Requirements7AI extractedStatus is derived from each row's mapping
Ref
Regulatory requirement
Interpretation AI
Status
Scope
Art. 5(1)
Requirement
Financial entities shall have an internal governance and control framework that ensures effective and prudent management of ICT risk.
Operate a governance structure where senior management is accountable for ICT risk and where roles, responsibilities, and oversight are clearly defined.
Confidence 96%
Compliant
Regional
FRIENLDE
›
Art. 6(1)
Requirement
Financial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system.
Maintain a written, current ICT risk framework that sits inside enterprise risk management — not a standalone document.
Confidence 94%
Compliant
Regional
FRIENLDE
›
Art. 6(2)
Requirement
The ICT risk management framework shall include at least strategies, policies, procedures, ICT protocols and tools necessary to duly and adequately protect all information assets and ICT assets.
The framework must explicitly cover protection of all ICT and information assets — software, hardware, servers, and data.
Confidence 91%
Gap
Regional
FRIENLDE
›
Art. 6(5)
Requirement
The ICT risk management framework shall be documented and reviewed at least once a year, as well as upon the occurrence of major ICT-related incidents.
Review the framework annually at minimum, and additionally after any major ICT incident or supervisory finding.
Confidence 92%
Gap
Regional
FRIENLDE
›
Art. 28(1)
Requirement
Financial entities shall manage ICT third-party risk as an integral component of ICT risk, including a documented strategy for ICT third-party risk.
Treat third-party ICT risk as part of the core framework, with a register and exit plans for critical providers.
Confidence 90%
Gap
Regional
FRIENLDE
›
Art. 11(6)
Requirement
Financial entities shall test ICT business continuity plans and ICT response and recovery plans in respect of ICT systems supporting all functions at least yearly.
Run at least an annual full-restore test plus quarterly tabletop exercises across continuity and recovery plans.
Confidence 93%
Gap
Regional
FRIENLDE
›
Recital 27
Guidance
In line with the principle of proportionality, the ICT risk management framework should reflect the size, business profile, and risk appetite of the financial entity.
Apply proportionality — a small payments firm need not match a tier-1 bank, but the basis for that judgement must be documented.