Digital Equipment Ltd.
Compliance 4 min read

BB ICT Guidelines: what changed in 2026

By DEL Compliance Desk 15 June 2026 Last updated: 15 June 2026

The 2026 revision tightens three areas: third-party risk, recovery testing, and board-level accountability. None of them need new spending if you already run a disciplined ICT operation — but all of them need paperwork that proves it.

Team reviewing guideline documents at a workspaceComplianceJun 2026

Third parties now inherit your risk

Vendors with access to bank systems — including hardware maintainers and managed service providers — fall under the same scrutiny as in-house staff. Expect to show vendor access logs, contract clauses on data handling, and an inventory of who can touch what. Most institutions already have the logs; almost none have the inventory.

Recovery tests must be demonstrated, not declared

Written DR plans no longer satisfy examiners on their own. The 2026 guidance expects evidence of scheduled failover exercises with timings — RTO measured, not assumed. A twice-yearly documented drill with screenshots and variance notes is the pattern auditors are accepting.

Board reporting gets specific

ICT risk reports to the board must now name critical incidents, overdue remediations, and capacity thresholds. The format is left to institutions, which is an opportunity: a one-page quarterly dashboard with those three rows is fully compliant and survives board scrutiny better than a forty-slide deck.

Keep reading

Turn the theory into a plan.

Every article here comes from projects we delivered. If one matches your roadmap, our engineers will scope it with you — no obligation.

Keep reading

More insights

← All articles