Back to Frameworks

EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04)

European Union (EBA)
v2019/04 as amended 2025/02 (consolidated 2026-05-19)
3 domains
43 controls

The European Banking Authority Guidelines on ICT and security risk management (EBA/GL/2019/04, applied from 30 June 2020), as amended by EBA/GL/2025/02 from 20 May 2025: with DORA governing the ICT risk of EU financial entities from 17 January 2025, sections 3.1 to 3.7 (governance and strategy, the risk management framework, information security, ICT operations, project and change management, business continuity) were repealed and only section 3.8, payment service user relationship management, remains, addressed to payment service providers. The repealed sections are kept here with their text and their mappings to DORA as the historical baseline.

Verified

EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) is a compliance framework from European Union (EBA) with 3 domains and 43 controls that map to 13 other frameworks. The largest domains are Sections 3.1 to 3.7, repealed by EBA/GL/2025/02 from 20 May 2025 and superseded by DORA – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) (32 controls), Section 3.8: payment service user relationship management (in force) – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) (8 controls), Subject matter, scope, addressees and status – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) (3 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (3)

Section 3.8: payment service user relationship management (in force) – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04)

8 controls
Controls in the Section 3.8: payment service user relationship management (in force) – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) domain of EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04)7 controls
CodeTitle
EBA-GL-92Awareness of security risks through assistance and guidance
EBA-GL-93Updating guidance for new threats
EBA-GL-94Option to disable payment functionalities
EBA-GL-95Adjustable spending limits
EBA-GL-96Alerts on initiated and failed payment transactions
EBA-GL-97Informing users of updates to security procedures
EBA-GL-98Assistance on security questions and anomaly notifications

Sections 3.1 to 3.7, repealed by EBA/GL/2025/02 from 20 May 2025 and superseded by DORA – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04)

32 controls

Subject matter, scope, addressees and status – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04)

3 controls

Your Compliance Coverage

If you comply with EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04), you already cover:

Maps to 13 other frameworks

34 total controls
DORA
9 source controls mapped|8 target controls covered
26%
NIST Cybersecurity Framework 2.0
4 source controls mapped|3 target controls covered
12%
ISO 27002:2022
2 source controls mapped|3 target controls covered
6%
ISO 22301:2019
1 source controls mapped|2 target controls covered
3%
NIST SP 800-53 Rev 5
1 source controls mapped|1 target controls covered
3%
ISO 27701:2019
1 source controls mapped|1 target controls covered
3%
ISO 27001:2022
1 source controls mapped|2 target controls covered
3%
ISO 19011:2018
1 source controls mapped|1 target controls covered
3%
ISO/IEC 42001:2023
1 source controls mapped|1 target controls covered
3%
ISO/IEC 17025:2017 - General Requirements for Testing and Calibration
1 source controls mapped|2 target controls covered
3%
ISO 27018:2019
1 source controls mapped|1 target controls covered
3%
ISO 13485:2016
1 source controls mapped|1 target controls covered
3%
ISO/IEC 38500:2024
1 source controls mapped|10 target controls covered
3%

Coverage is not the same as your position

This page shows what EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) and who does it apply to?

EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) is a compliance framework from European Union (EBA) with 3 domains and 43 controls. The European Banking Authority Guidelines on ICT and security risk management (EBA/GL/2019/04, applied from 30 June 2020), as amended by EBA/GL/2025/02 from 20 May 2025: with DORA governing the ICT risk of EU financial entities from 17 January 2025, sections 3.1 to 3.7 (governance and strategy, the risk management framework, information security, ICT operations, project and change management, business continuity) were repealed and only section 3.8, payment service user relationship management, remains, addressed to payment service providers. The repealed sections are kept here with their text and their mappings to DORA as the historical baseline. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) actually require?

EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) has 43 controls organised across 3 domains. The largest domains are Sections 3.1 to 3.7, repealed by EBA/GL/2025/02 from 20 May 2025 and superseded by DORA – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) (32 controls), Section 3.8: payment service user relationship management (in force) – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) (8 controls), Subject matter, scope, addressees and status – EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) do I already cover?

EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) maps to 13 other compliance frameworks. The top mapping partners are DORA (26% coverage), NIST Cybersecurity Framework 2.0 (12% coverage), ISO 27002:2022 (6% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04)?

Start your EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 43 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.

Get Started Free →

Free forever — no credit card required