Under active development Content is continuously updated and improved

Article 6.6Article 6.6

>Control Description

The ICT risk management framework of financial entities, other than microenterprises, shall be subject to internal audit by auditors on a regular basis in line with the financial entities’ audit plan. Those auditors shall possess sufficient knowledge, skills and expertise in ICT risk, as well as appropriate independence. The frequency and focus of ICT audits shall be commensurate to the ICT risk of the financial entity.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.