Framework

Bank of Ghana CISD 2026, Assessed And Evidenced

The Bank of Ghana Cyber and Information Security Directive 2026 runs to 129 controls across 21 Parts, applied by institution tier. Auditara scores every applicable control, builds the remediation plan, and produces the gap report the regulator expects.

129
Controls across 21 Parts
5 tiers
Proportionality applied at intake
22
Activities across 4 phases

Who Needs It

Banks and Specialised Deposit Takers

The Directive applies in full at the upper tiers, where the widest control set is expected.

Savings and Loans, Finance Houses and Microfinance

Requirements scale to your tier, so the assessment covers what your licence category attracts.

Rural and Community Banks

Lower tiers carry a proportionate subset, and the workspace hides what does not apply to you.

Payment Service Providers and Electronic Money Issuers

Payment and e-money institutions fall within scope, with tier driven expectations on controls and reporting.

Why This Matters to Regulated Institutions

The Directive Is Not Optional

Institutions regulated by the Bank of Ghana are expected to assess themselves against the Directive and evidence the result. The submission is the point, not a slide deck.

Proportionality Is Easy to Get Wrong

Applying every control regardless of tier wastes months. Applying too few leaves gaps the regulator will find. Auditara scopes to your tier from the start.

Evidence Has to Be Traceable

Each control needs a status, a rationale, an owner, and a date. Auditara records all four and keeps the trail intact for the RFI that follows.

What Is Inside the CISD 2026 Programme

The full Directive, scoped to your tier, with the artefacts the regulator asks for.

All 129 Controls Across 21 Parts

Scored control by control with plain English guidance, tier proportionality applied so you assess what actually applies to your institution.

22 Activities Across 4 Phases

A phased programme with a deliverable per activity and a gate criterion before the phase can close, so nothing is signed off without evidence.

The Gap Report

A branded gap report with status per control, rationale, and a prioritised remediation plan carrying owners and target dates, exported as Word or PDF.

Audit Ready Evidence

Evidence linked per activity, approvals recorded with sign-off, and a read only room you can open for supervisory review.

How Auditara Runs It

Step 1

Book the Call

Fifteen minutes with a PECB certified Lead Auditor and Lead Implementer. We confirm your tier, your scope, and your submission timeline, then your workspace opens.

Step 2

Answer the Intake

A guided intake captures your institution's profile and tier in plain English, and sets the assessment up around it.

Step 3

Assess and Remediate

Score every applicable control, then give each gap an owner and a target date. AI drafts remediation wording from your notes, which you confirm.

Step 4

Produce the Report

Generate the gap report and remediation plan, approve your document set, and keep the evidence trail ready for supervisory questions.

Two Ways to Run It

At Your Own Pace

Readiness Workspace: the guided workspace set up around your institution's tier, opened after your onboarding call.

With Us Delivering

Guided Implementation: we run the programme with you to audit readiness, with a written guarantee. Scope is agreed on your onboarding call.

Every route starts with a call with a certified ISO 27001 and ISO 42001 Lead Implementer.

Book A Call

Questions

What is the Bank of Ghana CISD 2026?

The Cyber and Information Security Directive 2026 sets the cyber and information security requirements for institutions regulated by the Bank of Ghana. It runs to 129 controls across 21 Parts, applied proportionately by institution tier.

How does tier proportionality work?

The Directive applies across five tiers. Auditara sets your programme up around your institution's tier at intake, so the assessment covers what applies to you rather than everything at once.

What does the Bank of Ghana actually want to see?

A documented, evidenced self assessment against the Directive. The gap report is the artefact they expect, and Auditara generates it from your scored assessment with owners and target dates attached.

How long does it take?

Institutions typically work through the assessment in weeks rather than months, then work the remediation plan. Guided Implementation compresses that with delivery support to a written guarantee.

Where is our data held?

All data is stored in the EU West region and is GDPR compliant. Evidence can stay in the systems you already use, linked rather than copied.

Ready to Get Certified?

Readiness Workspace is free to start. Guided Implementation adds delivery to audit readiness, agreed with you on the call.

Tier-Aware AssessmentDelivered by a PECB Certified Lead Auditor and Lead ImplementerThe Report BoG Expects

See all frameworks