Skip to main content

Basel Consolidated Guidelines

This page sets out the guidelines and sound practices issued by the Basel Committee on Banking Supervision (BCBS). The application page outlines the implementation expectations for guidelines and sound practices, and their scope of application.

The consolidated guidelines and sound practices comprise the 13 modules listed below. Each module is divided into chapters. Each chapter includes links to the original source publications from which the contents of the chapter are based, related standards, related guidelines or sound practices, and other publications that are relevant to a particular topic.

Please provide first name.
Looks good!
RMA50

Digitalisation and financial technology risks

This chapter describes risks and expectations for banks and supervisors related to electronic banking (e-banking) activities.
  • Published: 01 Jan 2026

Guidelines

This chapter describes risks and expectations for banks and supervisors related to electronic banking (e-banking) activities.

The contents of this chapter are based on:

Related standards

Related guidelines

Other related publications

Foreword

50.1

Electronic banking, or e-banking, includes the provision of retail and small value banking products and services through electronic channels as well as large value electronic payments and other wholesale banking services delivered electronically. E-banking does not create inherently new risks, but may change the traditional risks associated with banking activities, including strategic, operational, legal and reputational risks. While existing risk management principles remain applicable to e-banking activities, such principles must be tailored, adapted and, in some cases, expanded to address the specific risk management challenges created by the characteristics of e-banking activities.

Key terms

50.2

The following terms are used throughout this chapter and have the meaning given below:

  1. Authentication: refers to the techniques, procedures and processes used to verify the identity and authorisation of prospective and established customers.
  2. Authorisation: refers to the procedures, techniques and processes used to determine that a customer or an employee has legitimate access to the bank account or the authority to conduct associated transactions on that account.
  3. Biometric technology: is an automated view of physiological or behavioural characteristics used to identify and/or authenticate a person. Common forms of biometric technology include facial scans, fingerprint scans, iris scans, retina scans, hand scans, signature scans, voice scans and keystroke dynamics. Biometric identification systems provide very strong authentication, but may pose greater implementation complexities than other identification/authentication methods.
  4. Cross-border e-banking: is the provision of online banking products or services by a bank in one country to residents of another country including where a foreign bank provides e-banking products or service to residents in a foreign country from a location in the bank’s home country or from an “onshore” physical establishment in another foreign country.
  5. Identification: refers to the procedures, techniques and processes used to establish the identity of a customer when opening an account.
  6. Spoofing: refers to is the impersonation of a legitimate customer through use of his/her account number, password, personal identification number (PIN) and/or email address.
  7. Sniffer: is a device that is capable of eavesdropping on telecommunications traffic, capturing passwords and data in transit.

Electronic Banking Risk Management Principles

50.3

This chapter sets out supervisory expectations and guidance for banks carrying out electronic banking (e-banking) activities, as well as to their home and host supervisors. Banks are expected to recognise, address and manage the risks associated with the provision of e-banking services.

50.4

Principle 1: Prior to engaging in cross-border e-banking activities, a bank should conduct appropriate risk assessment and due diligence and establish an effective risk management program for such activities.

50.5

Initial risk assessment, due diligence and ongoing risk management considerations should include, but are not limited to, such factors as country risk, compliance risk, regulatory requirements, local business practices, accounting standards and the legal environment, as well as the operational, security, privacy, and customer service challenges presented by the online delivery of banking products and services to foreign customers.

50.6

One of the major risks associated with cross-border operations is failure, whether inadvertent or otherwise, to comply with applicable foreign (and therefore possibly less well known) laws and regulations, and uncertainty over how “choice of law” principles can be applied in an e-commerce context. Banks should recognise that substantial differences might exist between jurisdictions with respect to bank licensing, supervisory and customer protection requirements. A bank’s due diligence reviews should also recognise that local authorities other than bank supervisors may exercise oversight on issues pertaining to the bank’s activities with local residents. Such authorities may include the central bank, consumer protection authorities, investment services regulators, or authorities responsible for preventing financial crime. The differences in licensing and other requirements in various jurisdictions, and the uncertainty with respect to how choice of law principles are applied could increase the complexity and cost of the bank’s due diligence.

50.7

A bank could be expected to define and generally mitigate its due diligence obligation by posting on its website a conspicuous disclaimer that limits its on-line product and service offerings to only the residents of specified countries. This type of disclaimer should be made in conjunction with the need for the bank to be transparent relative to its intentions. However, the bank should also recognise that the legal effect of such a disclaimer might be somewhat uncertain. In addition, its value may vary between jurisdictions, particularly if the disclaimer is not backed up by appropriate policies and internal controls that ensure that the bank does not inadvertently conduct e-banking business with residents of an excluded country.

50.8

Sound security control practices for e-banking include:

  1. Security profiles should be created and maintained and specific authorisation privileges assigned to all users of e-banking systems and applications, including all customers, internal bank users and outsourced service providers. Logical access controls should also be designed to support proper segregation of duties.1
  2. E-banking data and systems should be classified according to their sensitivity and importance and protected accordingly. Appropriate mechanisms, such as encryption, access control and data recovery plans should be used to protect all sensitive and high-risk e-banking systems, servers, databases and applications.
  3. Storage of sensitive or high-risk data on the organisation’s desktop and laptop systems should be minimised and properly protected by encryption, access control and data recovery plans.
  4. Sufficient physical controls should be in place to deter unauthorised access2 to all critical e-banking systems, servers, databases and applications.
  5. Appropriate techniques should be employed to mitigate external threats to e-banking systems, including the use of:
    1. Virus-scanning software at all critical entry points (eg remote access servers, e-mail proxy servers) and on each desktop system.
    2. Intrusion detection software and other security assessment tools to periodically probe networks, servers and firewalls for weaknesses and/or violations of security policies and controls.
    3. Penetration testing of internal and external networks.
  6. A rigorous security review process should be applied to all employees and service providers holding sensitive positions.
1

Definitions of security and quality standards and reliance on certification schemes can be institution specific or standardised (ie within a national banking industry to enhance and foster the security level of e- banking activities). Banks can also choose to establish access rights in either a centralised or distributed manner. For example, there may be a single authorisation authority responsible for assigning access rights to specific identities, groups or roles within a bank, or there may be several authorisation authorities established to address the varying needs within the different business lines.

2

This should include controls guarding against unauthorised access by external parties such as visitors, contractors or technicians who may have access to the premises although they may not be directly involved in the e-banking service.

50.9

Principle 2: Banks should take appropriate measures to authenticate the identity and authorisation of customers with whom it conducts business over the internet.

50.10

Banks should use reliable methods for verifying the identity and authorisation of new customers as well as authenticating the identity and authorisation of established customers seeking to initiate electronic transactions.

50.11

Customer verification during account origination is important in reducing the risk of identity theft, fraudulent account applications and money laundering. Failure on the part of the bank to adequately authenticate customers could result in unauthorised individuals gaining access to e-banking accounts and ultimately financial loss and reputational damage to the bank through fraud, disclosure of confidential information or inadvertent involvement in criminal activity.

50.12

Legitimate user authorisation can be misrepresented through a variety of techniques generally known as “spoofing." Online hackers can also take over the session of a legitimate authorised individual through use of a "sniffer" and carry out activities of a mischievous or criminal nature. Authentication control processes can in addition be circumvented through the alteration of authentication databases.

50.13

It is critical that banks have formal policy and procedures identifying appropriate methodology(ies) to ensure that the bank properly authenticates the identity and authorisation of an individual, agent or system (including the banks’ own websites) by means that are unique and, as far as practical, exclude unauthorised individuals or systems.3 Banks can us a variety of methods to establish authentication, including PINs, passwords, smart cards, biometrics, and digital certificates.4 These methods can be either single factor or multi-factor (eg using both a password and biometric technology to authenticate). Multi-factor authentication generally provides stronger assurance.

3

Systems must ensure that they are dealing with an authenticated individual, agent or system and with a valid authentication database.

4

A bank may issue digital certificates using public key infrastructure (PKI) to a customer to secure communications with the bank. Digital certificates and PKI are discussed more fully in Principle 3.

50.14

The bank must determine which authentication methods to use based on management's assessment of the risk posed by the e-banking system as a whole or by the various sub- components. This risk analysis should evaluate the transactional capabilities of the e- banking system (eg funds transfer, bill payment, loan origination, account aggregation etc.), the sensitivity and value of the stored e-banking data, and the customer's ease of using the authentication method.

50.15

Robust customer identification and authentication processes are particularly important in the cross-border e-banking context given the additional challenges that may arise from doing business electronically with customers across national borders. These include the greater risk of identity impersonation and the greater difficulty in conducting effective credit checks on potential customers.

50.16

As authentication methods continue to evolve, banks are encouraged to monitor and adopt industry sound practice in this area such as ensuring that:

  1. Authentication databases that provide access to e-banking customer accounts or sensitive systems are protected from tampering and corruption. Any such tampering should be detectable and audit trails should be in place to document such attempts.
  2. Any addition, deletion or change of an individual, agent or system to an authentication database is duly authorised by an authenticated source.5
  3. Appropriate measures are in place to control the e-banking system connection such that unknown third parties cannot displace known customers.
  4. Authenticated e-banking sessions remain secure throughout the full duration of the session. or in the event of a security lapse the session should require re- authentication.
5

In some cases, the authenticated source may be an electronic source.

50.17

Principle 3: Banks should use transaction authentication methods that promote non-repudiation and establish accountability for e-banking transactions.

50.18

Non-repudiation involves creating proof of the origin or delivery of electronic information to protect the sender against false denial by the recipient that the data has been received, or to protect the recipient against false denial by the sender to which the data has been sent. Risk of transaction repudiation is already an issue with conventional transactions such as credit cards or securities transactions. However, e-banking heightens this risk because of the difficulties of positively authenticating the identities and authority of parties initiating transactions, the potential for altering or hijacking electronic transactions, and the potential for e-banking users to claim that transactions were fraudulently altered.

50.19

To address these heightened concerns, banks need to make reasonable efforts, commensurate with the materiality and type of the e-banking transaction, to ensure that:

  1. E-banking systems are designed to reduce the likelihood that authorised users will initiate unintended transactions and that customers fully understand the risks associated with any transactions they initiate.
  2. All parties to the transaction are positively authenticated and control is maintained over the authenticated channel.
  3. Financial transaction data are protected from alteration and any alteration is detectable.
50.20

Banks employ various techniques, such as digital certificates using public key infrastructure (PKI), that help establish non- repudiation and ensure confidentiality and integrity of e-banking transactions.6 A bank may issue a digital certificate to a customer or counterparty to allow for their unique identification/authentication and reduce the risk of transaction repudiation.

6

Each party in a PKI has a private/public key pair. The private key is secret so that only one person should use it. All parties use the public key. The private key generates an electronic signature on the document and the key pairs are designed so that a message encrypted with the private key can only be read by using the other key. A bank may act as its own certification authority (CA) or rely on another trusted third-party to associate a person or entity with the digital certificate. However, if a bank relies on a third- party digital certificate to establish authenticity, it should confirm that the CA, when issuing the certificate, used the same level of authentication that the bank would have used to authenticate the person.

50.21

Sound authorisation practices for e-banking applications include:

  1. Specific authorisation and access privileges should be assigned to all individuals, agents or systems, which conduct e-banking activities.
  2. All e-banking systems should be constructed to ensure that they interact with a valid authorisation database.
  3. No individual agent or system should have the authority to change his or her own authority or access privileges in an e-banking authorisation database.7
  4. Any addition of an individual, agent or system or changes to access privileges in an e-banking authorisation database should be duly authorised by an authenticated source empowered with the adequate authority and subject to suitable and timely oversight and audit trails.
  5. Appropriate measures should be in place to make e-banking authorisation databases reasonably resistant to tampering. Any such tampering should be detectable through ongoing monitoring processes. Sufficient audit trails should exist to document any such tampering.
  6. Any e-banking authorisation database that has been tampered with should not be used until replaced with a validated database.
  7. Controls should be in place to prevent changes to authorisation levels during e- banking transaction sessions and any attempts to alter authorisation should be logged and brought to the attention of management.
7

As this might not be feasible for system administrator users, other stringent internal controls and segregation of duties should be put in place to monitor the activities of those user accounts.

50.22

Principle 4: Banks should ensure that appropriate measures are in place to protect the data integrity of e-banking transactions, records and information.

50.23

Data integrity refers to the assurance that information that is in-transit or in storage is not altered without authorisation. Failure to maintain the data integrity of transactions, records and information can expose banks to financial losses as well as to substantial legal and reputational risk.

50.24

The inherent nature of straight-through processes for e-banking may make programming errors or fraudulent activities more difficult to detect at an early stage. Therefore, it is important that banks implement straight-through processing in a manner that ensures safety and soundness and data integrity.

50.25

As e-banking is transacted over public networks, transactions are exposed to the added threat of data corruption, fraud and the tampering of records. Accordingly, banks should ensure that appropriate measures are in place to ascertain the accuracy, completeness and reliability of e-banking transactions, records and information that is either transmitted over the internet, resident on internal bank databases, or transmitted/stored by third-party service providers on behalf of the bank. Common practices used to maintain data integrity within an e-banking environment include the following:

  1. E-banking transactions should be conducted in a manner that makes them highly resistant to tampering throughout the entire process.
  2. E-banking records should be stored, accessed and modified in a manner that makes them highly resistant to tampering.
  3. E-banking transaction and record-keeping processes should be designed in a manner as to make it virtually impossible to circumvent detection of unauthorised changes.
  4. Adequate change control policies, including monitoring and testing procedures, should be in place to protect against any e-banking system changes that may erroneously or unintentionally compromise controls or data reliability.
  5. Any tampering with e-banking transactions or records should be detected by transaction processing, monitoring and record keeping functions.
50.26

Principle 5: Banks should ensure that clear audit trails exist for all e-banking transactions.

50.27

Delivery of financial services over the internet can make it more difficult for banks to apply and enforce internal controls and maintain clear audit trails if these measures are not adapted to an e-banking environment. Banks should ensure that effective internal controls can be provided in highly automated environments, and that the controls can be independently audited, particularly for all critical e-banking events and applications.

50.28

A bank's internal control environment may be weakened if it is unable to maintain clear audit trails for its e-banking activities. This is because much, if not all, of its records and evidence supporting e-banking transactions are in an electronic format. In determining where clear audit trails should be maintained, the following types of e-banking transactions should be considered:

  1. The opening, modification or closing of a customer’s account.
  2. Any transaction with financial consequences.
  3. Any authorisation granted to a customer to exceed a limit.
  4. Any granting, modification or revocation of systems access rights or privileges.
50.29

Sound audit trail practices for e-banking systems include:

  1. Sufficient logs should be maintained for all e-banking transactions to help establish a clear audit trail and assist in dispute resolution.
  2. E-banking systems should be designed and installed to capture and maintain forensic evidence in a manner that maintains control over the evidence, and prevents tampering and the collection of false evidence.
  3. In instances where processing systems and related audit trails are the responsibility of a third-party service provider:
    1. the bank should ensure that it has access to relevant audit trails maintained by the service provider; and
    2. audit trails maintained by the service provider meet the bank's standards.
50.30

Principle 6: Banks should ensure that adequate information is provided on their websites to allow potential customers to make an informed conclusion about the bank's identity, home country and regulatory status of the bank prior to entering into e-banking transactions.

50.31

To minimise legal and reputational risk associated with e-banking activities, banks should ensure that adequate information is provided on their websites to allow customers to make informed conclusions about the identity and regulatory status of the bank before they enter into e-banking transactions.

50.32

Examples of such information that a bank could provide on its own website include:

  1. The name of the bank and the location of its head office (and local offices if applicable).
  2. The identity of the primary bank supervisory authority(ies) responsible for the supervision of the bank's head office.
  3. How customers can contact the bank's customer service centre regarding service problems, complaints, suspected misuse of accounts, etc.
  4. How customers can access and use applicable Ombudsman or consumer complaint schemes.
  5. How customers can obtain access to information on applicable national compensation or deposit insurance coverage and the level of protection that they afford (or links to websites that provide such information).
  6. Other information that may be appropriate or required by specific jurisdictions.8
8

For instance, the bank may wish to specify those countries in which the bank intends to provide e-banking services or, conversely, those countries in which it does not intend to provide such services.

50.33

Principle 7: Banks should take appropriate measures to ensure adherence to customer privacy requirements applicable to the jurisdictions to which the bank is providing e-banking products and services.

50.34

Maintaining a customer’s information privacy is a key responsibility for a bank. Misuse or unauthorised disclosure of confidential customer data exposes a bank to both legal and reputational risk. To meet these challenges concerning the preservation of privacy of customer information, banks should make reasonable endeavours to ensure that:

  1. The bank's customer privacy policies and standards take account of and comply with all privacy regulations and laws applicable to the jurisdictions to which it is providing e-banking products and services.
  2. Customers are made aware of the bank's privacy policies and relevant privacy issues concerning use of e-banking products and services.
  3. Customers may decline (“opt out”) from permitting the bank to share with a third party for cross-marketing purposes any information about the customer’s personal needs, interests, financial position or banking activity.
  4. Customer data are not used for purposes beyond which they are specifically allowed or for purposes beyond which customers have authorised.9

The bank’s standards for customer data use must be met when third parties have access to customer data through outsourcing relationships.

9

In some jurisdictions, laws and regulations may not require banks to seek the customer’s permission to use customer data for internal purposes. However, they may require that banks give customers the option to decline permission for the bank to share such information with a third party or an affiliate. In other jurisdictions, customers may have the right to prevent the bank from using their data for either internal or external purposes.

50.35

Sound practices to help maintain the privacy of customer e-banking information include:

  1. Banks should employ appropriate cryptographic techniques, specific protocols or other security controls to ensure the confidentiality of customer e-banking data.
  2. Banks should develop appropriate procedures and controls to periodically assess its customer security infrastructure and protocols for e-banking.
  3. Banks should ensure that its third-party service providers have confidentiality and privacy policies that are consistent with their own.
  4. Banks should take appropriate steps to inform e-banking customers about the confidentiality and privacy of their information. These steps may include:
    1. Informing customers of the bank’s privacy policy, possibly on the bank’s website. Clear, concise language in such statements is essential to assure that the customer fully understands the privacy policy. Lengthy legal descriptions, while accurate, are likely to go unread by most customers.
    2. Instructing customers on the need to protect their passwords, personal identification numbers (PINs) and other banking and/or personal data.
    3. Providing customers with information regarding the general security of their personal computer, including the benefits of using virus protection software, physical access controls and personal firewalls for static internet connections.
50.36

Principle 8: Banks should develop appropriate incident response plans to manage, contain and minimise problems arising from unexpected events, including internal and external attacks, that may hamper the provision of e-banking systems and services.

50.37

Effective incident response mechanisms are critical to minimise operational, legal and reputational risks arising from unexpected events such as internal and external attacks that may affect the provision of e-banking systems and services. Banks should develop appropriate incident response plans, including communication strategies, that ensure business continuity, control reputational risk and limit liability associated with disruptions in their e-banking services, including those originating from outsourced systems and operations.

50.38

To ensure effective response to unforeseen incidents, banks should develop:

  1. Incident response plans to address recovery of e-banking systems and services under various scenarios, businesses and geographic locations. Scenario analysis should include consideration of the likelihood of the risk occurring and its impact on the bank. E-banking systems that are outsourced to third-party service providers should be an integral part of these plans.
  2. Mechanisms to identify an incident or crisis as soon as it occurs, assess its materiality, and control the reputational risk associated with any disruption in service.10
  3. A communication strategy to adequately address external market and media concerns that may arise in the event of security breaches, online attacks and/or failures of e-banking systems.
  4. A clear process for alerting the appropriate regulatory authorities in the event of material security breaches or disruptive incidents occur.
  5. Incident response teams with the authority to act in an emergency and sufficiently trained in analysing incident detection/response systems and interpreting the significance of related output.
  6. A clear chain of command, encompassing both internal as well as outsourced operations, to ensure that prompt action is taken appropriate for the significance of the incident. In addition, escalation and internal communication procedures should be developed and include notification of the Board where appropriate.
  7. A process to ensure all relevant external parties, including bank customers, counterparties and the media, are informed in a timely and appropriate manner of material e-banking disruptions and business resumption developments.
  8. A process for collecting and preserving forensic evidence to facilitate appropriate post-mortem reviews of any e-banking incidents as well as to assist in the prosecution of attackers.
10

Monitoring of help desk and customer support activities and regular review of customer complaints may help to identify gaps in information being detected and reported through established security controls versus actual intrusion activities.

Application of the guidelines and sound practices

  1. The Basel Framework is the full set of standards of the BCBS. The membership of the BCBS has agreed to fully implement these standards and apply them to the internationally active banks in their jurisdiction.1 For other banks, BCBS members may adopt a proportional approach to implementing specific rules and principles under the given standard.
  2. Guidelines elaborate the standards in areas where they are considered desirable for the prudential regulation and supervision of banks, in particular internationally active banks. They generally supplement BCBS standards by providing additional guidance for the purpose of their implementation.
  3. Sound practices generally describe actual observed practices, with the goal of promoting common understanding and improving supervisory or banking practices. BCBS members are encouraged to compare these practices with those applied by themselves and their supervised institutions to identify potential areas for improvement.
  4. The BCBS also publishes various other documents, including implementation reports and newsletters. These documents do not constitute standards, guidelines or sound practices.
  5. The Committee's standards (ie those set out in the Basel Framework) are subject to monitoring and assessment of their adoption by jurisdictions through the Regulatory Consistency Assessment Programme (RCAP). The Basel Core Principles are used in assessing the effectiveness of countries' regulatory and supervisory regimes, generally under the Financial Sector Assessment Program (FSAP). Guidelines, sound practices and other publications are not subject to RCAPs or FSAPs.
  6. The Committee periodically reviews its guidelines and sound practices as standards, supervisory practices and the financial system evolve. The consolidated guidelines and sound practices are intended to be a living document, which will be updated when the Committee publishes new materials.
  7. Unless otherwise indicated, the guidelines have been developed with a view towards application to: (i) large, internationally active banks; and (ii) supervisory and other relevant financial authorities in Basel Committee member jurisdictions. However, smaller banks and authorities in all jurisdictions may benefit from considering the guidelines and applying them on a proportionate basis, depending on the size, complexity and risk profile of the bank or banking sector for which the authority is responsible.

1 The Core Principles for effective banking supervision (Basel Core Principles) are also a standard and form part of the Basel Framework but are applicable to all jurisdictions and all banks.

This module describes expectations to combat money laundering and terrorist financing.

This module describes expectations and practices relating to capital adequacy.

This module describes expectations for corporate governance.

This module describes expectations for credit risk and counterparty credit risk management.

This module describes expectations for external audit and sets out references related to public disclosure.

This module describes expectations for banks’ internal audit and compliance functions.

This module describes expectations for liquidity risk management.

This module sets out references related to market risk and interest rate risk.

This module describes expectations for the management of operational risk and operational resilience.

This module describes expectations for the management of problem assets and expected credit losses.

This module describes the application of proportionality in prudential regulation and supervision.

This module describes expectations for risk management.

This module describes the nature and application of prudential supervision.

You might also be interested in