Framework · Bank of Ghana regulated
Bank of Ghana Cyber and Information Security Directive (CISD)
Mandatory regulatory framework for licensed banks, specialised deposit-taking institutions, savings and loans companies, and payment service providers operating in Ghana.
GHANA PRACTICE
Where this framework fits at Goldline
Goldline's active service lines are ISO 42001 (AI governance) and ISO 27001 (information security) implementation. BoG CISD is not a service Goldline delivers as a standalone product.
BoG CISD is delivered under Goldline's Ghana practice for Bank of Ghana regulated entities. This framework page sits alongside Goldline's Ghana practice, distinct from the UK service lines (ISO 42001 and ISO 27001 implementation).
For BoG-regulated entities, the BoG CISD Compliance programme is the primary route. Book the Free Diagnostic to confirm applicability and scope.
Book the Free DiagnosticWhat is the BoG CISD?
The Bank of Ghana Cyber and Information Security Directive sets the mandatory cyber and information security requirements for the Ghanaian financial sector. It is issued and enforced by the Bank of Ghana under its supervisory authority over licensed financial institutions. The CISD is not optional best practice. It is a regulatory obligation with supervisory teeth, and non-compliance carries regulatory consequences.
Who CISD applies to
The CISD applies to all institutions licensed by the Bank of Ghana, including:
Universal banks
Specialised deposit-taking institutions (SDIs)
Savings and loans companies
Payment service providers (PSPs)
Other entities supervised by the Bank of Ghana
Approximately 100 plus licensed institutions sit in scope across these categories.
The five domains of obligation
CISD organises its requirements into five domains that collectively define a regulated institution's cyber and information security posture.
Information security governance
Board accountability, information security policy framework, designated security leadership, organisational structure for information security.
Risk management
Documented risk methodology, risk register, risk assessment cadence, risk treatment, and reporting to the board.
Incident management
Incident response procedures, breach notification to the Bank of Ghana, post-incident review, and evidence retention.
Third-party risk
Supplier due diligence, ongoing supplier risk assessment, contractual requirements, and supply chain cyber posture.
Business continuity
Business impact analysis, business continuity planning, disaster recovery, and recovery testing.
How CISD maps to ISO 27001
The CISD's five domains map directly onto ISO 27001 Annex A controls with substantial overlap. An institution implementing ISO 27001 addresses the majority of CISD requirements through the same control set, with localised additions to satisfy Bank of Ghana-specific reporting and supervisory expectations. This makes ISO 27001 implementation the most efficient path to CISD compliance while delivering an internationally recognised certificate as a second outcome.
Implementation considerations
Engagement scope must align to the institution's licence category and operating footprint
Risk methodology should be designed for both BoG supervisory review and ISO 27001 audit
Incident notification timelines and templates need pre-agreement with the BoG-facing leadership
Third-party risk assessment must cover both Ghanaian sub-processors and international correspondent relationships
Business continuity testing requires evidence retention to BoG supervisory standard
Goldline programme that addresses this
The Goldline BoG CISD 2026 Programme delivers CISD compliance and ISO 27001 certification in a single engagement for BoG-regulated institutions. Senior practitioner-led delivery with local in-market partnership.
Explore the programme →Frequently asked questions
Speak to a senior practitioner about BoG CISD compliance
Scoped, calibrated, and led by a senior practitioner with deep UK regulated and Ghanaian financial sector experience.
