Banking Act (Cap. 371)
Banking Act (Cap. 371), article 19C
19C. (1) Without prejudice to the application of Chapter II of
the DORA Regulation, credit institutions shall establish a fram ework
with appropriate mitigation measures and control mechanisms to
manage the operational and security risks, relating to the payment
services they provide. As part of that framework, credit instit utions
shall establish and maintain effective incident management
procedures, including for the detection and classification of m ajor
operational and security incidents.
(2) Credit institutions shall provide to the Central Bank on an
annual basis or at shorter interv als, as may be determined by t he
competent authority in co-operation with the Central Bank, an u pdated
and comprehensive assessment of t he operational and security ri sks
relating to the payment services they provide and on the adequa cy of
the mitigation measures and control mechanisms implemented in
response to those risks.
(3) The competent authority shall co-operate with the Central
Bank in the assessment and proce ssing of documents referred to in
sub-article (2).
(4) The competent authority may issue, amend or revoke
Banking Rules as may be required in order to better implement t he
provisions of this article.
Incident reporting.
Added by:
XXVI.2019.9.
Amended by:
XI.2025.33.
Text read from the consolidated PDF published by Legislation Malta. Tables, figures and marginal notes may be incomplete or out of place: the official PDF is authoritative. General information, not legal, tax or accounting advice.