|
OJK Risk Management Requirements for Commercial BanksOJK
|
Commercial banks and banking groups within scope |
Risk governance, appetite and limits, control functions, monitoring, risk reporting and independent review. |
|
Source
|
|
OJK Governance Requirements for Commercial BanksOJK
|
Commercial banks operating in Indonesia |
Board and committee governance, internal controls, compliance, internal audit, conflicts and corrective follow-up. |
|
Source
|
|
POJK 34/2025 on Information Technology ImplementationOJK
|
Rural banks and Sharia rural banks within the regulation’s scope |
IT governance, digital security, incident response, third-party services, business continuity, control testing and assurance. |
|
Source
|
|
POJK 3/2024 on Financial-Sector Technology InnovationOJK
|
Financial-sector technology innovation providers within scope |
Risk management, governance, consumer data, incident handling, supervisory reporting and service-provider controls. |
|
Source
|
|
Personal Data Protection Law No. 27 of 2022Komdigi
|
Personal-data controllers and processors within scope |
Data governance, impact assessment, security, breach notification, processor oversight and accountability records. |
|
Source
|