisis communication measures ensuring timely communication to internal and external stakeholders and authorities in the event of a major disruption.
- Documented policy/procedure implementing this guideline section
- Evidence of application reviewed by the management body / competent authority
- Section not addressed in the ICT risk framework
- Policy exists but not applied/evidenced
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.