Establishing an ICT risk management framework
Regulation (EU) 2022/2554 of the European Parliament and of the Council on digital operational resilience for the financial sector (DORA) sets uniform requirements for the digital operational resilience of financial entities. These requirements cover ICT risk management, ICT incident management and reporting, digital operational resilience testing, ICT third-party risk management, and the sharing of information on cyber threats. A financial entity must ensure that its ICT governance framework, processes, systems, controls, and documentation are proportionate to its size, overall risk profile, and the nature, scale, and complexity of its services, activities, and operations. In practice, a financial market participant must maintain clearly structured and current documentation when commencing and continuing its operations. This documentation should cover policies, practical procedures and instructions, descriptions of solutions, and other materials supporting operational activities.
The documentation must be organised hierarchically and maintained systematically. It should range from fundamental principles and policies to descriptions of specific processes and the practical application of solutions. Latvijas Banka does not prescribe a specific format or length. The main requirement is that the documentation reflects the entity's actual approach and ability to manage ICT risk, maintain business continuity, and oversee ICT third-party service providers. Latvijas Banka expects each financial market participant to maintain this documentation proactively, review it regularly, and update it when necessary. This ensures that it remains aligned with current risks, regulatory requirements, and developments in the financial market participant's activities.
The principle of proportionality allows a financial entity to adapt its ICT risk management measures and the extent of its documentation to its size and overall risk profile, and to the nature, scale, and complexity of its services, activities, and operations. A smaller financial entity with a simpler operating model may therefore use simpler solutions, provided that they adequately address the relevant ICT risks and ensure compliance with the applicable DORA requirements (Article 4 of DORA).
The ICT risk management approach is the framework established by a financial entity for managing risks related to ICT systems, data, cybersecurity, technology processes, and ICT third-party services. It helps ensure that ICT risks are identified, assessed, mitigated, and monitored in a timely manner and that material information is reported to the management body.
The ICT risk management approach usually defines responsibilities, the risk tolerance level, the procedures for identifying and assessing ICT risks, risk mitigation measures and controls, the maintenance of the ICT risk register, the acceptance of residual risk, the monitoring of material risks, and reporting to the management body, as well as regular risk reviews and updates.
The financial entity must independently conduct an ICT risk assessment based on ensuring the operation of critical or important functions.
The requirements are based on the following provisions:
- Article 5 of DORA on the organisation of ICT risk management, the responsibility of the management body, the allocation of duties and control functions;
- Article 6 of DORA on establishing a sound, comprehensive, and well-documented ICT risk management framework, the digital operational resilience strategy, the risk tolerance level, and the review and audit of the framework;
- Articles 7 to 15 of DORA on ICT systems and tools, the identification of ICT risks and dependencies, protection and prevention, detection, response and recovery, learning and evolving, and communication;
Articles 3 and 27 of Delegated Regulation (EU) 2024/1774 on policies and procedures for identifying, assessing, mitigating, monitoring, and reporting ICT risk and on the report on the review of the ICT risk management framework.
The ICT and information security policy sets out the information security principles, objectives, and control measures approved by the management body. These principles, objectives, and measures protect the availability, authenticity, integrity, and confidentiality of information and ICT systems.
A financial market participant must be able to define a consistent approach to information and ICT security. This includes its position on the management and tolerance of ICT risks, levels of protection, and system controls. The framework must be aligned with the entity's overall risk management strategy and cover both preventive and response measures. It is often set out in a high-level policy document, usually an ICT security policy, which is approved by the management body. More detailed procedures, internal rules, and descriptions of activities are then developed under this policy. The ICT and information security policy usually defines security objectives and responsibilities, access rights management, data protection, logging and monitoring, ICT operations, network and physical security, vulnerability and patch management, security incident management, and regular review of the policy.
The requirements are based on the following provisions:
- Article 5(2), point (b), of DORA on the responsibility of the management body to approve and oversee policies aimed at ensuring the availability, authenticity, integrity, and confidentiality of data;
- Article 6 of DORA on a documented ICT risk management framework that includes information security policies, procedures, protocols, and tools;
- Articles 8 and 9 of DORA on the identification and classification of ICT assets and information and the implementation of protection and prevention measures;
- Article 2 of Delegated Regulation (EU) 2024/1774 on the general elements of ICT security policies, procedures, protocols, and tools, together with the requirements of that Regulation on ICT asset management, encryption, ICT operations security, vulnerability and patch management, data and system security, logging, network security, access control, identity management, and physical security.
The ICT incident management and reporting procedure sets out how ICT-related incidents are identified, recorded, classified, managed, and resolved, how their root causes are analysed, and how major ICT-related incidents are reported to the competent authority.
These arrangements are usually documented in a procedure, such as an ICT incident management procedure, or in a workflow description. The document defines the specific steps, allocation of duties and responsibilities for incident management. It is developed from the previously defined security principles and forms an important part of the entity's operational resilience arrangements. In accordance with the principle of proportionality, smaller entities are also expected to establish arrangements suited to the scale and nature of their activities.
The requirements are based on the following provisions:
- Articles 17 to 23 of DORA;
- Articles 22 and 23 of Delegated Regulation (EU) 2024/1774 on the ICT-related incident management policy and on the detection and management of ICT-related incidents;
- Articles 1 to 9 of Delegated Regulation (EU) 2024/1772 on the criteria for classifying ICT-related incidents and materiality thresholds;
- Delegated Regulation (EU) 2025/301 on the content and time limits for the initial notification, intermediate report, and final report;
- Implementing Regulation (EU) 2025/302 on standard forms, templates, and procedures for reporting.
Business continuity planning defines how a financial entity will continue its operations and recover its most important systems after a disruption, who will be responsible, and how the plans will be tested.
Business continuity documentation includes the business impact analysis, the ICT business continuity policy, and ICT response and recovery plans. It identifies critical or important functions and their dependencies, recovery time and recovery point objectives, plan activation criteria, responsibilities and roles, communication arrangements, backup solutions, and regular testing.
The business impact analysis (BIA) helps identify critical or important functions and their dependencies on specific ICT resources. Its purpose is to assess how different disruptions could affect the entity's operations and to define the necessary recovery measures in advance. The business continuity plan (BCP) and disaster recovery plan (DRP) are developed on the basis of the BIA.
The requirements are based on the following provisions:
- Article 11 of DORA on the ICT business continuity policy, business impact analysis, ICT response and recovery plans, and their testing;
- Article 12 of DORA on backup policies, restoration procedures, and recovery systems;
Articles 24 to 26 of Delegated Regulation (EU) 2024/1774 on the components of the ICT business continuity policy, testing of plans, and ICT response and recovery plans.
Information on existing and planned ICT third-party services includes a list of ICT third-party service providers and the services received. It identifies the functions supported, including critical or important functions, the assessment of the criticality and risks of the services, arrangements for managing contractual relationships, monitoring measures, subcontracting and exit strategies.
The register of information contains information on all contractual arrangements with ICT third-party service providers and is updated regularly. This includes the ICT services received, contracts, service providers and subcontractors, functions supported, locations where services are provided, locations where data are stored, and contract termination arrangements. ICT services supporting critical or important functions are identified separately.
Documented ICT infrastructure also supports the assessment of ICT third-party service management. It helps identify critical dependencies and potential risks arising from these relationships.
The requirements are based on the following provisions:
- Article 28 of DORA on the principles for the sound management of ICT third-party risk, the register of information on contractual arrangements, the assessment of planned contractual arrangements, service monitoring, and exit strategies;
- Article 29 of DORA on the preliminary assessment of ICT concentration risk before entering into a contractual arrangement;
- Article 30 of DORA on key contractual provisions for arrangements with ICT third-party service providers;
- Delegated Regulation (EU) 2024/1773 on the policy regarding contractual arrangements for the use of ICT services supporting critical or important functions, including risk assessment, due diligence on the ICT third-party service provider, monitoring of contractual arrangements, and exit strategies;
- Delegated Regulation (EU) 2025/532 on the conditions for subcontracting ICT services supporting critical or important functions;
- Implementing Regulation (EU) 2024/2956 on standard templates for the register of information and the information to be included on ICT services, service providers, contractual arrangements, functions supported, and the ICT service supply chain.
Additional information
Please clarify:
- which IT staff will be physically located in Latvia and what their roles, expected responsibilities and workload will be in accordance with Article 5 of DORA;
- which functions have been identified as critical or important functions within the meaning of Article 3, point (22), of DORA;
- whether artificial intelligence (AI) systems are being developed or used, including AI systems that incorporate general-purpose AI models, within the meaning of Article 3, points (1), (3), (4), (63), and (66), of the AI Act;
- the overview of ICT infrastructure and systems, including ICT assets and their architecture, integrations, data flows, and information on ICT third-party services used, in accordance with Article 8 of DORA.
Governance of the use of artificial intelligence
Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence, known as the Artificial Intelligence Act or AI Act, determines how a financial entity identifies, assesses, approves, uses, and monitors AI systems and manages the related risks. The AI Act requirements cover responsible persons, inventories, and risk classification of AI systems, conditions of use, human oversight, data protection, transparency and security measures, and AI literacy among staff.
"AI system" means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
For the assessment of governance of the use of artificial intelligence:
- The financial entity must provide information on the AI systems it uses and develops that meet the definition of an AI system in Article 3, point (1), of the AI Act.
- The name, a brief description, and the main functions of each AI system must be provided.
- For each AI system, the financial entity must indicate its role or roles. It must state whether it acts as a provider, product manufacturer, deployer, authorised representative, importer, or distributor in relation to the system and briefly explain the basis for determining the role.
- The financial entity must also indicate which of its critical or important functions are supported by the AI system.
The requirements are based on the following provisions:
- Article 3, points (1) and (3) to (9), of the AI Act on the definitions of an AI system and the possible roles of a financial entity;
- Article 4 of the AI Act on ensuring a sufficient level of AI literacy;
- Articles 5 and 6 of and Annex III to the AI Act on identifying prohibited AI practices and high-risk AI systems;
- Articles 16 and 22 to 26 of the AI Act on the obligations of different operators of AI systems and circumstances in which the role of a financial entity changes;
- Article 50 of the AI Act on transparency obligations for certain AI systems;
- Article 8(1), (4), and (5) of DORA on identifying and documenting ICT assets, dependencies, and the critical or important functions supported.
Governance of crypto-asset services
Regulation (EU) 2023/1114 of the European Parliament and of the Council on markets in crypto-assets (MiCA) sets out how a financial entity organises, provides, and monitors crypto-asset services and manages the related risks. It covers responsible persons, governance arrangements, the safeguarding of clients' assets, the prevention of conflicts of interest, the handling of complaints, oversight of outsourcing, business continuity, and record keeping.
A crypto-asset service provider must maintain secure and resilient ICT systems that are appropriate for the scale of its activities. It must manage ICT risks, protect client data and crypto-assets, ensure the continuity of its systems, and oversee ICT service providers.
In addition to the DORA requirements, a crypto-asset service provider must, depending on the services provided:
- maintain electronic records and retain complete and traceable records of all crypto-asset services, activities, orders, and transactions for at least five years (Article 68(9) of MiCA and Delegated Regulation (EU) 2025/1140);
- maintain a register of positions opened in the name of each client, record any movements in accordance with instructions given by clients as soon as possible, protect clients' crypto-assets and means of access, segregate clients' crypto-assets from its own holdings, and ensure that crypto-assets or means of access are returned to clients (Article 75(2) and (7) of MiCA);
- ensure that its trading systems are resilient and have sufficient capacity, reject erroneous orders or orders that exceed predetermined volume and price thresholds, ensure orderly trading and business continuity, and fully test systems before deployment and after substantial updates (Article 76(7) and (8) of MiCA);
- keep the order book records of the trading platform for at least five years, link orders to executed transactions, and publish the required pre-trade and post-trade information, including in a machine-readable format (Article 76(9) to (15) of MiCA and Delegated Regulation (EU) 2025/416);
- implement and maintain effective arrangements, systems, and procedures to prevent and detect market abuse and immediately report suspicious orders, transactions and other aspects of the functioning of distributed ledger technology that may indicate market abuse to the competent authority (Article 92(1) of MiCA);
- include in agreements with clients a description of the security systems used for crypto-asset transfers and establish policies and procedures for providing crypto-asset transfer services in accordance with the applicable requirements (Article 82(1) and (2) of MiCA).