GuideJuly 28, 20268 min read

IT Risk Management under OJK: What Banks Must Demonstrate

OJK expects Indonesian banks to run information technology risk management as a governed, evidenced discipline. What the regulator looks for, where the human factor sits, and how to evidence the awareness component.

IT risk management as a supervised discipline

OJK treats information technology risk as a category of operational risk that commercial banks must manage through a defined governance structure, not as a technical matter delegated entirely to the IT function. POJK 11/2022 on the implementation of information technology by commercial banks sets the framework, and supervisory expectations run through board accountability, risk identification, control design, and reporting.

The practical implication is that the artefacts matter as much as the controls. A bank can operate strong technical security and still perform poorly in supervision if it cannot show a documented risk assessment, a clear owner for each risk, and evidence that the board received and acted on the information.

This guide covers what that looks like operationally, with particular attention to the human-factor component, which is consistently the hardest part to evidence well.

Governance and board accountability

The direction of travel in Indonesian financial regulation is that technology risk is a board-level responsibility. Boards are expected to understand the bank's technology risk profile, approve the risk appetite, and receive reporting frequent and specific enough to act on.

That standard is not met by an annual slide showing training completion percentages. Boards need to see where risk is concentrated, whether it is improving, and what is being done about the areas that are not. Reporting that only shows activity, rather than outcome, tends to attract supervisory questions rather than settle them.

The most useful board reporting on human risk answers three questions: which parts of the organization are most susceptible, is susceptibility trending down, and what happens to the people who repeatedly fail.

The risk cycle applied to technology

The expected cycle is conventional: identify risks, measure or assess them, monitor and control them, and report. Applied to technology this means maintaining an inventory of systems and their criticality, assessing threats against them, implementing proportionate controls, and monitoring whether those controls remain effective.

Two areas commonly draw supervisory attention. Third-party and outsourcing risk, because banks increasingly depend on external providers whose controls they do not directly operate. And change management, because a significant share of availability incidents originate in changes the bank made to its own systems.

Incident management ties the cycle together. A bank that cannot reconstruct what happened during an incident, and how quickly it was detected and escalated, will struggle to demonstrate that its monitoring controls work.

Where the human factor sits

Phishing and social engineering sit inside IT risk, not beside it. The dominant route into a bank's systems is a person: an employee who enters credentials into a convincing page, approves a fraudulent payment instruction, or authorises an MFA prompt they did not initiate.

This means workforce susceptibility is a measurable technology risk with an owner, a current value and a target, rather than a training administration statistic. Treating it that way changes what gets reported and what gets funded.

It also connects to the bank's own customers. Indonesian banks face sustained impersonation of their brand through fake customer service accounts, fraudulent WhatsApp messages and malicious APK files. Staff awareness and customer-facing fraud response are two sides of the same risk.

Evidencing the awareness component

Awareness is where documentation is usually weakest, because most organizations can only produce completion records. Completion proves attendance, not capability. Supervisors and internal audit increasingly ask the harder question: has behaviour changed.

Behavioural evidence answers it. Phishing simulation results, trended over multiple campaigns, broken down by department and role, with repeat-clicker identification and a defined remediation path, demonstrate that the control is operating and improving. That is a materially stronger position than a training register.

Claro is built for this: bilingual phishing simulation across email, WhatsApp, SMS and voice, per-user risk scoring, department and role-level analytics, automatic remediation training for those who fail, and exportable reporting mapped to OJK expectations alongside ISO 27001 and UU PDP. On-premise deployment is available where data residency requires it.

Key takeaways

  • OJK treats IT risk as governed operational risk under POJK 11/2022, with board accountability rather than pure IT ownership.
  • Evidence quality matters as much as control strength: documented assessments, named risk owners, and board reporting that shows outcomes.
  • Third-party risk and change management are the two areas that most commonly draw supervisory attention.
  • Workforce susceptibility to phishing is a measurable technology risk, not a training statistic.
  • Behavioural evidence, trended over time and broken down by department, is materially stronger than training completion records.

Frequently asked questions

  • POJK 11/2022 on the implementation of information technology by commercial banks sets the primary framework, supported by OJK circular guidance. Technology risk is treated as a category of operational risk with board-level accountability.

Build a program that sticks

Claro helps you run simulation, training, and reporting in one place.

Request a demo