Financial entities shall have in place an internal governance and control framework that ensures an effective and prudent management of all ICT risks, in order to achieve a high level of digital operational resilience.
Board-approved document defining the internal governance and control framework for ICT risk management, including roles, responsibilities, reporting lines, and oversight mechanisms.
ict-governance-frameworkGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
ICT GOVERNANCE AND CONTROL FRAMEWORK
Nordvik Bank AG
Version 2.1 | Approved: 10 January 2025 | Next Review: 10 January 2026
Approving Body: Board of Directors
Classification: Internal — Restricted
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
EXECUTIVE SUMMARY
This document establishes the internal governance and control framework for ICT
risk management at Nordvik Bank AG ("the Bank"), as required by Article 5 of the
Digital Operational Resilience Act (Regulation (EU) 2022/2554, "DORA"). The
framework defines the organisational structure, roles, responsibilities, reporting
lines, and oversight mechanisms that ensure effective and prudent management of all
ICT risks across the Bank.
The governance framework is designed to achieve a high level of digital operational
resilience by embedding ICT risk management into the Bank's overall corporate
governance structure. It ensures that the management body is actively involved in
steering and adapting the ICT risk management framework, and that adequate resources
are allocated to ICT risk management activities.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
GOVERNANCE STRUCTURE
1.1 Organisational Overview
The Bank's ICT governance structure is organised around three principal layers:
Strategic Layer: Board of Directors and Board Risk Committee — responsible
for setting ICT risk appetite, approving the ICT risk
management framework, and overseeing its implementation.
Tactical Layer: Executive Management (CIO, CISO, CRO) and the ICT Risk
Committee — responsible for translating strategic direction
into operational policies, allocating resources, and
monitoring risk indicators.
Operational Layer: ICT Operations, Security Operations Centre, Business Units
— responsible for day-to-day implementation of controls,
incident management, and risk reporting.
1.2 Governance Model
The Bank operates a federated governance model where ICT risk management
responsibilities are distributed across business lines and technology functions,
with centralised oversight provided by the Risk Management function. This model
ensures that ICT risk decisions are made close to the operational context while
maintaining consistent standards and reporting across the organisation.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
BOARD OVERSIGHT RESPONSIBILITIES
2.1 Board of Directors
The Board of Directors shall:
(a) Define and approve the Bank's ICT risk appetite and tolerance levels;
(b) Approve the ICT risk management framework and any material amendments;
(c) Ensure adequate budget and human resources are allocated to ICT risk
management, including ICT security and digital operational resilience;
(d) Receive and review quarterly ICT risk reports from the Board Risk Committee;
(e) Approve the Bank's digital operational resilience strategy;
(f) Ensure that members of the management body maintain sufficient knowledge
and skills to understand and assess ICT risk, including through regular
training on ICT-related topics (minimum annually).
Oversight frequency: Quarterly review of ICT risk posture at Board meetings.
2.2 Board Risk Committee
The Board Risk Committee ("BRC") shall:
(a) Oversee the implementation of the ICT risk management framework;
(b) Review the ICT risk dashboard and key risk indicators quarterly;
(c) Review and challenge material ICT risk assessments and treatment plans;
(d) Monitor the status of ICT risk remediation actions;
(e) Recommend changes to the ICT risk appetite to the Board;
(f) Review the results of digital operational resilience testing.
The BRC meets quarterly, with extraordinary sessions convened following material
ICT incidents or significant changes to the Bank's ICT risk profile.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
THREE LINES OF DEFENCE MODEL
The Bank applies the Three Lines of Defence model to ICT risk management in
accordance with DORA Article 5(2) and EBA Guidelines:
FIRST LINE OF DEFENCE — Risk Ownership
ICT Operations and Development:
— Own and manage ICT risks within their operational domains
— Implement and maintain ICT security controls
— Maintain ICT asset inventories and configuration management
— Report ICT incidents and near-misses
— Conduct first-level risk assessments for change management
Business Units:
— Own business process-level ICT risks
— Define business requirements for ICT resilience (RTO/RPO)
— Participate in business continuity testing
— Report ICT-related operational disruptions
SECOND LINE OF DEFENCE — Risk Oversight
Risk Management Function (CRO):
— Maintain the ICT risk management framework and risk appetite
— Provide independent challenge to first-line risk assessments
— Maintain the enterprise ICT risk register
— Report ICT risk posture to the Board Risk Committee
— Coordinate ICT risk-related regulatory engagement
Compliance Function:
— Monitor adherence to DORA and related regulatory requirements
— Advise on regulatory expectations for ICT risk management
— Conduct compliance assessments of ICT policies and procedures
Information Security Function (CISO):
— Define ICT security policies and standards
— Manage threat intelligence and vulnerability management
— Oversee security incident response
— Conduct security awareness training
THIRD LINE OF DEFENCE — Independent Assurance
Internal Audit:
— Provide independent assurance on the effectiveness of ICT risk
management and control frameworks
— Conduct risk-based ICT audits per the annual audit plan
— Report findings directly to the Audit Committee
— Follow up on remediation of audit findings
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ICT RISK COMMITTEE TERMS OF REFERENCE
5.1 Purpose
The ICT Risk Committee ("ICTRC") is an executive-level committee established to
provide focused oversight of ICT risk management activities across the Bank.
5.2 Composition
Chair: Chief Risk Officer (CRO)
Members: Chief Information Officer (CIO)
Chief Information Security Officer (CISO)
Head of Business Continuity
Head of Vendor Management
Head of IT Operations
Representatives from material business lines (Retail Banking,
Corporate Banking, Treasury, Payment Services)
5.3 Meeting Frequency
The ICTRC meets monthly, with extraordinary sessions as required following
material ICT incidents or emerging threats.
5.4 Responsibilities
(a) Review and update the ICT risk register
(b) Approve ICT risk treatment decisions within delegated authority
(c) Monitor key risk indicators and escalate breaches
(d) Review ICT incident trends and lessons learned
(e) Oversee third-party ICT risk management activities
(f) Recommend policy changes to the Board Risk Committee
(g) Review digital operational resilience testing plans and results
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
REPORTING LINES AND ESCALATION
6.1 Reporting Structure
Board of Directors
└── Board Risk Committee (quarterly ICT risk reports)
└── ICT Risk Committee (monthly risk register updates)
├── CIO — ICT operations and infrastructure reporting
├── CISO — Security posture and incident reporting
├── CRO — Risk assessment and appetite monitoring
└── Business Lines — Operational disruption reporting
6.2 Escalation Thresholds
Level 1 (Operational): ICT incidents affecting non-critical systems
→ Escalate to ICT Operations Manager within 1 hour
Level 2 (Tactical): ICT incidents affecting important functions or
risk appetite threshold breaches
→ Escalate to CISO/CIO within 2 hours
Level 3 (Strategic): ICT incidents affecting critical functions or
material risk appetite breaches
→ Escalate to CRO and ICTRC within 4 hours
→ Notify Board Risk Committee Chair within 24 hours
Level 4 (Crisis): Major ICT incidents with potential systemic impact
→ Activate Crisis Management Team immediately
→ Notify Board Chair and competent authority per
DORA Article 19 timelines
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
REVIEW AND APPROVAL HISTORY
This framework is reviewed annually and following material changes to the Bank's
ICT risk profile, organisational structure, or regulatory requirements.
Document History:
v2.1 10 Jan 2025 Updated for DORA compliance; enhanced Three Lines of Defence
v2.0 15 Jan 2024 Major revision; established ICT Risk Committee
v1.5 12 Jan 2023 Annual review; updated escalation thresholds
v1.0 20 Mar 2022 Initial version
Approved by: Board of Directors
Signature: [Board Chair]
Date: 10 January 2025
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
ict_governance_framework_status — fs-ict-governance-framework
{
"factId": "c1d2e3f4-a5b6-7890-cdef-100000000001",
"evidenceId": "a0b1c2d3-e4f5-6789-abcd-100000000001",
"evidenceClassId": "ict-governance-framework",
"factType": "ict_governance_framework_status",
"data": {
"governance_model": "Federated governance with centralised oversight by Risk Management function",
"approval_date": "2025-01-10",
"next_review_date": "2026-01-10",
"has_three_lines_of_defence": true,
"board_oversight_frequency": "quarterly",
"ict_risk_committee_exists": true,
"reporting_lines_documented": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-01-15T09:00:00Z",
"supersededBy": null
}
fs-ict-governance-frameworkDORA-Art5-P1approval_datenext_review_dateboard_oversight_frequency{
"properties": {
"approval_date": {
"format": "date",
"type": "string"
},
"board_oversight_frequency": {
"enum": [
"monthly",
"quarterly",
"semi-annual",
"annual"
],
"type": "string"
},
"governance_model": {
"minLength": 1,
"type": "string"
},
"has_three_lines_of_defence": {
"type": "boolean"
},
"ict_risk_committee_exists": {
"type": "boolean"
},
"next_review_date": {
"format": "date",
"type": "string"
},
"reporting_lines_documented": {
"type": "boolean"
}
},
"required": [
"governance_model",
"approval_date",
"next_review_date",
"has_three_lines_of_defence",
"board_oversight_frequency"
],
"type": "object"
}