Compliance

OJK Compliance in Indonesia: A Guide for Financial Services

If you operate in Indonesian financial services, OJK sets the expectations. Here's a practical overview and how to build a program that's ready for supervision.

The Pelta Team7 min readUpdated Part of OJK-DFA

Indonesia's Otoritas Jasa Keuangan (OJK) — the Financial Services Authority — sets governance, risk-management and information-security expectations for the financial services entities it regulates, with a growing focus on digital financial services. If you operate in Indonesian financial services, OJK is your regulator, and building a supervision-ready program starts with understanding its themes.

OJK regulations are issued in Indonesian and updated over time, and the specific rules depend on your entity type and activities. Treat this as a general overview and confirm the current applicable OJK regulations with qualified local counsel.

What OJK expects

As with other financial regulators, the emphasis is on board-level accountability, a baseline of security controls, monitoring and incident handling, resilience for critical services, and oversight of the third parties that support financial services. The recurring themes:

  • Governance: board-approved policies and clear accountability for information security and risk.
  • Risk management: identifying, assessing and treating technology and security risk.
  • Security controls: access control, data protection and secure operations.
  • Monitoring and incident handling: detecting, responding to and reporting incidents.
  • Resilience: business continuity and recovery for critical financial services.
  • Third-party risk: governing outsourced and technology-provider arrangements.
Building an OJK-ready program

Scope

Applicable rules

Assess

Risk & gaps

Control

Security & resilience

Evidence

Map & maintain

Report

To the regulator

International certifications help — but don't replace local rules

Because OJK's themes overlap heavily with international standards like ISO 27001, much of the underlying control work is reusable. But international certifications alone don't automatically satisfy local OJK requirements — you still need to map your controls to the applicable OJK regulations. Doing that mapping once, and reusing the evidence, is what keeps a multi-framework program manageable.

Comply once, reuse everywhere — in PeltaSee how the crosswalk works
Compliant

ISO 27001

  • Controls mapped
  • Evidence collected
  • Policies & procedures in place

Adding OJK

~60% carried over
Carried over from ISO 27001 New work for your team

Auto-completed from your existing program

GovernanceRisk managementAccess controlIncident handlingResilienceThird-party risk

Overlap shown is illustrative — the actual carry-over depends on the maturity of your existing program.

How Pelta helps

Pelta lets you manage OJK expectations as a control set with linked evidence, reuse overlapping controls from frameworks you already run, and keep critical-service resilience and third-party risk in view — so you're ready for supervision rather than assembling evidence under time pressure.

Frequently asked questions

Who does OJK regulate?+

OJK (Otoritas Jasa Keuangan) is Indonesia's Financial Services Authority. It regulates banks, financial institutions, and increasingly digital financial services providers and fintechs operating in Indonesia.

What does OJK expect for information security?+

Broadly: board-level governance, risk management, a baseline of security controls, monitoring and incident handling, resilience for critical services, and oversight of third parties. Specifics depend on entity type and current regulations.

Do international certifications satisfy OJK requirements?+

They help and much of the control work overlaps, but international certifications alone do not automatically satisfy local OJK requirements — map your controls to the applicable OJK regulations.

How does Pelta help with OJK compliance?+

Pelta manages OJK expectations as a control set with linked evidence, reuses overlapping controls from frameworks like ISO 27001, and keeps critical-service resilience and third-party risk in view for supervision.

Put this into practice with Pelta

Book a walkthrough and see how Pelta turns compliance, third-party risk and resilience into one continuous, evidence-backed program.