OJK Information-Security Risk Management: Evidence Checklist
Start with scope, not a compliance label
This article concerns POJK No. 11/POJK.03/2022 on Information-Technology Operation by Commercial Banks, published by OJK in 2022. Its OJK regulation page identifies the instrument for commercial banks. It is not a universal information-security rule for every financial-services business, and this article does not decide whether it applies to any institution, group entity, outsourced service, or product.
That distinction matters. Source requirement means wording and applicability established by the authoritative instrument. Implementation interpretation means a practical way to organize assessment evidence. A test report is implementation evidence; it is not a regulator decision, legal advice, proof of compliance, or a certification.
Before using this checklist, compliance owner, legal counsel, and accountable technology/risk owner should record: legal entity; licence or business status; exact instrument and version; relevant provisions; effective-date status; system boundary; and any related OJK requirements. Escalate ambiguity rather than filling it with a broad “OJK compliant” statement.
Evidence register for a tested service
Use one row per assertion. Keep source copies and assessment artifacts separate.
| Evidence item | Owner | Pass criterion | Fail or remediation record |
|---|---|---|---|
| Applicability memo | compliance/legal | named reviewer signs dated scope decision | status unconfirmed; no regulatory mapping used |
| Asset and data map | system owner | production interfaces, privileged paths, and suppliers named | missing component gets owner and due date |
| Risk record | risk owner | risk, treatment, approval, and review date traceable | open risk or expired acceptance escalated |
| Test authorization | accountable executive | target, dates, methods, stop contact, and exclusions signed | testing does not start |
| Test evidence | assessor | timestamp, target version, method, result, and integrity hash retained | result marked insufficient, not passed |
| Remediation and retest | engineering owner | fixed version and repeat result linked to finding | finding remains open or accepted by named owner |
A completed example: API gateway / release 2026.08.4 / owner Platform. Scope memo says the bank entity and gateway are in the approved assessment boundary. The evidence folder holds signed authorization, authenticated test notes, sanitized request samples, report hash, ticket SEC-184, merge reference, and retest dated 2026-08-08. The pass condition is not “no vulnerabilities.” It is that stated test objectives were executed within authorization, evidence is reproducible, material findings have a recorded disposition, and no critical unremediated finding is incorrectly shown as closed.
Sampling and exceptions
Sample control operation, not policy existence. For access review, request period, population, reviewer, decisions, and removal proof. For change management, request approved change, deployment identifier, security test result, rollback decision, and post-change review. For incident readiness, request the current playbook, exercise date, participant list, lessons, and tracked actions. Redact personal data and credentials before sharing.
An exception needs asset or control, business reason, risk statement, compensating control, approving authority, start date, expiry, and review trigger. “Temporary” without expiry fails this checklist. An assessment finding needs severity rationale, affected version, reproduction conditions, owner, target date, and retest rule. Acceptance of residual risk belongs to authorized customer governance, not assessor staff.
Review boundary
Publication date, amendment status, and applicability must be rechecked against OJK source before relying on this article. Operator, legal, and—where a formal assurance process is involved—relevant accreditation or certification reviewers must decide their own evidence standard. Evidence can support internal risk decisions; it cannot guarantee OJK acceptance, legal compliance, audit outcome, or certification.
Evidence handover
At handover, give governance reviewers an index rather than an undifferentiated archive: source reference; scope decision; authorization; test plan; evidence hashes; finding register; exception register; remediation status; retest result; and retention or destruction receipt. Each entry should name custodian and access restriction. This allows a reviewer to see missing evidence without granting broad access to sensitive test material.
Review status is ready only when every required entry is present, attributable, and within agreed review period. It is blocked when applicability, authorization, or evidence integrity is unresolved; conditional when a named risk owner has accepted a bounded exception. Those workflow labels are internal evidence states, not regulatory conclusions.
Sources
Worked evidence decision
For a payment API, freeze one release identifier before testing. Map its internet endpoint, administrator path, change ticket, access-review sample, and vendor dependency to evidence index entries. Expected behavior: reviewer traces each conclusion to dated authorization and artifact without treating coverage as regulatory approval. Edge case: gateway hotfix replaces tested build after collection; record version delta and reopen affected conclusions. Closure test: independently select one finding and one control sample, then reproduce path from scope memo through remediation status.
Worked closure check
For payment-API release evidence, retain legal-entity scope memo, gateway build, OJK source reference date, authorization, API owner, and signed test outcome. It is an internal risk-management record, not confirmation of POJK applicability, regulator acceptance, certification, or legal compliance. A hotfix, vendor route, or banking-entity change requires revised boundary review. Independent governance reviewer traces one security objective through source artifact, finding, and retest or risk acceptance, keeping incomplete regulatory mapping marked blocked.