CyberTRIZPEDIA

Banking & Finance

239 regulations apply to this sector.

Written for this sector

3DS3D Secure is a payment authentication protocol for card-issuing banksAI ActAI in credit scoring and financial decisions is designated high-riskAML REG PACKAGEAML package primarily targets banks and financial institutions for money laundering controlsAML VENVenezuelan AML regulation targets financial institutions for sanctions complianceAMLAAMLA establishes the EU AML Authority primarily overseeing financial sectorAMLD66th AML Directive strengthens criminal liability for banks and financial firmsBancontact Scheme RulesBelgian card payment scheme rules directly govern banks and payment institutionsBank Recovery and Resolution Directive 2014/59/EUBRRD is written specifically for bank recovery and resolution frameworks.Basel IIIBasel III is written specifically for banks covering capital and liquidity requirementsBASEL3 VENVenezuelan implementation of Basel III capital standards for banksBCBS 239BCBS 239 is written exclusively for banks on risk data aggregation and reportingBE Card Payment Scheme OversightBelgian oversight of card payment schemes targeting banks and payment institutionsBE Payment OversightBelgian National Bank oversight of payment systems targets banks and payment institutionsBE PSLBelgian private securities law governs financial instruments and securities markets.BE UBO AMLUBO register and AML rules primarily target financial institutions.BE WhistleblowingFinancial institutions required to establish whistleblowing channels.Belgian AML LawBanks are primary obliged entities under Belgian AML law.Belgian Law 18/09/2017Belgian AML/CFT law of 18/09/2017 primarily targets financial sector.Berlin Group NextGen PSD2API standards for PSD2 open banking directly target banks and payment institutions.Book VII Payment ServicesBook VII of Belgian Code of Economic Law governs payment services providers.BSABank Secrecy Act primarily requires AML compliance from financial institutions.CBM BelgiumNational Bank of Belgium (CBM) oversight primarily covers financial institutions.CFTC Part 160CFTC Part 160 governs privacy notices for commodity trading customersCFTC System SafeguardsCFTC system safeguards apply to derivatives trading platforms and FCMsCIRCIAFinancial sector critical infrastructure covered by CIRCIA reportingCLS FX SettlementCLS FX Settlement governs foreign exchange settlement risk for banksCOSO 2013Internal control framework widely mandated in financial sector complianceCOSO ERMEnterprise risk management framework heavily used in financial servicesCRDCapital Requirements Directive written specifically for credit institutions and banksCRRCapital Requirements Regulation directly governs prudential rules for credit institutionsCRR III AT1CRR III governs capital requirements including AT1 instruments for banks and credit institutions.CRR/CRDCapital Requirements Regulation/Directive directly governs banks and credit institutions.CSCFSWIFT Customer Security Controls Framework applies to financial institutions using SWIFT.CSDR SDCentral Securities Depositories Regulation governs securities settlement and depositories.CTIF/CFIBelgian financial intelligence unit targets AML/CFT compliance in financial sector.DCAMDCAM data management maturity model is primarily adopted by financial institutions.DORABanks and investment firms explicitly named as in-scope entitiesEAABanking services and consumer-facing digital tools explicitly in scopeEBA GL Loan Orig MonGuidelines specifically address credit institutions' loan origination standardsEBA ICT RiskEBA ICT risk guidelines target banks and investment firms directlyEBA Internal GovernanceInternal governance guidelines apply directly to credit institutionsEBA Major Incident Reporting PSD2Payment service providers under PSD2 must report major ICT incidentsEBA OutsourcingEBA outsourcing guidelines apply directly to credit and financial institutionsEBA PFRPayment and fee reporting requirements apply to payment service providersEBA Resolution ReportingResolution reporting obligations apply directly to banks and credit institutionsEBA SCA RTSEBA strong customer authentication standards target payment service providers and banks.ECB T2 RulesECB TARGET2 rules govern euro large-value payment settlement for banks.EIDAS2Banks must accept EU digital identity wallets for customer onboarding.EMDElectronic Money Directive regulates issuance and oversight of electronic money.EMD2EMD2 revised rules for electronic money institutions and e-money issuance.EMVEMV is the global standard for chip-based payment card transactions.EMV ChipEMV chip standards govern payment card security for banks and card issuers.EPC SCT RulebookEPC SEPA Credit Transfer rulebook governs payment service providers and banks.EPC SDD Core RulebookEPC SEPA Direct Debit rulebook governs payment service providers and banks.ESMA CloudESMA cloud guidance targets financial firms and investment service providers.ESRB Stablecoin 2025Financial stability risks from stablecoins directly concern banking and finance sector.EU Foreign Direct Investment Screening RegulationFDI in financial infrastructure is screened for national security implications.EU Instant Payments Regulation 2024Regulation mandates instant payment capability for banks and payment institutions.EU SanctionsBanks are primary enforcers of EU sanctions through transaction screening.EU Sanctions FrameworkFinancial institutions are primary implementers of EU sanctions frameworks.EU Sanctions RegimesBanks implement and comply with all EU sanctions regimes by jurisdiction.EU TaxonomyFinancial institutions must classify and disclose taxonomy-aligned investments.EU TFRTransfer of Funds Regulation requires PSPs to include payer/payee data on transfers.EUICS2Financial sector is a critical sector under EU cybersecurity incident frameworksEuropean Market Infrastructure RegulationEMIR directly regulates derivatives trading, clearing and reporting for financial firms.FAPIFinancial-grade API security profile written for open banking and financial APIsFAPI 2FAPI 2.0 is the next-generation financial-grade API security profile for open bankingFATF LATAMFATF LATAM regional AML/CFT standards primarily target financial institutionsFATF StandardsFATF standards are primarily written for banks and financial institutions on AML/CFTFDX APIFinancial Data Exchange API standard governs financial data sharing between institutionsFedNowFedNow is the Federal Reserve's instant payment service for banks and credit unionsFedNow Operating ProceduresOperating procedures governing participation in the FedNow instant payment serviceFedwireFedwire is the Federal Reserve's real-time gross settlement system for large-value transfersFedwire FundsFedwire Funds Service governs large-value interbank fund transfers via Federal ReserveFFIEC CATFFIEC Cybersecurity Assessment Tool specifically targets financial institutions' cyber riskFFIEC IT HandbookFFIEC IT Handbook provides IT examination guidance specifically for financial institutionsFIDAFinancial Data Access regulation governs open finance data sharing across EU financial sectorFINRA 3110FINRA Rule 3110 requires broker-dealers to supervise associated persons and activitiesFINRA 4370FINRA Rule 4370 requires broker-dealers to maintain business continuity plansFINRA 4511FINRA Rule 4511 requires broker-dealers to maintain accurate books and recordsFit & ProperFit and proper requirements are core to licensing and governance in financial services.GDPRFinancial institutions process large volumes of personal data subject to GDPR.GIIN IRIS PlusImpact investment funds and financial institutions use IRIS+ for impact reporting.GIIN-IRISImpact investors and development finance institutions use IRIS metrics for reporting.GLBAGLBA is written specifically for financial institutions' privacy and data security obligations.HKMA OR2HKMA operational resilience guidelines target Hong Kong-authorised banks directly.HKMA TM G1HKMA TM-G1 is a technology risk guideline directed at Hong Kong banks.HKMA TMG1HKMA TMG1 is a technology risk guideline directed at Hong Kong banks.IFRSIFRS governs financial reporting standards central to banking and finance.IFRS S1Financial institutions are key reporters of sustainability-related financial disclosures.IFRS S2Banks must disclose climate-related risks and opportunities under IFRS S2.IIA StandardsInternal audit functions in banks closely follow IIA Standards.Impact PrinciplesImpact investors and development finance institutions adopt these principles.IOSCO OP RESIOSCO operational resilience guidance targets securities and financial markets.IOSCO ORIOSCO operational risk principles apply to securities markets and intermediaries.IOSCO OutsourcingIOSCO outsourcing principles govern third-party risk in financial markets.ISAE 3402Financial sector relies on ISAE 3402 reports for outsourced service providersISO 20022ISO 20022 is the global messaging standard for financial payments and securitiesISO 22301Business continuity is a core regulatory requirement for financial institutions.ISO 22313Guidance standard directly supports BCM implementation required in finance.ISO 22317BIA is a regulatory expectation in financial sector resilience frameworks.ISO 22361Financial institutions require crisis leadership frameworks for systemic events.ISO 27001Financial regulators mandate or reference ISO 27001 for information security.ISO 27002Financial sector uses ISO 27002 controls to satisfy regulatory security requirements.ISO 8583ISO 8583 defines messaging standards for card-based financial transactions.MARMarket Abuse Regulation targets financial markets, trading, and investment firms.MAS TRMMAS TRM is written for Singapore-regulated financial institutions and banks.MAS TRM NoticeMAS TRM Notice is a binding notice directed at MAS-regulated financial institutions.MiFID IIMiFID II is written for investment firms, banks, and financial markets in the EU.MiFIRMiFIR regulates trading venues and transparency in EU financial markets.NACHANACHA governs ACH electronic payment network used by US financial institutions.NACHA RulesNACHA Rules govern ACH network participants including banks and credit unions.NASDAQ GOVNASDAQ governance rules apply to listed companies, primarily in financial marketsNBB Annual AccountsNational Bank of Belgium annual accounts rules apply to Belgian financial institutionsNBB CircularNBB circulars are prudential guidance issued to Belgian banks and credit institutionsNBB Circular PI 2019NBB 2019 payment institution circular regulates Belgian payment service providersNBB Payment InstitutionsNBB framework directly regulates authorisation and supervision of payment institutionsNBB Payment OversightNBB oversees payment systems operated by banks and financial institutions.NIS2Banking and financial market infrastructure explicitly in NIS2 scope.NY DFS 504NY DFS regulation targeting financial institutions' compliance programsNY DFS Part 500NY DFS cybersecurity regulation for licensed financial entitiesNYDFS TPSPNY DFS guidance on third-party service provider oversight for financialsNYSE LCMNYSE Listed Company Manual governs exchange-listed companies' complianceOFACBanks must screen transactions against OFAC sanctions listsOFAC SanctionsFinancial institutions are primary enforcer of OFAC sanctions complianceOFAC SDNBanks must screen all customers and transactions against SDN listOFAC VENVenezuela-specific OFAC sanctions program affecting financial transactionsOpen Banking StandardDirectly governs how banks share data via open APIsOpen Banking UKUK-specific open banking framework mandated for major banks by CMAPayconiq Scheme RulesMobile payment scheme rules directly govern financial institutions and payment providers.PAYCONIQ WERO TransitionTransition from Payconiq to Wero affects banks and payment service providers.PCI Contactless Payments on COTSContactless payment acceptance on COTS targets payment providers and acquirers.PCI DSSPCI DSS is written for entities handling payment card data in financial services.PCI DSS ExtensionExtension applies to payment card ecosystem participants in financial services.PCI MPOCMobile payments on COTS standard targets payment service providers and acquirers.PCI P2PEP2PE standard governs encryption of payment data for acquirers and payment providers.PCI PINPIN security standard applies to banks, acquirers and payment terminal operators.PFMIPFMI sets international standards for financial market infrastructures like CCPs and CSDs.PSD2PSD2 directly regulates payment services and account access for banks.PSD3PSD3 updates payment services regulation for banks and payment institutions.PSRPayment Systems Regulator oversees UK payment systems and participants.PSR SafeguardingSafeguarding rules protect customer funds held by payment institutions.Red Flags RuleUS rule requires financial institutions to detect identity theft warning signs.Reg ERegulation E governs electronic fund transfers at banks and credit unions.Reg S AMLAML regulation applies to banks and financial institutions' offshore transactions.Regulation CCRegulation CC governs fund availability and check processing at US depository institutions.Sanctions and Anti-Money Laundering Act 2018Financial institutions are primary subjects of sanctions and AML obligations.SEC Cyber DiscSEC-regulated public companies must disclose material cybersecurity incidents and risk management.SEC Cyber DisclosureSEC-regulated public companies must disclose material cybersecurity incidents and risk management.SEC REG SPSEC Regulation S-P governs privacy of customer financial information at broker-dealers and investment firms.SEC Regulation SCIDirectly targets securities exchanges, clearing agencies, and market infrastructure entities.SEC_REG_SSEC Regulation S governs offshore securities offerings exempt from US registration requirements.SEPASEPA governs euro payment standards and processes for banks and payment institutions.SFDRSFDR targets financial market participants including asset managers and investment firms.SOX ITGCSOX ITGC applies to IT controls at US-listed financial reporting entities including banks.STEP2 SEPA RulesSTEP2 is a pan-European payment processing system for SEPA transactionsSWIFT CSPSWIFT Customer Security Programme mandates cybersecurity controls for SWIFT usersSWIFT FINSWIFT FIN is the messaging standard for interbank financial transactions globallySYSC 15AFCA SYSC 15A imposes operational resilience requirements on regulated financial firmsTARGET2-SecuritiesT2S is a European securities settlement platform for central securities depositoriesTCFDTCFD disclosures are mandated for financial institutions on climate-related risksTIBER-EUTIBER-EU is an ECB threat intelligence-based ethical red teaming framework for financial entitiesTIPSTIPS (TARGET Instant Payment Settlement) is an ECB instant payment settlement serviceUK Bribery ActFinancial sector faces high bribery risk and active enforcement scrutiny.UN Convention against CorruptionAsset recovery and money laundering provisions directly implicate finance sector.UN Principles for Responsible InvestmentAsset managers and institutional investors are the primary signatories.

Also applies

CBE-KBOFinancial institutions must be registered in the KBO enterprise register.CCPA/CPRAFinancial firms handling CA consumer data must complyCEC RulebookFinancial participants in energy markets subject to CEC rulesCIS ControlsFinancial firms use CIS Controls to meet cybersecurity requirementsCOBIT 2019Widely adopted in financial services for IT governance complianceCOBIT 2019Widely adopted in financial services for IT governance complianceCOBIT 2019Widely adopted in financial services for IT governance complianceCOBIT Design GuideFinancial sector uses guide to tailor COBIT governance implementationsCSA CCMFinancial institutions use CCM to assess cloud vendor security.CSRDBanks and financial institutions must comply with CSRD sustainability disclosures.CSRD/ESRSFinancial sector entities report under sector-specific ESRS standards.DMBOK ExtensionFinancial sector applies extensions for regulatory data governanceDMBOK v2Financial institutions use DMBOK for data governance complianceEU TFR CryptoBanks interfacing with crypto transfers must comply with extended TFR rules.FAIRFinancial institutions use FAIR to quantify and manage cyber risk exposureFCPAFinancial institutions face FCPA exposure through cross-border transactions and clientsFTC AI GuidanceAI in financial services marketing and decisions addressed by FTC guidance.GHG ProtocolFinancial institutions use GHG Protocol to measure financed emissions portfolios.GRIFinancial institutions widely adopt GRI for ESG disclosure.India Information Technology Act, 2000Applies to digital banking, electronic payments and financial data protectionIOSCO Crypto/DeFiBanks engaging in crypto activities subject to IOSCO crypto guidance.ISAE 3000Used for assurance on sustainability and non-financial reports in financeISO 10002Financial services apply ISO 10002 for regulated complaints handlingISO 22318Financial institutions apply supply chain resilience to third-party dependencies.ISO 22989Finance sector AI deployments reference standard concepts for governance frameworks.ISO 23053Financial institutions apply ML frameworks for model risk governance.ISO 23894Financial institutions manage AI model risk using this guidance framework.ISO 25010Financial software systems are evaluated against quality characteristics for compliance.ISO 27004Financial institutions measure security controls effectiveness for regulatory reporting.ISO 27005Banks apply ISO 27005 for regulatory risk management complianceISO 27014Financial institutions apply it for board-level security governanceISO 27017/27018Banks using cloud services apply these standards for complianceISO 27031Financial sector uses it for operational resilience of ICT systemsISO 27032Financial sector applies it for online and cyber threat managementISO 27033Banks apply it to secure internal and external network architectureISO 27034Banks apply it to secure financial applications and softwareISO 27035Financial institutions use it to manage security incidents effectivelyISO 27036Banks manage third-party ICT supplier risk using this standardISO 27037Financial institutions apply it in fraud and cybercrime investigationsISO 27040Banks apply it to secure financial data in storage systemsISO 27050Financial institutions use it for regulatory investigations and litigationISO 27701Banks process large volumes of personal data requiring PIMS complianceISO 29100Financial institutions apply it to embed privacy in system designISO 29134Banks conduct PIAs for financial products involving personal dataISO 30414Financial institutions report human capital metrics to regulators and investorsISO 31000Financial sector uses ISO 31000 as basis for enterprise risk managementISO 31010Financial risk teams apply ISO 31010 techniques for risk evaluationISO 37000Financial institutions reference ISO 37000 for board-level governance frameworksISO 37001Financial institutions implement anti-bribery controls per ISO 37001ISO 37301Financial sector uses ISO 37301 to structure regulatory compliance programmesISO 38500Financial institutions apply IT governance principles for technology oversightISO 38507Financial institutions apply AI governance guidance for algorithmic systemsISO 42001Financial firms managing AI models adopt ISO 42001 frameworksMarkets in Crypto-Assets Regulation 2023/1114Financial institutions offering crypto services must comply with MiCA.MiCA StablecoinBanks and payment institutions issuing stablecoins subject to MiCA rules.MITRE ATT&CKFinancial sector SOC teams use ATT&CK for threat detection and response.NBB Governance Manual 2022Payment institutions operate within banking and finance regulatory ecosystem.NIST 800-53Financial institutions reference NIST 800-53 for compliance frameworks.NIST AI RMFFinancial sector increasingly uses AI for decisions requiring risk management.NIST CSFFinancial sector widely adopts NIST CSF for cybersecurity risk management.NIST Privacy FrameworkFinancial institutions managing customer data apply privacy risk frameworks.NIST RMFWidely adopted as security risk framework in financial sectorNY SHIELD ActFinancial firms holding NY resident data must complyOAuth 2.1Used in open banking APIs for secure authorization flowsOWASP SAMMFinancial sector adopts SAMM for secure software developmentSASBFinancial institutions use SASB standards for ESG reportingSingapore Cybersecurity Act 2018Financial sector critical infrastructure must comply with cybersecurity requirements.SOC2Financial sector third-party vendors commonly required to hold SOC 2 reports.Solvency IIFinancial conglomerates with insurance arms subject to Solvency II group requirements.SSAE 18Financial sector relies on SSAE 18 SOC reports for third-party vendor assurance.TNFDFinancial institutions disclose nature-related dependencies and risks under TNFDUNDP SDG ImpactImpact investors and development finance institutions apply SDG Impact standards.US State Privacy LawsFinancial institutions handling personal data face state privacy law obligations.

TRIZ for Banking & Finance

Worked contradictions and resolutions for this sector.