What POJK 11/2022 Actually Requires of Financial Institutions
POJK No. 11/POJK.03/2022 governs how commercial banks in Indonesia implement information technology, setting requirements across IT governance, risk management, cybersecurity, and resilience testing, including expectations around security awareness and human-layer controls, not just technical safeguards.
For boards, this means cyber resilience isn't just an IT budget line. It requires governance oversight, documented risk assessments, and evidence that controls actually work in practice, not just on paper.
One recurring theme in this regulatory direction, also echoed in BSSN guidance and ISO 27001 controls, is that people are part of the attack surface, and institutions are expected to manage that risk deliberately, through training, testing, and monitoring, rather than assuming policy documents alone are sufficient.
POJK 11/2022 in summary: the obligations that matter most
In summary, POJK 11/2022 governs the implementation of information technology by commercial banks. For security and awareness leaders, four obligations carry the most weight: governance of technology risk with clear board accountability, risk management applied across the technology estate, management of third-party and outsourcing arrangements, and incident handling with reporting to the regulator.
Each of those requires evidence rather than assertion. A documented assessment, a named owner, a control that demonstrably operates, and reporting that reached the people accountable for it.
Phishing resilience sits inside the risk management obligation. It is not named as a separate requirement, but workforce susceptibility is one of the clearest technology risks a bank carries, and it is one of the few that can be measured directly.
Governance and Board Oversight Under POJK 11/2022
A defining feature of POJK 11/2022 is where it places accountability. The regulation strengthens the role of directors and commissioners in IT governance, meaning cyber resilience is not something a bank can fully delegate to a technical team, it is a board-level responsibility with named oversight.
In practice this raises the standard of evidence leadership needs. Directors are expected to understand the bank's IT risk posture, ensure risk management processes actually function, and confirm that controls are tested rather than assumed. Human-layer risk, how susceptible staff are to social engineering, sits squarely inside that oversight duty.
For a security leader, this changes how results should be communicated. Board members do not need raw campaign logs, they need a clear, trended view of how employee resilience is changing and where the residual risk concentrates, presented in a way that lets them exercise the oversight the regulation expects of them.
Why Phishing Is the Human Risk Regulators Care About
Phishing remains the most common way attackers gain an initial foothold in financial institutions, because it targets people rather than infrastructure. A single successful email or WhatsApp message can lead to credential theft, fraud, or a wider breach.
For a regulator focused on systemic financial stability, an institution that cannot demonstrate it actively measures and reduces employee susceptibility to social engineering is harder to trust with resilience claims, even if its technical controls are strong.
This is why board-level conversations increasingly ask not 'do we have security awareness training' but 'can we show measurable improvement in how employees respond to simulated attacks over time', a much higher bar that requires ongoing simulation, not a once-a-year slideshow.
Crucially, this is one of the few risk areas an institution can measure directly rather than estimate. Unlike many operational risks, employee susceptibility can be observed through controlled simulation, quantified, and tracked over time, which is exactly why regulators and boards increasingly treat it as a metric to be managed rather than a soft, unmeasurable concern.
Building a Defensible Phishing Resilience Program
A credible program combines three elements: realistic phishing simulations across email and, increasingly, other channels; targeted micro-learning triggered the moment someone clicks or reports; and a risk score that tracks behavior change per employee, department, and branch over time.
For Indonesian banks, simulations should reflect real local lures, courier notifications, HR announcements, government or tax-themed emails, WhatsApp messages, rather than generic templates, because relevance drives genuine behavior change rather than rote recognition of a foreign-looking email.
Consistency matters more than intensity: a steady cadence of simulations and short, focused training modules, tracked over quarters, produces a defensible trend line, whereas a single large campaign right before an audit tends to look exactly like what it is.
It also helps to define success in advance. Agreeing on target click and reporting rates, and on how quickly a high-risk individual should see follow-up training, gives the program clear objectives that leadership can hold it to, and turns a vague ambition to 'improve awareness' into something concrete enough to measure and report.
Testing Beyond Email: Vishing and WhatsApp Channels
Attackers reaching bank employees in Indonesia do not limit themselves to email. Voice calls impersonating IT support or a senior executive, and WhatsApp messages posing as colleagues, vendors, or customers, are part of the real threat picture, so a resilience program that tests only email measures an incomplete slice of exposure.
Adding controlled vishing and WhatsApp simulations to the program gives a fuller, more honest read on how staff respond under pressure across the channels they actually use. It also reflects the spirit of managing the human attack surface deliberately, rather than defending one channel while leaving the others untested.
Multi-channel testing does need care, disclosure, consent where appropriate, and the same no-blame framing as email simulations, so that employees experience it as realistic practice rather than entrapment. Handled well, it produces both better behavior change and a broader, more defensible evidence base.
There is a practical benefit for banks specifically: fraud attempts against customers frequently begin on these same channels, so employees who learn to spot a vishing or WhatsApp lure in a simulation are better equipped to recognize the real thing when it targets the institution or its clients. The training investment defends the bank on more than one front at once.
Turning Program Data Into Audit-Ready Evidence
When examiners or internal audit ask for evidence of cyber resilience controls, the strongest answer is a report that ties together campaign history, click and report rates over time, training completion, and risk scores by department, mapped to the relevant regulatory control areas.
This is where a platform-generated compliance report earns its keep: rather than assembling spreadsheets under deadline pressure, security teams can produce a structured, dated record showing the program has been running continuously and improving results.
Claro's compliance reporting is built to support this kind of evidence gathering for OJK, ISO 27001, and UU PDP-related expectations. It doesn't replace legal or regulatory advice, but it gives security and compliance teams a clear, defensible record to bring into board and examiner conversations.
Timing matters here too. Evidence assembled hastily in the weeks before an examination tends to look thin and reactive, while a record that has accumulated quarter after quarter reads as proof of a living program. Generating that record continuously, rather than reconstructing it under pressure, is what turns a compliance obligation into a genuine operational strength.
How POJK 11/2022 Connects to ISO 27001 and UU PDP
POJK 11/2022 does not exist in a vacuum. Its expectations around risk management, awareness, and control testing overlap heavily with ISO 27001, whose controls cover information security awareness and human resource security, and which many Indonesian banks already reference or certify against.
There is also a clear link to UU No. 27 Tahun 2022, the Personal Data Protection Law. Because phishing is a leading route to exposing customer data, reducing employee susceptibility supports the data-protection obligations under UU PDP at the same time as the resilience expectations under POJK 11/2022.
The efficiency this creates is worth planning around. A single, well-documented human risk program can generate evidence that speaks to OJK supervision, ISO 27001 certification, and UU PDP duties together, so security and compliance teams should design their reporting to map cleanly across all three rather than building separate efforts for each.
Key takeaways
- POJK 11/2022 expects banks to manage cyber resilience as a governed program, including the human layer, not just technical controls.
- Board oversight is explicit, so report employee resilience as clear, trended evidence, and design it to map across ISO 27001 and UU PDP too.
- Phishing susceptibility is a measurable risk regulators expect institutions to track and reduce over time.
- Localized, realistic simulations, including WhatsApp and vishing channels, produce more defensible behavior change than generic templates.
- A consistent, ongoing simulation and training cadence matters more than a single pre-audit campaign.
- Structured compliance reporting that ties campaign data to risk scores gives boards and examiners a clear record of program effectiveness.