Authentic statutory obligations decomposed into atomic machine-actionable conditions, actions, and verification standards.
Financial entities shall have in place an internal governance and control framework that ensures an effective and prudent management of ICT risk. Financial entities shall continuously monitor and control the security and functioning of ICT systems and tools and shall minimise the impact of ICT risk on ICT systems.