Third parties now inherit your risk
Vendors with access to bank systems — including hardware maintainers and managed service providers — fall under the same scrutiny as in-house staff. Expect to show vendor access logs, contract clauses on data handling, and an inventory of who can touch what. Most institutions already have the logs; almost none have the inventory.
Recovery tests must be demonstrated, not declared
Written DR plans no longer satisfy examiners on their own. The 2026 guidance expects evidence of scheduled failover exercises with timings — RTO measured, not assumed. A twice-yearly documented drill with screenshots and variance notes is the pattern auditors are accepting.
Board reporting gets specific
ICT risk reports to the board must now name critical incidents, overdue remediations, and capacity thresholds. The format is left to institutions, which is an opportunity: a one-page quarterly dashboard with those three rows is fully compliant and survives board scrutiny better than a forty-slide deck.




