Follow

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Contact

Kosovo CBK Regulation on Information Systems and Cyber Risk Management

The Central Bank of the Republic of Kosovo (CBK) approved the Regulation on Information Systems and Cyber Risk Management on 29 August 2025.

The Regulation establishes minimum standards, criteria and procedures for information technology, information systems and cyber risk management for financial institutions licensed or supervised by the CBK.

It represents a significant regulatory framework for strengthening ICT governance, cybersecurity, operational resilience and technology risk management across Kosovo’s financial sector.

Advertisement


Who Does the Regulation Apply To?

The Regulation applies to financial institutions licensed or supervised by the CBK, subject to the scope and proportionality requirements established by the Regulation. In the light of this Regulation, it refers to Financial
Institutions, or FI institutions, which include Banks, Microfinance Institutions, Non-bank Financial Institutions, Insurance Companies, Kosovo Insurance Bureau, Pension Savings Funds, Cryptocurrency Operators and other entities that carry out financial activities, as defined in any relevant Law for the purposes of this Regulation

All banks are required to comply with the Regulation.

For other financial institutions within its scope, the relevant requirements are applied according to the principle of proportionality, taking into account factors such as:

  • size;
  • overall risk profile;
  • internal organization;
  • nature and scope of activities;
  • complexity of services and operations; and
  • riskiness of their activities and operations.

Non-Banking Financial Institutions that only conduct foreign-exchange activities and Insurance Intermediaries are excluded from the scope of the Regulation.


What Does the Regulation Cover?

The Regulation establishes requirements across the main areas of information systems, technology and cybersecurity risk management.

ICT Governance and Management

Financial institutions are required to establish appropriate governance arrangements for information technology and cybersecurity.

The Regulation addresses areas including:

  • ICT governance and organizational responsibilities;
  • ICT strategy;
  • policies and procedures;
  • ICT asset and information management;
  • third-party service providers;
  • staff competencies and background checks;
  • information security awareness and training; and
  • ICT budgeting.

Technology and Cyber Risk Management

Financial institutions must establish an appropriate framework for identifying, assessing, treating, monitoring and reporting technology and cyber risks.

Requirements cover areas such as:

  • technology risk management frameworks;
  • risk assessments;
  • risk treatment and management;
  • risk monitoring and reporting;
  • IT project management;
  • acquisition of IT systems;
  • secure system development;
  • security by design;
  • system requirements, design and implementation;
  • testing and acceptance;
  • secure coding;
  • application security testing;
  • DevSecOps; and
  • APIs.

IT Service Management and Operational Security

The Regulation establishes requirements for managing IT systems and services throughout their operational lifecycle.

These include:

  • IT documentation;
  • physical checks;
  • Software as a Service (SaaS);
  • configuration management;
  • technology refresh management;
  • patch management;
  • change management;
  • incident management;
  • post-incident reviews and lessons learned;
  • identity and access management;
  • network management;
  • virtualization security;
  • data security and privacy;
  • security of personal devices used in the work environment; and
  • secure disposal.

Cybersecurity Operations

Financial institutions must establish capabilities for identifying, detecting, responding to and managing cybersecurity threats and incidents.

The Regulation addresses:

  • cyber threat intelligence;
  • information sharing;
  • cyber-event monitoring and detection;
  • cyber-incident response;
  • cyber-incident management; and
  • regulatory incident reporting.

These requirements reinforce the need for institutions to maintain effective cybersecurity monitoring and incident-management capabilities.

Business Continuity and Disaster Recovery

Operational resilience is another major component of the Regulation.

Financial institutions are expected to establish measures covering:

  • system availability;
  • business continuity management;
  • disaster recovery;
  • disaster recovery testing;
  • backup and recovery; and
  • data center requirements.

These controls are intended to support the availability and recovery of critical systems and services following disruptive events.

Security Testing and Exercises

Financial institutions must assess the effectiveness of their cybersecurity controls through appropriate security testing.

The Regulation addresses:

  • vulnerability scanning;
  • penetration testing;
  • incident response exercises; and
  • corrective measures resulting from identified weaknesses.

Security weaknesses identified through testing should therefore feed into remediation and risk-management processes.

Independent Audit and Assurance

The Regulation also establishes independent audit requirements relating to ICT and cybersecurity.

Independent assurance provides management and governing bodies with an objective assessment of whether ICT governance, cybersecurity controls and risk-management arrangements are appropriately designed and implemented and whether applicable regulatory requirements are being addressed.

Outsourcing and Third-Party Technology Services

The use of external technology providers does not remove the financial institution’s responsibility for managing technology and cyber risks.

The Regulation establishes requirements covering areas including:

  • governance of outsourced technology services;
  • outsourcing risk assessments;
  • contractual requirements;
  • access and audit rights;
  • ongoing supervision of outsourced functions;
  • supplier competence; and
  • cloud computing.

Financial institutions should therefore incorporate technology and cybersecurity risk considerations throughout the lifecycle of outsourced technology arrangements.

Artificial Intelligence

A particularly important element of the Regulation is its treatment of Artificial Intelligence (AI).

The Regulation establishes requirements concerning the development and deployment of AI-enabled solutions and addresses areas such as:

  • AI governance;
  • AI risk assessment;
  • fairness and bias;
  • transparency;
  • explainability and auditability;
  • data quality;
  • model validation;
  • stress testing;
  • customer transparency;
  • incident reporting; and
  • AI-enabled solutions used in critical functions.

The inclusion of AI demonstrates that technology risk management is no longer limited to traditional IT infrastructure and cybersecurity controls. Financial institutions must also consider the governance and risks associated with increasingly automated and AI-enabled systems.


Enforcement and Administrative Measures

Compliance with the Regulation is subject to CBK supervision.

The Regulation contains provisions concerning:

  • remedial measures;
  • administrative penalties;
  • applicability;
  • regulatory reporting;
  • incident-reporting templates;
  • implementation guidelines; and
  • transitional and final provisions.

Financial institutions should therefore treat implementation as a regulatory compliance obligation rather than solely as an IT or cybersecurity initiative.


Key Dates

The Regulation was approved on 29 August 2025 and entered into force on 15 September 2025.

Financial institutions within its scope are required to comply with its requirements from:

1 June 2026

Organizations subject to the Regulation should therefore have the required governance structures, policies, processes, controls, technical measures and supporting evidence in place.


What Should Financial Institutions Do?

Implementation should begin with a structured assessment of the institution’s current ICT and cybersecurity environment against the requirements of the Regulation.

Key activities should include:

  1. Perform a regulatory gap assessment against the applicable requirements.
  2. Identify applicable requirements based on the institution’s regulatory status and the principle of proportionality.
  3. Review ICT and cybersecurity governance, including roles, responsibilities and management oversight.
  4. Review and update policies, procedures and standards required to support compliance.
  5. Assess technology and cyber risks and document appropriate risk-treatment measures.
  6. Review technical and operational controls, including access management, patching, network security, monitoring, backup and recovery.
  7. Review incident-management and regulatory-reporting processes.
  8. Assess business continuity and disaster-recovery capabilities.
  9. Review outsourcing, cloud and third-party technology arrangements.
  10. Assess AI governance and controls where AI-enabled solutions are used.
  11. Conduct vulnerability assessments, penetration testing and resilience exercises as applicable.
  12. Establish evidence and documentation demonstrating implementation and ongoing compliance.

From Compliance Requirement to Operational Resilience

The CBK Regulation on Information Systems and Cyber Risk Management establishes a comprehensive framework for technology governance and cyber resilience within Kosovo’s regulated financial sector.

Its scope extends beyond traditional cybersecurity. It connects governance, technology risk, secure development, IT operations, cyber defence, incident management, business continuity, outsourcing, independent assurance and artificial intelligence within a common regulatory framework.

For financial institutions, effective implementation should therefore not be treated as a one-time compliance exercise.

It should become part of the institution’s broader technology governance, risk management and operational resilience framework.


Official Regulation:
Central Bank of the Republic of Kosovo – Regulation on Information Systems and Cyber Risk ManagementApproved: 29 August 2025
Entry into force: 15 September 2025
Compliance date: 1 June 2026

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Advertisement
D P3 Sh.p.k.
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.