Frameworks
EU banking governance with EBA ICT
Complex EBA requirements across your entire institution without clear governance leave you exposed to regulatory findings.
Tidal brings clarity and control. Implement ICT governance, manage security risks systematically, and exceed EBA expectations across all required areas.

EBA ICT Guidelines in depth
The EBA ICT Guidelines are established by the European Banking Authority and describe how financial institutions should manage ICT risks within the European supervisory context. The guidelines focus on governance, risk management, and control over ICT and information security.
In practice, EBA ICT Guidelines are often seen as abstract European regulations. This leads to interpretation differences and fragmented implementation within organisations, especially when national and European frameworks overlap.
By applying EBA ICT Guidelines as a coherent framework, clarity emerges. ICT risks, responsibilities, and decision-making are uniformly organised and align with European supervisory expectations.
How Tidal helps you get certified
Hit the ground running
Start with our pre-built controls, policies, and risk assessment templates.
Our platform guides you through establishing your ISMS scope, identifying assets, and implementing right-sized controls that match your business needs.


Why Tidal Control
We understand your challenges because we've been there. Our team of GRC experts and security professionals built Tidal to solve the real problems compliance teams face every day.
Made in Europe
Built and hosted in Europe. Your compliance data stays in the EU for full control and peace of mind.
Continuous automation
Automated evidence collection from cloud providers and development tools working 24/7 for you.
Real security
Build secure systems that protect your business and satisfy auditors, not just check compliance boxes.
Go beyond EBA ICT Guidelines
Explore complementary frameworks that strengthen your EU banking institution's ICT governance.
DORA
Meeting digital resilience requirements? DORA took over the general ICT risk management that these guidelines used to carry, and adds operational resilience testing and incident reporting on top.
ISO 27001
Building information security? ISO 27001 provides foundational security controls that complement EBA's ICT governance requirements.
NIST CSF
Aligning with international security standards? NIST Cybersecurity Framework provides complementary guidance for ICT risk management alongside EBA requirements.
RVIT
Securing telecommunications infrastructure? RVIT protects the telecom systems your banking operations depend on.
Integrate with your existing tools
Learn more about EBA ICT Guidelines
Learn more about implementing and managing EBA ICT Guidelines

Testimonials
What our customers say
With a single click, one Tidal test checks dozens of disks for encryption. Doing that manually would take a lot of time.
Frequently asked questions
The EBA Guidelines on ICT and security risk management (EBA/GL/2019/04) set requirements for credit institutions, investment firms, and payment service providers in the EU. Their scope was narrowed by EBA/GL/2025/02, which applies from 20 May 2025. Sections 3.1 to 3.7 were deleted outright, so general ICT risk management now sits in DORA, and the only part still standing is Guideline 3.8 on relationship management with payment service users for payment services. If you're a financial entity in DORA scope, start there and treat what is left of these guidelines as a PSD2 addition covering how you deal with payment service users.
Our platform provides pre-built controls for ICT governance, security, resilience and third-party risk management, and helps maintain evidence of compliance. Since the 2025 amendment those obligations come from DORA for financial entities in its scope, so the controls are mapped to DORA with the surviving EBA guideline on payment service user relationships alongside them.
Yes, though the requirement has moved. Business continuity was Section 3.7 of EBA/GL/2019/04 and was deleted in 2025; for financial entities the obligation now sits in DORA. Our platform includes tools for continuity and disaster recovery, testing, and the documentation either regime expects.
Cloud outsourcing was never part of EBA/GL/2019/04. It sits in the separate EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02), and for financial entities in DORA scope the third-party rules now come from DORA. Our platform guides you through risk assessment, contractual clauses and oversight arrangements for cloud providers under whichever of those applies to you.
Yes, our platform organises your ICT risk documentation, maintains evidence of control effectiveness, and provides audit-ready reports. You'll have clear visibility of your compliance status and can demonstrate adherence to EBA requirements.
Our platform continuously monitors your ICT controls, schedules required reviews and assessments, and maintains evidence of continued compliance. You'll receive alerts for upcoming requirements and any gaps, helping you maintain regulatory compliance efficiently.


























