İçeriğe geç
AC

BRSA Cyber ​​Security Regulations and Banks

10 Nisan 2026 IT Law 1 dk okuma 76 görüntülenme

Banks are subject to special cyber security obligations within the scope of BRSA and Banking Law No. 5411.

Basic Regulations

  • Banks Information Systems Regulation
  • BRSA Board of Directors Decision: Penetration test obligation
  • ISO 27001 certification (mandatory)
  • Business Continuity Plan (BCP)
  • Disaster Plan (DRP)

Penetration Tests

  • Mandatory to be performed annually
  • Reported to BRSA by an independent third party

Data Breach Notification

The Bank reports the data breach immediately to BRSA, must notify its customers and the KVKK Authority (Art. 12/5).

Artificial Intelligence and Algorithm Governance

BRSA seeks AI systems such as credit scoring and fraud detection to be explainable and auditable.

Sanction

  • BRSA administrative fine
  • Withdrawal of operating permission (heavy in case of violations)
  • KVKK additional penalty

Banking and IT law lawyer recommended.

Telif bildirimi This content and all related Q&A texts are protected under Turkish Copyright Law No. 5846. Unauthorized copying, reproduction, publication, adaptation, bulk extraction, or commercial use is prohibited; legal and criminal remedies are reserved in case of infringement.

Hukuki destek arıyorsanız

Bu konuda profesyonel hukuki destek için Aycan Ceylan Avukatlık Bürosu olarak yanınızdayız.

Görüşme Planla