Bank regulators want proof that your apps hold up.
Supervisors from Frankfurt to Riyadh, Singapore and New York now expect banks to test their mobile apps and APIs often, behind login, and to prove each fix. Here is what each regulator asks, in plain words and with the official sources, and how Ostorlab supports the testing part.
- EU: DORA testing rules, and the ECB action plan due 31 October 2026
- Middle East: UAE, Saudi Arabia, Qatar, Kuwait and Jordan
- Asia: Pakistan, Bangladesh, Japan, Singapore and Indonesia
- Americas: United States and Brazil, plus Ukraine in Europe
Start with the three most asked-about
Each page sums up what the regulation asks, links to the official text, and maps Ostorlab's testing to it.
- ECB letter on AI-enabled cyber threatsFor banks the ECB supervises directly: what the letter of 7 July 2026 asks for in the action plan due on 31 October 2026.Read the page
- DORA resilience testing (Articles 24 to 27)For EU financial entities: the testing programme, the tests DORA lists, and where threat-led penetration testing (TLPT) fits.Read the page
- CBUAE Notice 2176 and mobile fraud controlsFor UAE licensed financial institutions: the CBUAE's fraud prevention rules, Notice 2176, and how to test your app's defenses.Read the page
These pages sum up public texts to help you plan testing. They are not legal advice. Ostorlab supports your testing obligations; it does not make you compliant on its own, so check how it fits with your compliance team.
Bank regulations where Ostorlab works
One page per regulator, each built from the official texts: what they ask of your mobile app and its APIs, how Ostorlab helps with the testing, and what stays with you.
European Union and Europe
- EU: DORA resilience testingWeekly automated scans, static and dynamic testing, yearly tests and TLPT under DORA and its technical standards.
- EU: ECB letter on AI-enabled cyber threatsThe action plan significant banks owe the ECB by 31 October 2026, focus area by focus area.
- Ukraine: NBU information security and authentication rulesPeriodic pentests, OWASP, five-attempt lockout, ten-minute time-outs and tamper protection: the NBU's rules for mobile banking apps.
- United Kingdom: PRA and FCA operational resilienceImpact tolerances, scenario testing and CBEST, plus SCA, outsourcing and incident reporting: the PRA and FCA rules for mobile banking apps and APIs.
- Switzerland: FINMA operational resilience and cyber rulesCircular 2023/1, the cyber guidance and the revised FADP applied to mobile banking apps and APIs: pentests, critical data, exercises and reporting.
- Turkey: BDDK and CBRT banking rulesAnnual pentests, app hardening, SMS OTP limits and remote onboarding: the BDDK, CBRT and KVKK rules for mobile banking apps.
Middle East
- UAE: CBUAE rules and Notice 2176Fraud prevention, authentication, sessions, APIs and device protections in the public CBUAE texts.
- Saudi Arabia: SAMA Cyber Security FrameworkAnnual pentests, security testing of every change, MFA on e-banking and root detection: SAMA's rules for mobile banking apps.
- Qatar: QCB Technology Risks regulationTwice-yearly pentests, app testing before and after go-live, and data kept in Qatar: QCB's rules for mobile banking apps.
- Kuwait: CBK Cyber and Operational Resilience FrameworkThe CBK's CORF rules for mobile banking apps and APIs: rooted devices, MFA, sessions, OTPs and penetration testing.
- Jordan: CBJ Cyber Risks Resilience InstructionsThe CBJ's rules for mobile banking apps and APIs: yearly penetration tests, TLS pinning, rooted devices, MFA and session limits.
- Bahrain: CBB cyber security rules and PDPLTwice-yearly pentests, app, API and third-party assessments, and e-banking authentication: the CBB's rules for mobile banking apps.
- Oman: CBO Cyber Security & Resilience FrameworkThe CBO's BM 1194 framework and fraud circulars for mobile banking apps and APIs: annual pentests, MFA, session limits and app-store controls.
- Egypt: CBE cybersecurity and payment rulesWhat the CBE Financial Cybersecurity Framework, the internet banking and mobile payment rules and the Personal Data Protection Law ask of your mobile banking app and APIs.
Africa
- Morocco: Bank Al-Maghrib, DNSSI and CNDP rulesPenetration testing, m-wallet security rules, law 05-20 with the DNSSI, and personal data duties under law 09-08, applied to mobile banking apps and APIs.
- Nigeria: CBN Cybersecurity FrameworkYearly vulnerability assessments, annual penetration tests, quarterly scans, open banking API security and NDPA safeguards, applied to mobile banking apps and the APIs behind them.
- Kenya: CBK Cybersecurity GuidanceThe 2017 Guidance Note on Cybersecurity, the payment service provider guideline, the National Payment System rules and the Data Protection Act, applied to mobile banking apps and APIs.
- South Africa: FSCA and PA Joint StandardsVulnerability assessment, penetration testing, application security testing, MFA and POPIA safeguards, applied to mobile banking apps and the APIs behind them.
South Asia
- Pakistan: SBP digital banking securitySBP's technology risk framework and 2023 digital banking security measures, applied to mobile banking apps and APIs.
- Bangladesh: Bangladesh Bank ICT Security GuidelineThe ICT Security Guideline v4.0 and the 2026 Cybersecurity Framework, applied to mobile banking apps, MFS apps and APIs.
- India: RBI cybersecurity and payment security directionsThe RBI's 2026 cybersecurity and digital payment security directions for banks: half-yearly VA, annual PT, mobile app controls and two-factor authentication.
- Sri Lanka: CBSL technology risk directionsThe CBSL technology risk directions and the payment app guideline: pre-implementation testing, quarterly assessments, annual pentests and app hardening controls.
- Nepal: NRB IT and Cyber Resilience GuidelinesNepal Rastra Bank's IT Guidelines and Cyber Resilience Guidelines: mobile banking encryption, periodic penetration testing and MFA for critical systems.
Asia-Pacific
- Japan: FSA Cybersecurity GuidelinesFSA cybersecurity guidelines and supervisory guidelines for banks: mobile app assessments, public API testing and phishing-resistant MFA.
- Singapore: MAS Technology Risk ManagementMAS TRM Guidelines, Notices FSM-N05 and FSM-N06 and the Shared Responsibility Framework, applied to mobile banking apps and APIs.
- Indonesia: OJK cyber security testingPOJK 11/2022, SEOJK 29/2022, PADK 1/2026 and POJK 21/2023, applied to mobile banking apps and the APIs behind them.
- China: PBOC and NFRA mobile app rulesAnnual external assessments and NIFA filing, JR/T 0171 data categories, API testing before go-live and MLPS duties: the PBOC, NFRA and MIIT rules for mobile banking apps.
- Hong Kong: HKMA e-banking rulesHKMA module TM-E-1, the E-Banking Security ABCD circulars and the PCICSO, applied to mobile banking apps and APIs: independent assessment, annual penetration tests and in-app authentication.
- Taiwan: FSC blueprint and association standardsAnnual app baseline tests, OWASP MASVS and Mobile Top 10 coverage, root and jailbreak restrictions, key storage, SBOM and API security: the Taiwan standards for mobile banking apps.
- South Korea: FSC e-finance and FSI assessment rulesAnnual vulnerability analysis and assessment, FSI mobile app criteria, the network separation reform and PIPA: Korea's rules for mobile banking apps.
- Malaysia: BNM RMiT and PDPA amendmentsThe RMiT testing cadence, mobile app and API controls, the fraud countermeasures and the customer information rules, applied to mobile banking apps and APIs.
- Thailand: Bank of Thailand mobile banking securityThe BOT mobile banking security notification, the IT risk rules and the PDPA applied to mobile banking apps and APIs, from anti-tampering to face verification above 50,000 baht.
- Philippines: BSP IT risk and AFASA rulesApplication testing before production, annual external VA and PT, restrictions on rooted and jailbroken devices and the phase-out of SMS and email one-time PINs: the BSP and AFASA rules for mobile banking apps.
- Vietnam: SBV Circular 50/2024The State Bank of Vietnam's online banking security rules, the OWASP mobile testing standard, biometric transaction confirmation and patch deadlines, applied to mobile banking apps and APIs.
- Australia: APRA CPS 234 and CPS 230APRA's CPS 234 testing program, CPS 230 operational risk, the Scams Prevention Framework and the Consumer Data Right, applied to mobile banking apps and APIs.
- New Zealand: RBNZ cyber resilience and DTA standardsThe RBNZ cyber resilience guidance and data collection, the DTA operational resilience exposure draft and the Privacy Act 2020, applied to mobile banking apps and APIs.
Americas
- United States: FFIEC and NYDFS Part 500FFIEC IT Handbook, the 2021 authentication guidance, the GLBA security standards and NYDFS Part 500, applied to mobile banking apps and APIs.
- Brazil: CMN Resolution 4,893 and BCB Resolution 85Yearly independent pentests, vulnerability testing, secure development and Pix authentication: the BCB's rules for mobile banking apps.
- Canada: OSFI B-13 and B-10OSFI's B-13, B-10 and E-21, the 24-hour incident reporting advisory and I-CRT, applied to mobile banking apps and their APIs, plus PIPEDA and Quebec Law 25.
- Mexico: CNBV CUB and Banxico SPEIVulnerability scanning, twice-yearly pentests, authentication factors, lockout and the standardised mobile transfer flow: Mexico's rules for mobile banking apps and their APIs.
- Colombia: SFC Circular Básica JurídicaTwice-yearly penetration tests, two-factor authentication, end-to-end encryption and open finance API standards: the SFC rules for mobile banking apps.
- Chile: CMF cybersecurity and outsourcing rulesRAN Chapters 20-10, 20-7 and 1-13, the Cybersecurity Framework Law and the CMF's strong customer authentication standard, applied to mobile banking apps and APIs.
- Argentina: BCRA technology and security rulesIndependent vulnerability tests, secure development, MFA, device binding and one-hour incident notification: the BCRA rules for mobile banking apps and their APIs.
- Peru: SBS cybersecurity and card authentication rulesPeriodic testing under the SGSI-C, strong authentication for digital operations, two factors for card payments and 48-hour breach notice: the SBS and data protection rules for mobile banking apps.
Three regimes, compared
Who each one applies to, what it asks you to test, and where Ostorlab supports the testing part.
| ECB letter on AI-enabled cyber threats | DORA | CBUAE rules and Notice 2176 | |
|---|---|---|---|
| Issued by | ECB Banking Supervision | European Parliament and Council, with Commission technical standards | Central Bank of the UAE |
| Legal nature | Supervisory letter built on DORA, not a new regulation | EU regulation, directly applicable in every Member State | Federal law, regulations, standards and guidelines, plus Notice 2176, which is not public |
| Who it applies to | Significant institutions, the banks the ECB supervises directly | EU financial entities, including banks, payment and e-money institutions | Licensed financial institutions in the UAE, with some rules for specific licences |
| Key date or cadence | Action plan to the Joint Supervisory Team by 31 October 2026 | Applies since 17 January 2025: weekly scans, yearly tests, TLPT every 3 years if identified | Decree-Law in force since 16 September 2025; quarterly reporting of vulnerabilities |
| Testing it asks for | Prioritised vulnerability scanning at scale, AI-based tools under human oversight, security by design | Vulnerability scans, static and dynamic code testing, penetration and end-to-end testing, TLPT | Vulnerability assessments, code review, business-logic testing, yearly independent API testing |
| What it means for mobile apps | Mobile apps and their APIs are internet-facing assets and internally developed software | Apps supporting critical or important functions need weekly automated scans and security testing before release | Authentication, step-up checks, sessions and device protections are fraud controls to test |
| Where Ostorlab helps | Baseline, remediation and retest evidence for the application part of the plan | Static, dynamic and AI-agent testing, dependency tracking, remediation tracking, groundwork for TLPT | Shielding bypass tests, logged-in testing, API testing and evidence for each release |
What the three have in common
Different regulators, the same four expectations for the apps your customers use.
Test more often
Weekly automated scans under DORA, scanning at scale in the ECB letter, regular assessments in the UAE: a yearly pentest alone no longer covers it.
Test what customers really use
The store build, behind login, with the APIs and SDKs it depends on, not a debug build with protections turned off.
Prove the fix
Findings are prioritised, remedied and validated, and the record shows it, for auditors and supervisors.
Stay in control of data and AI
AI tools under human oversight, vendors you can audit, and data kept where your policies require.
Ostorlab supports your testing obligations. Decisions on compliance stay with your teams. This is not legal advice.
Trusted by banks and fintechs, including
Frequently asked questions
Straight answers on coverage, setup, and how results reach your team.
Can't find your answer? Book a demo or contact us.
Test your banking app before your supervisor asks
Start with a free scan of your app from the store, or book a demo to plan testing across your releases.




