Skip to content

Evidence request lists

EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)

Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

EBA GL 3.1/3.8: Proportionality and Payment Service User Relationship

EBA-GL-3.1
Proportionality

Institutions shall apply the guidelines in a manner proportionate to their size, internal organisation, and the nature, scope, complexity and riskiness of the services and products they provide.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.8
Payment service user relationship management

Payment service providers shall implement measures to assist and protect payment service users, including raising awareness of security risks and providing means to report fraud, suspicious incidents and security concerns.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced

EBA GL 3.2: Governance and Strategy

EBA-GL-3.2.1
Governance

The management body shall ensure adequate internal governance and control of ICT and security risk, with clear roles and responsibilities, and approve and oversee the ICT strategy and the ICT and security risk management framework.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.2.2
Strategy

Institutions shall set out an ICT strategy aligned with the business strategy, defining how ICT should evolve to support and enable the business, with action plans and monitoring of implementation.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.2.3
Use of third party providers

Where functions are outsourced or provided by third parties (including intragroup and ICT service providers), institutions shall ensure ICT and security risk is managed throughout the lifecycle, consistent with the EBA outsourcing guidelines.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced

EBA GL 3.3: ICT and Security Risk Management Framework

EBA-GL-3.3.1
Organisation and objectives

Institutions shall identify and manage ICT and security risk within a documented ICT and security risk management framework, with defined risk appetite, objectives and an independent control function as appropriate.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.3.2
Identification of functions, processes and assets

Institutions shall identify and maintain an up-to-date mapping of business functions, roles and supporting processes, and the information assets and ICT assets supporting them, and their interdependencies.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.3.3
Classification and risk assessment

Institutions shall classify the identified functions, processes and assets in terms of criticality, and perform and keep up to date a risk assessment of ICT and security risks to them.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.3.4
Risk mitigation

Institutions shall take measures to mitigate identified ICT and security risks, including the protection measures in the information security section, and address residual risk in line with their risk appetite.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.3.5
Reporting

Institutions shall report on ICT and security risks and the status of mitigation to the management body in a timely manner.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.3.6
Audit

ICT and security risk management shall be subject to independent and periodic audit by staff with sufficient ICT and security knowledge, following a risk-based audit plan.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced

EBA GL 3.4: Information Security

EBA-GL-3.4.1
Information security policy

Institutions shall establish an information security policy approved by the management body, defining the high-level principles and rules to protect the confidentiality, integrity and availability of information.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.4.2
Logical security

Institutions shall implement logical access controls on a need-to-know, least-privilege and segregation-of-duties basis, including user access management, privileged access, authentication, and logging/monitoring of access.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.4.3
Physical security

Institutions shall implement physical security measures to protect premises, data centres and sensitive areas against unauthorised access and environmental hazards.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.4.4
ICT operations security

Institutions shall implement security measures in ICT operations, including configuration and hardening, protection against malware, vulnerability and patch management, and encryption of data in transit and at rest as appropriate.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.4.5
Security monitoring

Institutions shall continuously monitor and log security-relevant events to detect anomalous activities and potential information-security incidents, with appropriate alerting and response.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.4.6
Information security reviews, assessment and testing

Institutions shall perform a programme of information security reviews, assessments and testing (including vulnerability assessments, penetration testing and, where relevant, scenario-based testing) to verify the effectiveness of controls.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.4.7
Information security training and awareness

Institutions shall establish an information-security training and awareness programme for all staff and contractors, including the management body.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced

EBA GL 3.5: ICT Operations Management

EBA-GL-3.5
ICT operations management

Institutions shall manage ICT operations based on documented processes and procedures, maintaining an up-to-date inventory of ICT assets, capacity and performance management, and data/system backup and restoration.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.5.1
ICT incident and problem management

Institutions shall establish ICT incident and problem management processes to monitor, log, classify, respond to and learn from ICT operational and security incidents, including escalation, communication and root-cause analysis.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced

EBA GL 3.6: ICT Project and Change Management

EBA-GL-3.6.1
ICT project management

Institutions shall implement an ICT project management approach that adequately addresses ICT and security risk in projects and project governance.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.6.2
ICT systems acquisition and development

Institutions shall ensure ICT and security requirements are addressed in the acquisition, development and maintenance of ICT systems, including secure development practices, testing and separation of environments.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.6.3
ICT change management

Institutions shall manage changes to ICT systems through a documented change management process covering assessment, approval, testing and rollback, including emergency changes.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced

EBA GL 3.7: Business Continuity Management

EBA-GL-3.7.1
Business impact analysis

Institutions shall conduct business impact analyses to assess their exposure to severe business disruptions and the potential impacts, informing recovery objectives and priorities.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.7.2
Business continuity planning

Institutions shall establish business continuity plans to ensure they can continue to operate and limit losses in the event of severe business disruption, based on the business impact analysis.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.7.3
Response and recovery plans

Institutions shall establish response and recovery plans, including ICT, to restore the operation of critical business functions within recovery time and point objectives.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.7.4
Testing of plans

Institutions shall test their business continuity and response and recovery plans periodically, and update them based on test results, incidents and changes.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
EBA-GL-3.7.5
Crisis communications

Institutions shall implement crisis communication measures ensuring timely communication to internal and external stakeholders and authorities in the event of a major disruption.

Artefacts an auditor will ask for
  • Documented policy/procedure implementing this guideline section
  • Evidence of application reviewed by the management body / competent authority
Where this commonly fails
  • Section not addressed in the ICT risk framework
  • Policy exists but not applied/evidenced
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.