Bank for International Settlements
Information and Communication Technology Risk Management Practices
Pages
23
Time to read
46 mins
Publication
Language
English
Pages
23
Time to read
46 mins
Publication
Language
English
This technical report outlines a range of practices in information and communication technology (ICT) risk management, focusing on how banks address non-malicious ICT incidents. The Basel Committee conducted this analysis as part of its 2025–26 work programme, highlighting the importance of ICT risk management in enhancing operational resilience for banks. The report details the participation of 16 jurisdictions and presents key findings from a survey regarding ICT incidents, their root causes, and the prevalent risk management practices observed. The report identifies several factors contributing to ICT incidents, such as gaps in change control and system design. Furthermore, it lists the top practices employed by banks, including ICT change management and third-party risk management. Additionally, it discusses the regulatory landscape and supervisory practices in place to guide banks in their ICT risk management efforts. Challenges faced by banks in implementing these practices, such as talent shortages and visibility into third-party risks, are also examined.