OJK Issues New Regulations on Information Technology Implementation for Commercial Banks
The Financial Services Authority (OOK) has issued new provisions regarding the implementation of information technology (IT) by commercial banks. These regulations were developed in response to rapid advancements in information technology, which play a vital role in supporting both the operational and business activities of the banking industry.
The regulations are set out in the OJK Board of Commissioners Member Regulation Number 1 of 2026 concerning the Implementation of Information Technology by Commercial Banks (PADK OJK No. 1 of 2026).
According to its official statement, the rapid development of information technology offers various alternative solutions and conveniences for the banking industry. However, alongside these conveniences, several emerging risks must be identified and mitigated.
“The increased use of IT can also give rise to risks that need to be identified, mitigated, and even controlled, so as not to disrupt banking business,” OJK stated on Wednesday (2/9/2026).
Consequently, OJK has requested that banks strengthen their IT governance to ensure that the use of technology provides added value to the bank through the optimisation of resources to mitigate facing risks.
The legal basis for this OJK Board of Commissioners Member Regulation (PADK OJK) is Law No. 21 of 2011, as amended by Law No. 4 of 2023, and POJK No. 11/POJK.03/2022.
The regulation covers several aspects, including the implementation of IT governance, including the roles and responsibilities of the board of directors, the board of commissioners, the IT steering committee, and IT work units.
Furthermore, it regulates the process of developing IT architecture and IT strategic plans, as well as IT risk management processes, including the security of information and communication networks.
Additionally, the regulation governs the use of IT service providers, licensing for the placement of electronic systems and IT-based transaction processing outside of Indonesia, data management and personal data protection, the provision of IT services by banks, internal control and auditing, as well as reporting requirements.
The regulation, which takes effect on 1 March 2026 and was established on 23 January 2026, also provides guidelines for IT implementation by commercial banks, procedures for submitting reports and permit applications, report formats and notifications, as well as formats for permit applications and realisation reports in IT implementation.
Upon the commencement of this PADK OJK, the provisions contained in the Financial Services Authority Circular Letter Number 21/SEOJK.03/2017 regarding the Implementation of Risk Management in the Use of Information Technology by Commercial Banks shall be revoked and declared invalid.