Indonesia's Otoritas Jasa Keuangan (OJK) — the Financial Services Authority — sets governance, risk-management and information-security expectations for the financial services entities it regulates, with a growing focus on digital financial services. If you operate in Indonesian financial services, OJK is your regulator, and building a supervision-ready program starts with understanding its themes.
What OJK expects
As with other financial regulators, the emphasis is on board-level accountability, a baseline of security controls, monitoring and incident handling, resilience for critical services, and oversight of the third parties that support financial services. The recurring themes:
- Governance: board-approved policies and clear accountability for information security and risk.
- Risk management: identifying, assessing and treating technology and security risk.
- Security controls: access control, data protection and secure operations.
- Monitoring and incident handling: detecting, responding to and reporting incidents.
- Resilience: business continuity and recovery for critical financial services.
- Third-party risk: governing outsourced and technology-provider arrangements.
Scope
Applicable rules
Assess
Risk & gaps
Control
Security & resilience
Evidence
Map & maintain
Report
To the regulator
International certifications help — but don't replace local rules
Because OJK's themes overlap heavily with international standards like ISO 27001, much of the underlying control work is reusable. But international certifications alone don't automatically satisfy local OJK requirements — you still need to map your controls to the applicable OJK regulations. Doing that mapping once, and reusing the evidence, is what keeps a multi-framework program manageable.
ISO 27001
- Controls mapped
- Evidence collected
- Policies & procedures in place
Adding OJK
~60% carried overAuto-completed from your existing program
Overlap shown is illustrative — the actual carry-over depends on the maturity of your existing program.
How Pelta helps
Pelta lets you manage OJK expectations as a control set with linked evidence, reuse overlapping controls from frameworks you already run, and keep critical-service resilience and third-party risk in view — so you're ready for supervision rather than assembling evidence under time pressure.
Frequently asked questions
Who does OJK regulate?+
OJK (Otoritas Jasa Keuangan) is Indonesia's Financial Services Authority. It regulates banks, financial institutions, and increasingly digital financial services providers and fintechs operating in Indonesia.
What does OJK expect for information security?+
Broadly: board-level governance, risk management, a baseline of security controls, monitoring and incident handling, resilience for critical services, and oversight of third parties. Specifics depend on entity type and current regulations.
Do international certifications satisfy OJK requirements?+
They help and much of the control work overlaps, but international certifications alone do not automatically satisfy local OJK requirements — map your controls to the applicable OJK regulations.
How does Pelta help with OJK compliance?+
Pelta manages OJK expectations as a control set with linked evidence, reuses overlapping controls from frameworks like ISO 27001, and keeps critical-service resilience and third-party risk in view for supervision.