Skip to main content

Framework · Bank of Ghana regulated

Bank of Ghana Cyber and Information Security Directive (CISD)

Mandatory regulatory framework for licensed banks, specialised deposit-taking institutions, savings and loans companies, and payment service providers operating in Ghana.

GHANA PRACTICE

Where this framework fits at Goldline

Goldline's active service lines are ISO 42001 (AI governance) and ISO 27001 (information security) implementation. BoG CISD is not a service Goldline delivers as a standalone product.

BoG CISD is delivered under Goldline's Ghana practice for Bank of Ghana regulated entities. This framework page sits alongside Goldline's Ghana practice, distinct from the UK service lines (ISO 42001 and ISO 27001 implementation).

For BoG-regulated entities, the BoG CISD Compliance programme is the primary route. Book the Free Diagnostic to confirm applicability and scope.

Book the Free Diagnostic

Browse all frameworks

What is the BoG CISD?

The Bank of Ghana Cyber and Information Security Directive sets the mandatory cyber and information security requirements for the Ghanaian financial sector. It is issued and enforced by the Bank of Ghana under its supervisory authority over licensed financial institutions. The CISD is not optional best practice. It is a regulatory obligation with supervisory teeth, and non-compliance carries regulatory consequences.

Who CISD applies to

The CISD applies to all institutions licensed by the Bank of Ghana, including:

  • Universal banks

  • Specialised deposit-taking institutions (SDIs)

  • Savings and loans companies

  • Payment service providers (PSPs)

  • Other entities supervised by the Bank of Ghana

Approximately 100 plus licensed institutions sit in scope across these categories.

The five domains of obligation

CISD organises its requirements into five domains that collectively define a regulated institution's cyber and information security posture.

Information security governance

Board accountability, information security policy framework, designated security leadership, organisational structure for information security.

Risk management

Documented risk methodology, risk register, risk assessment cadence, risk treatment, and reporting to the board.

Incident management

Incident response procedures, breach notification to the Bank of Ghana, post-incident review, and evidence retention.

Third-party risk

Supplier due diligence, ongoing supplier risk assessment, contractual requirements, and supply chain cyber posture.

Business continuity

Business impact analysis, business continuity planning, disaster recovery, and recovery testing.

How CISD maps to ISO 27001

The CISD's five domains map directly onto ISO 27001 Annex A controls with substantial overlap. An institution implementing ISO 27001 addresses the majority of CISD requirements through the same control set, with localised additions to satisfy Bank of Ghana-specific reporting and supervisory expectations. This makes ISO 27001 implementation the most efficient path to CISD compliance while delivering an internationally recognised certificate as a second outcome.

Implementation considerations

  • Engagement scope must align to the institution's licence category and operating footprint

  • Risk methodology should be designed for both BoG supervisory review and ISO 27001 audit

  • Incident notification timelines and templates need pre-agreement with the BoG-facing leadership

  • Third-party risk assessment must cover both Ghanaian sub-processors and international correspondent relationships

  • Business continuity testing requires evidence retention to BoG supervisory standard

Goldline programme that addresses this

The Goldline BoG CISD 2026 Programme delivers CISD compliance and ISO 27001 certification in a single engagement for BoG-regulated institutions. Senior practitioner-led delivery with local in-market partnership.

Explore the programme →

Frequently asked questions

Speak to a senior practitioner about BoG CISD compliance

Scoped, calibrated, and led by a senior practitioner with deep UK regulated and Ghanaian financial sector experience.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.