- within Finance and Banking topic(s)
- in Canada
- with readers working within the Technology, Media & Information and Retail & Leisure industries
- within Finance and Banking and Technology topic(s)
Among the main pressure points, the MFSA highlighted weaknesses in business continuity, incident handling, patch and vulnerability management, and contractual controls for ICT outsourcing arrangements. It also noted that overreliance on unverified generative AI in submissions can create generic or inaccurate materials that slow down authorisation processes.
The MFSA’s latest ICT circulars underline a clear supervisory focus on digital operational resilience, with particular scrutiny on authorisation applications, TLPT provider standards, and emerging cyber threat awareness. The message is that firms need stronger, more tailored documentation and a better practical grasp of DORA requirements, especially around ICT risk management and third-party oversight.
Among the main pressure points, the MFSA highlighted weaknesses in business continuity, incident handling, patch and vulnerability management, and contractual controls for ICT outsourcing arrangements. It also noted that overreliance on unverified generative AI in submissions can create generic or inaccurate materials that slow down authorisation processes.
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.
[View Source]