EBA欧洲银行-EBA-GL-2017-05-CT-GLs-on-ICT-Risk-Assessment-under-the-Supervisory-Review_5页_217kb
报告摘要
EBA Guidelines Compliance Table Summary
Core Content
This document is the EBA/GL/2017/05 Appendix 1, titled "Guidelines on ICT Risk Assessment under the Supervisory Review and Evaluation process (SREP)". It provides an overview of the compliance status of competent authorities across EU Member States, EEA-EFTA States, and European Territories under Article 355(3) TFEU with the EBA's guidelines on ICT risk assessment as part of the SREP process. The guidelines were issued on 11 May 2017 and became applicable from 01 January 2018, with an update on 19 February 2018.
Main Points
- The EBA has issued guidelines on ICT risk assessment to be integrated into the SREP framework.
- These guidelines are intended to enhance the supervision of financial institutions by incorporating ICT risk into the overall risk assessment process.
- The compliance status of each competent authority is reported, indicating whether they comply, intend to comply, or do not comply with the guidelines.
Compliance Status Overview
EU Member States
| Country | Competent Authority | Compliance Status | Comments |
|---|---|---|---|
| Belgium | National Bank of Belgium | Intends to comply | Implementation starts in 2018, awaiting ECB-SSM instructions |
| Bulgaria | Bulgarian National Bank | Intends to comply | By 31.12.2018; SREP manual will be updated |
| Czech Republic | Czech National Bank | Yes | Notification date: 03.11.2017 |
| Denmark | Finanstilsynet (FSA-DK) | Intends to comply | By 01.01.2018 |
| Germany | Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin) | Intends to comply | By first half of 2018 |
| Estonia | Finantsinspektsoon | Yes | Notification date: 01.11.2017 |
| Ireland | Central Bank of Ireland | Intends to comply | By 01.01.2018 |
| Greece | Bank of Greece | Intends to comply | By 01.01.2018 |
| Croatia | Hrvatska narodna banka | Intends to comply | By 01.01.2018 |
| Spain | Banco de España | Intends to comply | By 01.01.2018 |
| France | ACPR – Banque de France | Intends to comply | By application date; methodology is comparable to SSM's |
| Italy | Banca d'Italia | Intends to comply | By 30.06.2018 |
| Cyprus | Central Bank of Cyprus | Intends to comply | By 01.01.2018 |
| Latvia | Financial and Capital Market Commission | Intends to comply | By 30.09.2018 |
| Lithuania | Bank of Lithuania | Intends to comply | By 01.01.2018 |
| Luxembourg | Commission de Surveillance du Secteur Financier (CSSF) | Intends to comply | By 01.01.2018 |
| Hungary | The Central Bank of Hungary | Intends to comply | By 01.01.2018 |
| Malta | Malta Financial Services Authority (MFSA) | Intends to comply | Proportional approach for LSI's once ECB guidelines are in force |
| Netherlands | De Nederlandsche Bank | Yes | Notification date: 10.11.2017 |
| Austria | Austrian Financial Market Authority | Yes | Notification date: 07.11.2017 |
| Poland | Komisja Nadzoru Finansowego | Intends to comply | By 30.03.2018 |
| Portugal | Banco de Portugal | Intends to comply | By 01.01.2018 |
| Romania | National Bank of Romania | Yes | Notification date: 10.11.2017 |
| Finland | Finanssivalvonta (FIN-FSA) | Yes | Notification date: 15.02.2018 |
| Sweden | Finansinspektionen | Intends to comply | By 01.01.2018 |
| United Kingdom | Bank of England | Email pending | Policy consideration ongoing; expected response by mid-January 2018 |
| United Kingdom | Financial Conduct Authority (FCA) | Intends to comply | By 01.01.2018 |
EEA-EFTA States
| Country | Competent Authority | Compliance Status | Comments |
|---|---|---|---|
| Iceland | Financial Supervisory Authority, Iceland | Yes | Notification date: 10.11.2017 |
| Liechtenstein | Financial Market Authority Liechtenstein (FMA) | Yes | Notification date: 10.11.2017 |
| Norway | The Financial Supervisory Authority of Norway | Intends to comply | By 31.12.2018; already used for 2017 SREP |
European Territories under Article 355(3) TFEU
| Country | Competent Authority | Compliance Status | Comments |
|---|---|---|---|
| Gibraltar | Gibraltar Financial Services Commission | Intends to comply | By 01.01.2018 |
Key Information
- Application Date: The guidelines became applicable from 01 January 2018.
- Compliance Criteria: Competent authorities must inform the EBA whether they comply or intend to comply with the guidelines. If they continue to intend to comply after the application date, they are considered non-compliant unless specific conditions (A or B) are met.
- National Implementation: Some competent authorities are already compliant, while others are in the process of implementing the guidelines or plan to do so in 2018.
- SREP Integration: The guidelines are to be integrated into the SREP process, focusing on ICT risk assessment as part of operational risk.
- Transparency Note: The EBA aims to maintain transparency but cannot be held responsible for the accuracy of the provided information, which is sourced from the competent authorities themselves.
Notes
- The EBA's Regulations (Article 16(3)) require competent authorities to report their compliance status with each guideline or recommendation.
- Competent authorities may choose not to comply if the guidelines do not apply to their jurisdiction or if legislative changes are not yet in place.
- For detailed information on any competent authority's position, direct contact with the authority is recommended.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载