Evidence OJK POJK 11/2022 awareness and cyber-resilience expectations
OJK expects banks to govern information security, manage human risk, and test their posture, including the human layer. Claro helps you run that testing and evidence it for examiners.
- Regulator
- Otoritas Jasa Keuangan (OJK)
- Applies to
- Commercial banks and financial institutions in Indonesia
Overview
POJK No. 11/POJK.03/2022 governs the implementation of information technology by commercial banks in Indonesia. Issued by Otoritas Jasa Keuangan, the country's financial services authority, it sets out expectations for IT governance, risk management, information security, and cyber resilience across the banking sector. The regulation reflects OJK's supervisory view that technology risk is inseparable from banking risk and must be managed with board-level accountability. It applies to commercial banks and shapes how they organize, secure, and oversee their technology environment.
A central theme of the regulation is that banks must actively manage and test their security posture rather than treat security as a static checklist. This includes the human layer, since people remain one of the most exploited paths into a bank. Banks are expected to govern information security, identify and manage the risks introduced by their workforce, and maintain the resilience needed to withstand and recover from cyber incidents. Awareness and phishing resilience are practical, examinable parts of that posture. Testing is expected to be periodic and realistic, so that a bank can show how its controls perform against the kinds of attacks it actually faces.
Because OJK supervises banks through examination and reporting, evidence matters as much as intent. Banks should be able to show what security controls exist, how they are tested, what the results were, and how gaps are remediated over time. For the human layer this means demonstrable awareness programs, records of simulated attacks and how staff responded, and a clear picture of where human risk is concentrated. Regulators look for a living program, not a one-off training event.
This page provides general information and is not legal advice; banks should confirm how the regulation applies to their specific circumstances with qualified counsel and their OJK supervisory contacts. Claro supports the human-layer expectations of the regulation, including awareness, phishing simulation, testing, and the evidence to back it up, but Claro alone does not make a bank compliant. Full compliance depends on the wider governance, technical, and organizational program the regulation calls for across the institution.
What the rule expects
IT governance with board accountability
Banks are expected to govern information technology with clear roles and board-level oversight. Security awareness and human-risk management form part of that governance picture and should be visible to leadership.
Information security management
The regulation expects banks to manage information security systematically, not ad hoc. This includes protecting against the social-engineering attacks that target employees as the entry point.
Active testing of security posture
Banks must actively test their security, including the human layer, rather than assume controls work. Regular phishing simulation is a direct, evidenced way to test how staff respond to realistic attacks.
Human-risk management
People introduce risk, and the regulation expects banks to identify and manage it. Understanding which users and departments are most exposed lets a bank target its controls where they matter most.
Cyber resilience and recovery
Banks must be able to withstand and recover from cyber incidents. A workforce that detects and reports attacks quickly strengthens resilience by shortening the time an intrusion goes unnoticed.
Ongoing awareness programs
Awareness is expected to be a continuing program, not a single annual event. Repeated, role-relevant training keeps security behavior current as attacker techniques evolve.
Examinable evidence and reporting
Because OJK supervises through examination, banks should keep evidence of controls, tests, results, and remediation. Structured records of awareness and simulation support both internal governance and regulatory review.
How Claro helps you comply
Phishing simulation that tests the human layer
Claro runs realistic, bilingual phishing campaigns with scheduling, throttling, and per-recipient tracking. This gives banks a direct, repeatable way to test how staff respond and to evidence that testing for examiners.
Compliance module with control mapping
Claro's compliance module includes control-coverage mapping with OJK framework logic alongside ISO 27001 and NIST CSF. This helps banks connect awareness and testing activity to the controls examiners expect to see. The mapping makes it easier to show, control by control, that the human layer is being actively managed and not overlooked.
Human-risk scoring by user and department
Claro scores risk at the user and department level so banks can see where human risk concentrates. Leaders can direct awareness and training to the highest-risk groups, which supports risk-based management.
Just-in-time awareness and training
When a user fails a simulation, Claro delivers an instant awareness page and auto-enrolls them in role-relevant micro-modules. This turns each failure into targeted remediation that measurably reduces repeat clicks.
Phish-report button strengthens resilience
The Claro reporting button for Outlook and Gmail turns employees into human sensors who flag suspicious mail in one click. Faster detection shortens incident dwell time and supports cyber resilience.
Evidence packages and regulator-ready reports
Claro generates evidence packages and Claro-style PDF reports for boards and regulators, backed by detailed audit logs. This gives banks the examinable record OJK supervision depends on. Scheduled report delivery means the evidence is refreshed on a regular cadence, so a bank is not assembling it from scratch when an examination begins.
Frequently asked questions
The regulation does not prescribe a single technique, but it expects banks to actively test their security posture including the human layer. Phishing simulation is a widely accepted, evidenced way to test employee response and demonstrate that testing to examiners.
This page is provided for general information only and is not legal advice. Regulatory requirements change and apply differently depending on your organization. Confirm your specific obligations with qualified counsel or your regulator.
Related pages
BSSN Guidance
Indonesia's national cyber agency guidance. Strengthen the human layer it emphasizes.
Learn morePP 71/2019 (PSTE)
Indonesia's core rule for operating electronic systems: registration, security, and personal data protection obligations for PSE.
Learn moreBank Indonesia (PBI 2/2024)
Bank Indonesia's cyber-resilience rule requiring PJP and PIP to run risk management, DRP testing, and annual cyber-resilience simulations.
Learn moreBuild defensible security awareness evidence
Claro gives compliance and security teams the reporting auditors expect, in English and Bahasa Indonesia.
Request a demo