This document is a guide detailing the procedures for auditing the cyber risk management field, applicable from the audit period beginning January 1, 2025. It outlines the audit depth, which includes critical assessments based on various regulatory articles and circulars. The guide specifies the responsibilities of the audit team to adapt the standard work program according to the institution's specific situation, including size, business model, and risk exposure. The document emphasizes the importance of assessing the adequacy of governance related to cyber risk, the integration of cyber risks into operational risk management, and the evaluation of the board of directors' oversight. It also includes a comprehensive list of procedures for assessing the management of cyber risks, including training, reporting, and the identification of critical data and ICT assets. The guide aims to ensure compliance with stricter requirements set by regulatory bodies.