EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04)
The European Banking Authority Guidelines on ICT and security risk management (EBA/GL/2019/04, applied from 30 June 2020), as amended by EBA/GL/2025/02 from 20 May 2025: with DORA governing the ICT risk of EU financial entities from 17 January 2025, sections 3.1 to 3.7 (governance and strategy, the risk management framework, information security, ICT operations, project and change management, business continuity) were repealed and only section 3.8, payment service user relationship management, remains, addressed to payment service providers. The repealed sections are kept here with their text and their mappings to DORA as the historical baseline.
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) is a compliance framework from European Union (EBA) with 3 domains and 43 controls that map to 13 other frameworks. The largest domains are Sections 3.1 to 3.7, repealed by EBA/GL/2025/02 from 20 May 2025 and superseded by DORA – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) (32 controls), Section 3.8: payment service user relationship management (in force) – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) (8 controls), Subject matter, scope, addressees and status – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) (3 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (3)
Section 3.8: payment service user relationship management (in force) – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04)
| Code | Title |
|---|---|
| EBA-GL-92 | Awareness of security risks through assistance and guidance |
| EBA-GL-93 | Updating guidance for new threats |
| EBA-GL-94 | Option to disable payment functionalities |
| EBA-GL-95 | Adjustable spending limits |
| EBA-GL-96 | Alerts on initiated and failed payment transactions |
| EBA-GL-97 | Informing users of updates to security procedures |
| EBA-GL-98 | Assistance on security questions and anomaly notifications |
Sections 3.1 to 3.7, repealed by EBA/GL/2025/02 from 20 May 2025 and superseded by DORA – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04)
Subject matter, scope, addressees and status – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04)
Your Compliance Coverage
If you comply with EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04), you already cover:
DORA
26%
9 controls mapped
Compare →NIST Cybersecurity Framework 2.0
12%
4 controls mapped
Compare →ISO 27002:2022
6%
2 controls mapped
Compare →+ 10 more: ISO 22301:2019 (3%), NIST SP 800-53 Rev 5 (3%)
See all 13 mapped frameworks ↓Maps to 13 other frameworks
Coverage is not the same as your position
This page shows what EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) and who does it apply to?
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) is a compliance framework from European Union (EBA) with 3 domains and 43 controls. The European Banking Authority Guidelines on ICT and security risk management (EBA/GL/2019/04, applied from 30 June 2020), as amended by EBA/GL/2025/02 from 20 May 2025: with DORA governing the ICT risk of EU financial entities from 17 January 2025, sections 3.1 to 3.7 (governance and strategy, the risk management framework, information security, ICT operations, project and change management, business continuity) were repealed and only section 3.8, payment service user relationship management, remains, addressed to payment service providers. The repealed sections are kept here with their text and their mappings to DORA as the historical baseline. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) actually require?
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) has 43 controls organised across 3 domains. The largest domains are Sections 3.1 to 3.7, repealed by EBA/GL/2025/02 from 20 May 2025 and superseded by DORA – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) (32 controls), Section 3.8: payment service user relationship management (in force) – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) (8 controls), Subject matter, scope, addressees and status – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) do I already cover?
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) maps to 13 other compliance frameworks. The top mapping partners are DORA (26% coverage), NIST Cybersecurity Framework 2.0 (12% coverage), ISO 27002:2022 (6% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04)?
Start your EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 43 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required