ADGM FSRA Publishes Comprehensive IT Risk Management Guidance For Financial Sector
The Financial Services Regulatory Authority (FSRA) of Abu Dhabi Global Market (ADGM) has released its Information Technology (IT) Risk Management Guidance. This document offers a detailed framework for handling technology risks within ADGM's financial sector. The guidance was developed after extensive industry consultations, including feedback from stakeholders following a discussion paper and an industry briefing in February 2024.
The guidance is divided into four main sections, each outlining best practices for IT risk management. These practices are recommended for entities regulated by the FSRA. The first section focuses on establishing a culture of effective IT risk management, covering governance, incident management, audits, and managing third-party IT service providers.

The second section addresses managing IT environments. It includes IT asset management, infrastructure, system lifecycle, resilience, and response to cyber incidents. The third section emphasizes secure interactions through system access controls, cryptographic key management, and secure online transactions.
In the fourth section, the guidance explores leveraging business-embedded technologies. It highlights emerging technologies such as algorithm-driven solutions like generative artificial intelligence and decentralized infrastructure solutions like virtual asset platforms.
This guidance aligns with international standards set by global financial regulators and standard-setting bodies. The FSRA expects that regulated entities will implement these best practices in ways that suit their size, complexity, and business activities.
Emmanuel Givanakis, CEO of the ADGM FSRA, stated: "As technology continues to transform financial services, robust IT risk management becomes increasingly critical. This Guidance reinforces our supervisory focus on IT risk and cybersecurity while supporting innovation in digital finance. It provides practical direction for senior executives, compliance officers, and IT practitioners to strengthen their risk management frameworks. This initiative reflects our commitment to building a resilient and progressive international financial centre in Abu Dhabi."
The guidance aims to provide practical directions for senior executives, compliance officers, and IT practitioners to enhance their risk management frameworks. By doing so, it supports innovation in digital finance while maintaining a strong focus on cybersecurity.
With inputs from WAM