SEOJK 29/SEOJK.03/2022 OJK | Annual cyber security and resilience assessment for commercial banks: an inherent risk rating, plus maturity across two components — the quality of cyber risk management implementation, and the quality of cyber resilience process implementation. Filed within 15 business days of year end. | Independent assessment against both components — governance, risk framework, risk process and control system on one side; identify, protect, detect, respond and recover on the other — with the remediation sequence that actually moves the rating. | Scored assessment, evidence pack, board-ready summary |
POJK 11/POJK.03/2022 OJK | IT governance, architecture, risk management, personal data protection, service provision, and internal audit and control for commercial banks. | vCISO-led control design and third-party risk assessment, mapped clause by clause rather than to a generic framework. | Control matrix, outsourcing risk register |
PADK 1/2026 OJK | The implementing regulation under POJK 11, effective 1 March 2026: IT governance and architecture, IT risk management, third-party IT providers, offshore placement licensing, data management and personal data protection, internal control, audit and reporting. It repeals SEOJK 21/2017; SEOJK 29 remains in force alongside it. | Re-baseline against the new instrument rather than the one it replaced — most banks' control documentation still references the 2017 circular. | Re-baselined control matrix, gap register |
PBI No. 2 of 2024 Bank Indonesia | Information system security and cyber resilience for payment system operators, money market and foreign exchange participants, and other parties regulated and supervised by Bank Indonesia. | Threat-led testing of the payment rails themselves, plus 24/7 detection tuned to payment-specific abuse rather than generic malware signatures. | Test reports, detection coverage matrix |
PBI No. 10 of 2025 Bank Indonesia | Restructured, risk-based obligations across payment service providers, infrastructure operators and supporting providers. In force 31 March 2026. | Readiness assessment against your new category, before a supervisor tells you which one you are in. | Category gap analysis, remediation roadmap |
UU PDP Republic of Indonesia | Lawful basis, data protection impact assessment, and notification of a personal data breach within 72 hours. | Data governance implementation and incident runbooks built against the clock — 72 hours is not long enough to start deciding who signs. | DPIA records, notification runbook, RACI |
SWIFT CSP SWIFT | Annual attestation against the mandatory control set, independently assessed. | Independent assessment and remediation of failed controls, scheduled so attestation is not a fire drill. | Assessor report, attestation-ready pack |
PCI DSS v4.0.1 PCI SSC | Cardholder data environment controls, with segmentation validated by testing. | Segmentation penetration testing and CDE scoping — most of the saving is in proving the scope is smaller than assumed. | Segmentation test report, scope reduction memo |