Skip to main content
← BlogCompliance

Who is allowed to run a bank's penetration test: in-house, third party, or an offshore vendor

POJK 11/2022 requires banks to test their cyber security, but it does not require an external tester and does not bar a foreign vendor. What decides it is competence, supervision, and OJK's right of examination. Here it is article by article.

K
Karina Kosasih · Offensive Security Lead
August 19, 2026·8 min read

A bank may run its cyber security testing with its own team, with an Indonesian testing firm, or with a vendor domiciled abroad. POJK 11/2022 does not require an external tester and sets no nationality condition on an information technology service provider. What it does regulate is the provider's competence, the bank's ability to supervise it, and one clause that in practice rules out more foreign vendors than any other: the provider's willingness to give OJK access to examine the service.

The question almost always reaches us in a tangled form, usually because the duty to place electronic systems inside Indonesia is assumed to apply to the tester as well. Those two rules sit in different chapters and neither substitutes for the other.

The obligation is to test, in two forms

Pasal 23 of POJK 11/2022 requires banks to conduct cyber security testing based on vulnerability analysis and based on scenarios. The two run on different rhythms. Pasal 24 ayat (1) states that vulnerability-analysis testing must be carried out periodically, without naming a figure, so the frequency is set by the bank itself. Pasal 25 ayat (1) sets scenario-based testing at a minimum of once a year.

None of those three articles says who has to run it, and SEOJK 29/2022 answers it directly at romawi VII point 5: "Bank dapat melakukan pengujian keamanan siber secara mandiri atau menggunakan pihak ketiga", meaning a bank may carry out cyber security testing itself or use a third party. Where a third party is used, the bank must ensure that party has competence adequate to the testing need, and remains responsible for the conduct of the testing. So the claim that OJK requires an independent tester for cyber security testing is not true, and we see it used as a sales argument often enough to be worth saying plainly.

One point deserves clearing up, because it is routinely mixed up. A penetration test belongs to the vulnerability-analysis stream, not the scenario stream. SEOJK 29/2022 romawi VII point 2 states that this testing begins with vulnerability identification and then continues with a penetration test, and that its frequency is set on the bank's own internal evaluation. The Penjelasan to Pasal 24 ayat (1) of POJK 11/2022 says the same, that an example of vulnerability-analysis testing is a penetration test. The examples given for scenario-based testing, by contrast, are a table-top exercise, a cyber range exercise, a social engineering exercise, and an adversarial attack simulation exercise. So the once-a-year minimum in Pasal 25 ayat (1) attaches to the scenario exercises, not to the pentest.

That does not make a pentest optional for every bank. Romawi VII point 2 closes with a flat requirement: this testing must be carried out by banks that provide digital banking services or other services operating online.

Once you engage a third party, Chapter VI applies

Appointing a service provider moves you into a different set of rules. Pasal 29 ayat (1) permits a bank to use IT service providers. Ayat (2) of the same article requires the bank to have the capability to supervise the bank activities carried out by that provider. That sentence deserves a slow read: the bank has to be able to supervise, not merely to receive a report. A bank with nobody who can read testing findings critically has not met that requirement, however complete the report is.

Pasal 29 ayat (3) requires policies and procedures covering the identification of the need, the selection of the provider, how the working relationship is conducted, risk management of the engagement, and assessment of the provider's performance and compliance. Pasal 30 then fills in each part. For selection, ayat (2) asks the bank to consider the provider's qualifications and competence including its personnel, a cost and benefit analysis that involves the bank's own IT unit, prudence and risk management principles, and arm's length dealing where the provider is a related party.

The offshore question, answered precisely

Pasal 30 ayat (3) governs the content of the cooperation agreement, and huruf i is the decisive item for a foreign vendor: the provider's willingness to give the Financial Services Authority and other authorised parties access to examine the service activities it provides. A testing firm that will not sign that clause cannot be used, and where it is domiciled changes nothing. Equally, a foreign vendor that accepts the clause in writing breaches nothing merely by sitting outside Indonesia.

Two other items in the same ayat cause real friction with testing vendors. Huruf d requires that any transfer of part of the work or any subcontracting happens with the bank's approval, evidenced by a written document, and many penetration testing firms use freelance testers for peak load. Huruf c requires the provider to commit to submitting periodic IT audit results from an independent auditor covering its own service provision, which is a different document from the test report you are buying.

System placement and tester location are separate questions

The domestic requirement that gets quoted sits in Pasal 35, in the chapter on placing electronic systems. Ayat (1) requires the bank to place its electronic systems in a data centre and disaster recovery centre within Indonesian territory. Ayat (2) permits placement outside Indonesia provided OJK grants permission, and ayat (3) limits that permission to six criteria, among them systems for risk management integrated with a head office abroad, integrated anti money laundering implementation, global customer service requiring integration with group systems, and the bank's internal management.

No part of Pasal 35 speaks about who may test those systems. It governs where the systems sit. The practical consequence runs opposite to the common assumption: because your production systems are almost always in Indonesia, an offshore tester reaches systems that stay onshore, and the questions worth answering are about access control and the handling of finding data, not about the tester's passport.

Where OJK does require an independent external party

The belief that a bank must use an external provider does not come from nowhere. POJK 11/2022 does contain an obligation to use an independent external party, but for something else. Pasal 55 ayat (2) requires the bank to review its internal IT audit function at least once every three years using the services of an independent external party, and Pasal 55 ayat (3) huruf a requires the result of that review to be submitted to OJK.

Note what is being reviewed. The external party reviews the bank's internal IT audit function, not the bank's systems, and that is an assessment of audit quality rather than a security test. The obligation also runs on a three-year cycle, not annually. So when someone says OJK requires an external party, the sentence is true of Pasal 55 ayat (2) and untrue of the cyber security testing in Pasal 23 to 25. The two get conflated often, and the conflation is usually used to sell the wrong piece of work.

Where a certification like OSCP actually fits

No OJK regulation names OSCP, CREST, or any particular certification. What exists is broader than that, and more useful. SEOJK 29/2022 romawi VII point 5 closes by stating that a third party's competence is evidenced among other things by certification and or recognition from an authorised body in Indonesia or abroad. Two things follow from that one sentence. Certification is recognised as evidence of competence, and recognition from a body abroad carries the same weight as recognition from an Indonesian one, which settles any doubt about foreign providers and foreign certifications. Pasal 30 ayat (2) huruf a of POJK 11/2022 adds qualifications and competence including the provider's personnel. Because the wording is "among other things", certification is not the only route. A track record in the same sector, redacted sample reports, and the names of the testers who will actually do the work are usually more convincing than a list of certificates with no names attached.

What happens if the testing is not done

Pasal 27 ayat (1) sets an administrative sanction of a written warning for a bank that breaches, among others, Pasal 23, Pasal 24, and Pasal 25 ayat (1). Where the requirement is still not met after that warning, ayat (2) escalates to a ban on issuing new bank products, suspension of certain business activities, and or a downgrade of the governance factor in the bank's soundness rating. There is no fine in that article.

For the scope, method, and report contents of application testing, see web and application penetration testing. For timeline planning, see how long a penetration test takes, and for the wider picture of bank testing obligations, pentest requirements for Indonesian banks.

References

  1. OJK Regulation No. 11/POJK.03/2022 on Information Technology Implementation by Commercial Banks, BPK RI regulation database. Pasal 23 to 27 govern cyber security testing and its sanctions, Pasal 29 to 32 govern the use of IT service providers, and Pasal 35 governs the placement of electronic systems.
  2. SEOJK No. 29/SEOJK.03/2022 on Cyber Resilience and Security for Commercial Banks, OJK, in force 27 December 2022 (full text). Romawi VII point 2 places the penetration test in the vulnerability-analysis stream and makes it mandatory for banks with online services; point 5 provides that testing may be run in-house or through a third party, and how that party's competence is evidenced.
WhatsApp