Insights

IT governance at Japanese financial institutions: the FSA's six perspectives and where COBIT and FISC fit

For a Japanese financial institution, the starting point for IT governance is the 2nd edition of Points and Practices for Dialogue on IT Governance of Financial Institutions, published by the Financial Services Agency (FSA) in June 2023. This article sets out its six perspectives, how frameworks such as COBIT 2019 relate to them, where the FISC Security Guidelines and the FSA's cybersecurity guidelines fit, and how to put it all into practice, working from the primary sources.

Published

Key points

  • The FSA defines IT governance as the mechanism by which management exercises leadership, aligns IT with business strategy and creates corporate value. Its Points and Practices for Dialogue on IT Governance of Financial Institutions, 2nd edition (June 2023), sets out how it approaches dialogue on the subject and what it looks at.
  • The 2nd edition has six perspectives: leadership by management; an IT strategy and a DX strategy aligned with business strategy; an IT organisation and a DX promotion organisation that deliver the IT strategy; optimised IT resources (resource management); an IT investment management process that creates corporate value; and properly managed IT risk.
  • The paper is not a checklist. The FSA states that it will not apply the paper's individual points mechanically or use them as a checklist in inspection or supervision, and that dialogue will take full account of each institution's size and characteristics.
  • For how to build the framework, institutions use general standards. The paper itself names, as examples of guidelines in use at financial institutions, FISC's Security Guidelines and System Audit Standards, ISACA's COBIT, and METI's System Management Standards and System Audit Standards.
  • The paper is aimed mainly at deposit-taking institutions and insurers, but other financial services firms may use it too. The supervisory guidelines for financial instruments business operators, which include securities firms, say that IT governance matters just as much for those firms and cite the 2nd edition for reference.

What IT governance means: the FSA's and METI's definitions

IT governance is the mechanism by which management aligns IT with business strategy to create corporate value. The Financial Services Agency (FSA) defines it, in Points and Practices for Dialogue on IT Governance of Financial Institutions (the dialogue paper), as “the mechanism by which management exercises leadership, aligns IT with business strategy and achieves the creation of corporate value”. Translations of Japanese-only documents are ours.

The FSA adds that IT governance covers not only internal control but also growth strategies that raise earnings: stable systems are the precondition, and the question is how IT serves the strategy. The paper names three concerns when IT governance fails:

  • IT management is impeded and system stability suffers.
  • System costs beyond the institution's means go unchecked, with no review of what systems the strategy needs, harming its future soundness.
  • Even with a strategy to compete with new players from outside finance, transforming the business, culture and talent strategy included, causes disruption.

IT governance versus IT management

The System Management Standards of the Ministry of Economy, Trade and Industry (METI), dated 26 April 2023, split the two by accountability: IT governance belongs to the board of directors or equivalent body, IT management to executive management such as the CEO and CIO. They define IT governance as the board's activities, guided by stakeholders' needs, to set the IT strategy and policies for using IT systems to raise the organisation's value and trust and to see them through: responding to stakeholders and evaluating, directing and monitoring IT management.

The FSA notes that system risk management has traditionally focused on controls for each phase, such as planning, development, operation and information security: the IT management that supports IT governance.

IT governance and IT management compared
AspectIT governanceIT management
Purpose (FSA)Linking IT systems to the creation of corporate valueRisk management for stable system operation
Accountable (METI)Board of directors or equivalentExecutive management (CEO, CIO, etc.) and the IT function
Core activitiesIT strategy and policy; evaluating, directing and monitoring IT managementPlanning, development, operation and maintenance, external services, business continuity, etc.

What is the FSA's dialogue paper on IT governance (2nd edition)?

The dialogue paper is a discussion paper setting out the FSA's thinking and points of focus for dialogue with financial institutions on IT governance. It stems from an overhaul of inspection and supervision, under which the FSA decided to set out its thinking on each theme in discussion papers, expressly as material for discussion, and abolished the inspection manual with its system risk checklists:

  1. 1999: inspection manual for system risk management drawn up
  2. December 2002: inspection checklist for system integration risk management published
  3. June 2018: Basic Policy on Inspection and Supervision published
  4. June 2019: 1st edition of the dialogue paper
  5. December 2019: inspection manual abolished
  6. 2020 to 2022: annual survey reports and case studies on IT governance and related topics
  7. June 2023: 2nd edition, adding thinking and points of focus on digital transformation (DX)

Its status: not a checklist

The FSA says it “will not, in inspection or supervision, apply the individual points of this document mechanically or use them as a checklist”, and that dialogue will take full account of each institution's size and characteristics. Abolishing the manual, it explains, was not a rejection of established practice but a way to let institutions build on current practice in their own way.

The paper is aimed “mainly at deposit-taking financial institutions and insurance companies” but “does not prevent other companies providing financial services from using it”. It sets out how IT systems are now handled:

IT systems after the inspection manual (based on Figure 4 of the dialogue paper)
AreaOverviewRules until nowGoing forward
IT governanceLinking IT systems to the creation of corporate valueNone in particularDialogue based on this paper, drawing on generally available guidelines
IT managementRisk management for stable system operationThe inspection manual and the FISC Security Guidelines it citedGenerally available guidelines
System integrationPart of system risk management: managing integration projects after mergers and the likeInspection checklist for system integration risk managementAn outline in this paper, with a detailed annex

The dialogue depends on the issue

  • Stable system operation at risk (user protection): dialogue on system risk management.
  • System costs beyond the institution's means left unchecked (possibly affecting future soundness): dialogue within the discussion of future soundness.
  • Disruption from shifting to IT-driven strategies: dialogue centred on industry best practice.

Themes for continued dialogue include next-generation plans for regional banks' shared system centres alongside each bank's own IT governance, global IT governance at major institutions, and how monitoring should adapt as DX and other forces change finance.

The six perspectives: from leadership by management to IT risk

The 2nd edition lists six items as its “basic thinking and points of focus for in-depth dialogue”: management's guiding role (1), the strategy itself (2) and four mechanisms behind both the IT and DX strategies (3 to 6).

(1) Leadership by management

Management should lead in deciding what the institution's IT systems should look like, given its financial strength and strategy. For DX it should set the destination, lead the organisation there, keep communicating to win stakeholders' trust and support, and build momentum. Management here includes the heads of internal control functions, the systems department among them, and of business units; it should raise its IT and digital literacy and discuss, with balance, how to ensure security and manage IT risk, cyber risk included.

(2) IT strategy and DX strategy

The IT strategy sets policy on replacing core systems, upgrading information systems, the cloud and information security, and on the target architecture, such as the mix of mainframe and open platforms and of on-premises and cloud, data platforms and API integration. Legacy rebuild methods (rehosting, rewriting, replacement and so on) should be chosen after weighing medium- to long-term IT costs, the future of the programming language and the removal of black boxes.

The DX strategy, defined as clearly distinct from the IT strategy drawn up by the IT organisation, is the policy and plan for digital business innovation and development, for higher profitability or a new business model. It sets strategic areas, such as channel reform, operational innovation, branch digitalisation, more customer touchpoints, cross-selling and new businesses, and a medium- to long-term roadmap. With limited capacity to invest, institutions might share functions with allied banks or join a platform.

(3) IT organisation and DX promotion organisation

Organisational capability turns on who leads planning and development, which departments, subsidiaries and committees take part, and how IT, digital and information security talent is secured and developed, and above all on how decisions and responsibilities for planning, developing, operating and managing systems are split between management, the systems department and user departments. Where business units work in an agile way under delegated authority, the IT organisation should standardise methods, policies, tool selection and development environments to keep development under control.

(4) Optimised IT resources

Resources are optimised across people, things and money to deliver the IT strategy, outsourcing strategy included. People: define the skills needed concretely and develop IT and digital talent to a plan. Things: judge new technologies such as APIs, AI and the cloud on their security risk and on the opportunity lost by not adopting them. Money: do not take the budget for maintenance and regulatory compliance as given; secure strategic investment that creates corporate value.

(5) IT investment management process

Set a medium-term plan and annual budget for strategic IT investment and the DX projects within it, with a process that moves quickly from proposal through review to decision. Afterwards, evaluate projects expected to earn by ROI or similar measures in a PDCA cycle that adds resources, scales back or withdraws. Projects at proof-of-concept (PoC) stage, or needing medium-term work, can be tracked against plan with KPIs until revenue is in sight.

(6) Properly managed IT risk

Running existing systems on autopilot can itself be a business risk, in competition and cost, so the operational and other risks of adopting new technology should be weighed against the risk of forgoing future earnings or savings by not adopting it. DX brings risks from new products and services, system failure, information security (including cyber) and external partners (economic security, money laundering and terrorist financing, a partner pulling out). New products and services need security by design from the planning and design stage, and low-quality, unreliable data can make AI analysis produce wrong output.

In the 2nd edition, IT risk includes missing future benefits by not adopting new technology. The FSA wants this weighed in substance when deciding, not handled through formal quantitative measurement or as an extra item in investment criteria.

COBIT 2019, ISO/IEC 38500:2024, the System Management Standards and the Digital Governance Code compared

The dialogue paper says what to discuss and leaves how to build the framework to general standards, naming as examples FISC's Security Guidelines and System Audit Standards for financial institutions, ISACA's COBIT, and METI's System Management Standards and System Audit Standards.

The main IT governance standards compared
StandardPublisher and editionNatureUse at a financial institution
COBIT 2019ISACA; developed from COBIT 540 governance and management objectives, tailored with design factors; process capability levels 0 to 5Turning the six perspectives into objectives, processes and metrics; assessing the current state
ISO/IEC 38500:2024ISO/IEC JTC 1/SC 40; 3rd edition, February 2024, replacing the 2015 editionGuiding principles for members of governing bodies, and those who support them, on the effective, efficient and acceptable use of IT, in organisations of any size or sectorPrinciples for what the board decides about IT and how it oversees it
System Management StandardsMETI, 26 April 2023Two parts, IT governance and IT management, with objectives and example activitiesDividing roles between the board and executive management; a yardstick for internal and system audit
Digital Governance Code 3.0METI; issued November 2020, revised to 2.0 in September 2022 and to 3.0 after a study group's discussions from June 2024What management should do to drive companies' voluntary work on DX, framed as three perspectives and five pillarsSetting and disclosing the management vision and DX strategy (perspective (2))

One workable division: the dialogue paper for what to discuss; ISO/IEC 38500 and the System Management Standards for the roles of the board and executive management; COBIT for objectives, processes and metrics; and the FISC Security Guidelines for the level of individual security measures. The System Management Standards themselves say exhaustive application is not effective: select and adapt items to the organisation.

Mapping the six perspectives to COBIT 2019

COBIT 2019 sorts its 40 objectives into five domains: the 5 governance objectives in EDM (Evaluate, Direct and Monitor), and the 35 management objectives in APO (Align, Plan and Organize), BAI (Build, Acquire and Implement), DSS (Deliver, Service and Support) and MEA (Monitor, Evaluate and Assess).

The six perspectives mapped to COBIT 2019 objectives (example)
FSA perspectiveCOBIT 2019 objectives (examples)
(1) Leadership by managementEDM01 Ensured Governance Framework Setting and Maintenance; EDM05 Ensured Stakeholder Engagement
(2) IT and DX strategyAPO02 Managed Strategy; APO03 Managed Enterprise Architecture; APO04 Managed Innovation
(3) IT and DX organisationAPO01 Managed I&T Management Framework; APO08 Managed Relationships; BAI05 Managed Organizational Change
(4) IT resourcesEDM04 Ensured Resource Optimization; APO07 Managed Human Resources; BAI09 Managed Assets
(5) IT investment managementEDM02 Ensured Benefits Delivery; APO05 Managed Portfolio; APO06 Managed Budget and Costs
(6) IT riskEDM03 Ensured Risk Optimization; APO12 Managed Risk; APO13 Managed Security; APO10 Managed Vendors

This mapping is findn's own, not one published by the FSA or ISACA.

How the FISC Security Guidelines and the FSA's cybersecurity guidelines fit in

Perspective (6), IT risk, rests on two IT management documents: the FISC Security Guidelines, setting security standards for information systems, and the FSA's Guidelines on Cybersecurity for the Financial Sector, setting out points of focus for the cybersecurity management framework.

FISC Security Guidelines

Published by the Center for Financial Industry Information Systems (FISC), the FISC Security Guidelines on Computer Systems for Financial Institutions set standards for the security measures financial institutions are considered to need in developing, introducing and operating financial information systems, with commentary and examples for each item. First issued in December 1985 and revised many times since, they are now in their 14th edition (March 2026), which reflects revisions on AI security measures, cybersecurity, post-quantum cryptography (PQC), system failure cases and various guidelines.

Under the inspection manual, inspectors examining a business in depth checked it against these guidelines. The dialogue paper still expects generally available guidelines to be used in IT management and names these first.

Guidelines on Cybersecurity for the Financial Sector

Issued on 4 October 2024 as a more detailed document separate from the supervisory guidelines, these guidelines set out “fundamental response measures” and “recommended measures” for governance, identification, defence, detection, response, recovery and third-party risk management. The first are the basics institutions generally need, including cyber hygiene; the second are practices desirable for institutions whose incidents could seriously affect local communities and the economy, and good practices for major institutions to refer to. Neither tier demands a uniform response: institutions assess their own risks and act on them, a risk-based approach.

They apply to every business type whose supervisory guidelines contain cybersecurity management provisions, including major banks, small and regional financial institutions, insurers, financial instruments business operators and crypto-asset exchange service providers, and to financial instruments exchanges, and note that those provisions form part of system risk management.

Securities firms: the supervisory guidelines refer to the 2nd edition

The paper applies to securities firms too. The system risk section (III-2-8) of the FSA's Comprehensive Guidelines for Supervision of Financial Instruments Business Operators, etc. says properly functioning IT governance is just as important for these firms and cites the 2nd edition (June 2023). Its points of focus for the system risk management framework (III-2-8-1) cover:

  • Awareness of system risk
  • Establishing an appropriate risk management framework
  • System risk assessment
  • Information security management
  • Cybersecurity management
  • System planning, development and operations management
  • System audit
  • Outsourcing management
  • Contingency plans
  • System integration risk and project management
  • Response to system failures

The points most directly tied to IT governance ask whether the board, fully aware of system risk, has set a basic policy for company-wide risk management; whether an officer is in overall charge of systems; and whether the board has approved a medium- to long-term development plan built on a clear system strategy policy within the business strategy. On cybersecurity, they ask whether the board has built the necessary framework in light of the FSA's cybersecurity guidelines, and they cite the FISC Security Guidelines as reference on information security and system risk.

Further points cover internet trading (III-2-8-2), and firms must report to the authorities immediately on becoming aware of a system failure or cybersecurity incident. Securities firms are also designated critical infrastructure operators under the Basic Act on Cybersecurity.

KRIs, ledgers and outsourcing: keep evidence you can explain

Explaining IT governance in dialogue takes evidence beyond policies and rules: indicator trends, ledgers, outsourcee assessments and decision records. The FSA's cybersecurity guidelines specify the reporting and ledgers expected, an approach that suits IT risk generally.

What the cybersecurity guidelines ask for

  • At least once a year, reports to management on the cybersecurity risks faced, risk assessment results and progress on the implementation plan (fundamental response measure).
  • At least twice a year, reports to management on key performance indicators (KPIs) and key risk indicators (KRIs) (recommended measure).
  • Example KRIs: attempted cyberattacks, audit findings, incidents and unresolved vulnerabilities. Example KPIs: reporting rate in targeted email training, vulnerability response rate, information asset inventory progress and training participation rate.
  • Comprehensive, up-to-date ledgers of information systems and external system services (outsourcees and cloud services), including systems run by individual departments (fundamental response measure).
  • Support periods and software versions recorded in the hardware and software ledgers (fundamental response measure); a software bill of materials (SBOM) for in-house software and the like (recommended measure).

Example KRIs for each perspective

KRIs on the six perspectives move board reporting from description to trend-based decisions. Our example:

Example KRIs and evidence by perspective (findn's example)
PerspectiveExample KRIMain evidence
(2) IT and DX strategyStrategic projects behind the roadmapRoadmap, progress reports
(4) IT resourcesSystems past end of support, or reaching it within a yearHardware and software ledgers
(5) IT investment managementInvestments below their planned ROI or KPIsInvestment committee papers, post-investment reviews
(6) IT riskUnresolved vulnerabilities, incidents, open audit findingsRisk register, vulnerability records, audit reports
(6) IT risk: outsourceesCritical outsourcees with overdue assessmentsOutsourcee ledger, assessment results, contracts

Outsourcing and records of decisions

Outsourcing cuts across every perspective. The supervisory guidelines for securities firms expect outsourcees (system subsidiaries included) to be chosen against selection criteria, contracts to set out roles and responsibilities, audit rights, subcontracting procedures and service levels, and outsourced work to be monitored regularly. For system integration, the dialogue paper asks the institution to stay actively involved rather than leave it to the outsourcee.

None of this evidence needs to be created for the dialogue: the FSA says dialogue should not overburden institutions and that the content and frequency of regular submissions should be reviewed. The least burdensome approach is to keep the ledgers, meeting papers and approvals of daily management fit to explain as they stand.

How to proceed: from assessment to a roadmap and monitoring

In practice: assess the current state against the six perspectives, set a prioritised roadmap, then monitor with indicators.

  1. Assess: for each perspective, take stock of policies, organisation and authority, rules, ledgers and committee records, and check that facts support the position.
  2. Find gaps: measure against COBIT 2019 objectives and capability levels, the FISC Security Guidelines and the fundamental response measures of the cybersecurity guidelines, selecting what fits your size and characteristics.
  3. Prioritise: separate issues of user protection (stable system operation), future soundness (system costs) and business transformation.
  4. Plan and approve: separate what the board approves (IT strategy, medium- to long-term development plan, risk appetite) from what executive management carries out.
  5. Monitor: report KPIs and KRIs to management regularly; judge investments by ROI or KPIs to scale up, scale back or withdraw.
  6. Review: assess the framework's effectiveness at least once a year, feeding in internal and system audit results.

Design to scale: the dialogue paper takes size and characteristics fully into account, and the System Management Standards call exhaustive application ineffective. What counts is explaining what you chose and deferred, given your strategy and risks, not meeting every item uniformly.

How findn can help

findn Co., Ltd. provides IT consulting focused on financial institutions: IT strategy, IT governance frameworks aligned with the FISC Security Guidelines, COBIT and similar standards, IT risk and compliance, and information security and data governance. It is certified to ISO/IEC 27001:2022, and its CEO, Saravana Prathap (CISA), moved to Japan in 2005 and has since worked with major securities firms in Japan and abroad. findn also offers shachi, an IT governance platform for Japanese financial institutions covering a risk ledger with KRIs, policies and regulatory reports, an inspection binder, an audit trail, an IT asset ledger and SBOM/AIBOM.

Questions and answers

What is the difference between IT governance and IT management?
IT governance is where the board of directors or equivalent body sets the direction for how IT is used, and evaluates, directs and monitors IT management. IT management is where executive management plans, develops and operates systems in line with that direction and manages the risks. METI's System Management Standards distinguish the two by this division of accountability, and the FSA's dialogue paper likewise treats IT management as risk management aimed at the stable operation of systems.
Is the FSA's Points and Practices paper a checklist?
No. The FSA states that in inspection and supervision it will not apply the paper's individual points mechanically or use them as a checklist. The paper is material for dialogue towards better practice, and discussion is to take full account of each institution's size and characteristics.
What changed in the 2nd edition?
The 2nd edition (June 2023) builds on the dialogue and survey results since the 1st edition (June 2019) and expands the paper with thinking and points of focus on DX. Its perspectives treat a DX strategy alongside the IT strategy and a DX promotion organisation alongside the IT organisation, and it defines the DX strategy as clearly distinct from the IT strategy drawn up by the IT organisation.
How do COBIT and the FISC Security Guidelines differ in use?
COBIT 2019 is ISACA's framework for the governance and management of IT, and its 40 objectives suit designing and assessing the framework as a whole. The FISC Security Guidelines set out, item by item, the security measures that financial institutions' information systems need, and suit checking the level of individual controls. The FSA's dialogue paper names both as examples of guidelines used at financial institutions.
Does it apply to securities firms?
Yes. The 2nd edition is aimed mainly at deposit-taking institutions and insurers, but it says it does not prevent other financial services firms from using it. In addition, the FSA's Comprehensive Guidelines for Supervision of Financial Instruments Business Operators, etc. say that IT governance matters just as much for those firms, cite the 2nd edition for reference and set out points of focus for the system risk management framework.

Sources

  1. Points and Practices for Dialogue on IT Governance of Financial Institutions, 2nd edition, June 2023 (Japanese) Opens an external site (Financial Services Agency (FSA), Japan)
  2. Comprehensive Guidelines for Supervision of Financial Instruments Business Operators, etc., Part III: Supervisory Evaluation Items and Procedures (III-2-8 System Risk) (Japanese) Opens an external site (Financial Services Agency (FSA), Japan)
  3. Guidelines on Cybersecurity for the Financial Sector (provisional translation, 4 October 2024) Opens an external site (Financial Services Agency (FSA), Japan)
  4. FISC Security Guidelines on Computer Systems for Financial Institutions, 14th edition: publication page (Japanese) Opens an external site (The Center for Financial Industry Information Systems (FISC))
  5. System Management Standards, 26 April 2023 (Japanese) Opens an external site (Ministry of Economy, Trade and Industry (METI), Japan)
  6. Digital Governance Code (Japanese) Opens an external site (Ministry of Economy, Trade and Industry (METI), Japan)
  7. COBIT (COBIT 2019) Opens an external site (ISACA)
  8. ISO/IEC 38500:2024 Information technology: Governance of IT for the organization Opens an external site (International Organization for Standardization (ISO))

Contact

If you have any questions or challenges regarding IT governance, system design, development, or maintenance, please don’t hesitate to contact us.

Reception hoursWeekdays 9:00-18:00 (JST)

Contact form