Frameworks

EU banking governance with EBA ICT

Complex EBA requirements across your entire institution without clear governance leave you exposed to regulatory findings.

Tidal brings clarity and control. Implement ICT governance, manage security risks systematically, and exceed EBA expectations across all required areas.

Product screenshot

EBA ICT Guidelines in depth

The EBA ICT Guidelines are established by the European Banking Authority and describe how financial institutions should manage ICT risks within the European supervisory context. The guidelines focus on governance, risk management, and control over ICT and information security.

In practice, EBA ICT Guidelines are often seen as abstract European regulations. This leads to interpretation differences and fragmented implementation within organisations, especially when national and European frameworks overlap.

By applying EBA ICT Guidelines as a coherent framework, clarity emerges. ICT risks, responsibilities, and decision-making are uniformly organised and align with European supervisory expectations.

How Tidal helps you get certified

Why Tidal Control

We understand your challenges because we've been there. Our team of GRC experts and security professionals built Tidal to solve the real problems compliance teams face every day.

Made in Europe

Built and hosted in Europe. Your compliance data stays in the EU for full control and peace of mind.

Continuous automation

Automated evidence collection from cloud providers and development tools working 24/7 for you.

Real security

Build secure systems that protect your business and satisfy auditors, not just check compliance boxes.

Integrate with your existing tools

Testimonials

What our customers say

With a single click, one Tidal test checks dozens of disks for encryption. Doing that manually would take a lot of time.

Profile picture of Chiel Bos
Chiel Bos
COO·CBYTE
CBYTE logo

Frequently asked questions

The EBA Guidelines on ICT and security risk management (EBA/GL/2019/04) set requirements for credit institutions, investment firms, and payment service providers in the EU. Their scope was narrowed by EBA/GL/2025/02, which applies from 20 May 2025. Sections 3.1 to 3.7 were deleted outright, so general ICT risk management now sits in DORA, and the only part still standing is Guideline 3.8 on relationship management with payment service users for payment services. If you're a financial entity in DORA scope, start there and treat what is left of these guidelines as a PSD2 addition covering how you deal with payment service users.

Our platform provides pre-built controls for ICT governance, security, resilience and third-party risk management, and helps maintain evidence of compliance. Since the 2025 amendment those obligations come from DORA for financial entities in its scope, so the controls are mapped to DORA with the surviving EBA guideline on payment service user relationships alongside them.

Yes, though the requirement has moved. Business continuity was Section 3.7 of EBA/GL/2019/04 and was deleted in 2025; for financial entities the obligation now sits in DORA. Our platform includes tools for continuity and disaster recovery, testing, and the documentation either regime expects.

Cloud outsourcing was never part of EBA/GL/2019/04. It sits in the separate EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02), and for financial entities in DORA scope the third-party rules now come from DORA. Our platform guides you through risk assessment, contractual clauses and oversight arrangements for cloud providers under whichever of those applies to you.

Yes, our platform organises your ICT risk documentation, maintains evidence of control effectiveness, and provides audit-ready reports. You'll have clear visibility of your compliance status and can demonstrate adherence to EBA requirements.

Our platform continuously monitors your ICT controls, schedules required reviews and assessments, and maintains evidence of continued compliance. You'll receive alerts for upcoming requirements and any gaps, helping you maintain regulatory compliance efficiently.