The Bank of Ghana’s revised Cyber and Information Security Directive 2026 establishes a common baseline for cyber security and operational resilience across Bank-regulated financial institutions. It covers governance, risk, assets, cloud services, physical security, data-centre management, contracts, incident response and testing.
Its practical significance is wider than a new compliance document. At the launch, the Governor described a move beyond simple compliance towards “active and collective cyber resilience”. Infrastructure approval therefore cannot rest on a provider’s reputation or certificate alone. The institution must demonstrate why an arrangement is suitable for a particular workload and how its controls have been evidenced.

Start with the workload, not the provider
The first question is not, “Which provider do we prefer?” It is, “What are we placing there?”
The institution should define the business service, its owner, dependencies and criticality. It should classify the data involved and set recovery time and recovery point objectives. That classification should determine the required controls, assurance and approvals.
Data location must also be specific. A useful data-flow map shows where primary data, replicas, backups, logs and encryption keys sit; where processing occurs; and from which jurisdictions administrators, support teams and subcontractors can gain access.
CISD 2026 calls for data-residency checks and approvals for cross-border transfers, while the Governor’s launch remarks emphasised keeping databases containing personal and financial information within Ghana. Institutions should confirm the treatment of each data class with the Bank of Ghana rather than relying on a provider’s broad description of a “region”.
Turn resilience claims into evidence
CISD 2026 includes a dedicated data-centre management section. It addresses site risk, independent power paths, backup capacity, dual-fed racks, redundant cooling, fire protection, physical segregation, continuous monitoring and diverse connectivity through entry paths, meet-me rooms and telecommunications providers.
These are not matters to accept through marketing language. Procurement and risk teams should request current site-risk assessments, relevant diagrams, maintenance records, test reports, access-control evidence and connectivity maps. They should check whether apparently diverse links share a duct, last-mile route or upstream dependency.
The same discipline applies to continuity. The Directive calls for documented business continuity and disaster recovery arrangements, with annual continuity, recovery and failover testing for critical systems. A provider should supply the results of recent tests, including actual recovery times, shortcomings and corrective actions. A backup policy is not evidence that data can be restored.
Cloud and outsourcing do not transfer accountability
Cloud services divide responsibilities among the provider, the institution and sometimes other suppliers. CISD 2026 expects that division to be documented across physical security, network controls, identity, encryption, application security, monitoring, incident response, backup and compliance.
The Bank of Ghana’s Outsourcing Directive reinforces the point: the board and senior management retain ultimate accountability for an outsourced function. Due diligence should therefore examine the provider’s capabilities, financial and operational resilience, subcontractors, concentration risks and exit options.
Contracts should include measurable service levels, incident-notification duties, access to logs and forensic evidence, audit and regulatory rights, subcontractor obligations, transition support and verifiable data deletion.
Incident communication deserves particular attention. CISD 2026 requires immediate regulatory reporting in defined circumstances and places strict notification duties on third parties. The FICSOC commissioning address also explains how industry logs and alerts support threat intelligence and incident response. A provider’s escalation path, contacts and evidence-preservation process should be agreed and exercised before an incident occurs.
Four assurances that should not be confused
- Data-centre certification assesses a defined facility or operational scope against a standard. It does not configure the customer’s applications, create a contractual uptime promise or prove end-to-end recovery.
- A contractual SLA defines the service commitment, measurement method, exclusions and remedies agreed between the parties. It is only as useful as its scope and enforceability.
- Application-level recovery demonstrates that the institution can restore data and resume the complete service—including networks, identities, applications and dependencies—within approved objectives.
- The institution’s compliance responsibility remains with the regulated institution. Selecting a certified facility, cloud service or resilience provider does not automatically satisfy CISD 2026.
Ask for proof before approval
The strongest provider review links every important answer to evidence, a contractual obligation, a test result and an internal owner prepared to accept it.
To make that review practical, Onix has prepared The CISD 2026 Infrastructure Evidence Checklist. It gives CIOs, CISOs, operations, risk, audit and procurement teams structured questions, evidence requests, warning signs and approval fields for data-centre, cloud and resilience decisions.
Disclaimer: This article provides general information only. It is not legal or regulatory advice. Organisations should confirm the requirements applicable to them with the Bank of Ghana and their professional advisers.