Annex - Templates for notifications required under category 1 and category 2 obligations

Annex Email: HKMA E-mail Alert of 03 June 2026 (05:00 p.m. HKT)

Document Information

Title: Annex - Templates for notifications required under category 1 and category 2 obligations

Type: Annex

URL: https://brdr.hkma.gov.hk/eng/doc-ldg/docId/20260527-26-EN

Email Received: 2026-06-03 19:11

Summary Created: 2026-06-03 14:00

English Summary
Quick section switch
Management Summary
  • Purpose / Background: This document provides standardized notification templates for Authorized Institutions (AIs) designated as Critical Infrastructure (CI) operators under the *Protection of Critical Infrastructures (Computer Systems) Ordinance*. It facilitates mandatory regulatory reporting to the Monetary Authority (MA).
  • One-line conclusion: Designated AIs must use these prescribed forms to report operational changes, security management appointments, and material changes to computer systems via secure ICLNet email.
  • Key Changes:
  • Standardized notification templates for three specific regulatory triggers: Operator Changes (s.20), Appointment of Security Unit Supervisors (s.21), and Material Changes to Critical Computer Systems (s.22).
  • Formalized requirement for cross-copying the Technology Risk Team and Case Management Team at the HKMA.
  • Mandatory requirement to attach documentary evidence for personnel appointments and risk assessment documentation for system changes.
  • Implementation of a formal "Declaration" section requiring sign-off by the supervisor of the computer-system security management unit.
  • Key Dates / Deadlines: Submissions must be made within the specific statutory timeframes stipulated under sections 20(1), 21(4/6), and 22(1) of the Ordinance.
  • Applicability / Impact scope: All Authorized Institutions (AIs) designated by the MA as operators of critical computer systems.
  • Recommended management actions:
  • Update internal compliance workflows to incorporate these specific forms for all statutory notifications.
  • Ensure the "supervisor of the computer-system security management unit" is clearly identified and authorized to validate these filings.
  • Establish a secure communication channel via ICLNet for all regulatory filings directed to pcicso_ai@hkma.iclnet.hk.
  • Integrate the requirement for accompanying risk assessment documentation and system updates into the change management lifecycle.
  • Map internal reporting triggers to the specific sections of the Ordinance to ensure adherence to statutory deadlines.
Detailed Summary

1) Document Overview
The document serves as the official template suite for Designated AIs to fulfill their notification obligations under the *Protection of Critical Infrastructures (Computer Systems) Ordinance*. It ensures uniformity in data collection for critical oversight functions.

2) Main Requirements

  • Submission Protocol: All forms must be submitted via ICLNet secure email to pcicso_ai@hkma.iclnet.hk.
  • Copying Recipients: Submissions must be copied to the AI’s usual supervisory contact, the Technology Risk Team, and the Case Management Team.
  • Verification: Every form requires a declaration confirming the information is valid and reviewed by the supervisor of the computer-system security management unit.

3) Key Notification Areas

  • Operator Change (s.20): Reports changes such as M&A, disposal of business, or restructuring, including impact assessments on essential services.
  • Security Supervisor Appointment (s.21): Reports the identity, qualifications, and experience of the employee supervising the security management unit (documentary proof required).
  • Material Changes (s.22): Details changes to the design, configuration, or security of Critical Computer Systems (CCS), including platform migrations, major upgrades, or integration changes.

4) Important Dates & Transition
Submissions are triggered by the events defined in the Ordinance. AIs must adhere to the specific notification windows stated in sections 20, 21, and 22 of the Ordinance.

5) Impact and Risks

  • Operational: Increased administrative burden for managing documentation during system updates.
  • Compliance: High risk of non-compliance if statutory timelines are missed; requires strict alignment between IT change management and the Compliance/Legal departments.
  • Data/Reporting: Requires maintenance of updated system documentation to support submissions.

6) Compliance Action Checklist

  • [ ] Configure ICLNet accounts for secure submission.
  • [ ] Maintain a repository of "documentary proof" for security personnel appointments.
  • [ ] Align internal IT Change Management processes with the "Material Change" criteria (Section B, Form 3).
  • [ ] Brief the "supervisor of the computer-system security management unit" on their new declaration responsibilities.

7) Appendices/Attachments Summary
The document consists of three specific reporting templates:

  1. Form for Notifying an Operator Change: Captures business structural changes and their impact on essential services.
  2. Form for Notifying Appointment of Employee Supervising Computer-System Security Management Unit: Collects professional credentials and experience for key security personnel.
  3. Form for Notifying Material Changes to Certain Computer Systems: Details technical modifications to CCS, requiring supporting risk assessments and updated system documentation.
中文摘要
快速切換摘要區塊
管理層摘要
  • 目的/背景 配合《保護關鍵基礎設施(電腦系統)條例》(下稱「條例」),為獲金管局(MA)指定為關鍵基礎設施營運者(Designated AI)的認可機構,提供法定的通知表格範本,以履行相關合規申報義務。
  • 一句話結論 當涉及營運者變更、網絡安全主管任命或關鍵電腦系統(CCS)重大變更時,認可機構必須使用指定格式表格,透過安全電子郵件渠道向金管局匯報。
  • 關鍵變更
  1. 確立了針對「營運者變更」、「安全主管任命」及「CCS 重大變更」的三類標準化匯報格式。
  2. 強制規定所有申報必須通過 ICLNet 安全郵件系統提交。
  3. 要求申報時須同時抄送至相關監督團隊(技術風險組及個案管理組)。
  4. 申報內容需由機構內部電腦系統安全管理部門主管審核,並作出正式聲明。
  5. 重大變更申報需一併提交相關風險評估及更新後的系統文檔。
  • 重要日期 / 截止日 需嚴格遵守《條例》第 20、21 及 22 條規定的法定時限(具體時限依據《條例》執行)。
  • 適用對象 / 影響範圍 被金管局指定為「關鍵基礎設施營運者」的所有認可機構(Designated AI)。
  • 管理層建議行動
  1. 將此套表格納入機構的「電腦系統安全管理計劃」(Computer-system security management plan)。
  2. 確認相關表格的簽署授權機制,確保由合適的主管人員審核。
  3. 檢視並更新內部程序,確保涉及系統變更時,能及時收集風險評估報告及文檔附件。
  4. 確保負責技術風險的團隊熟悉 ICLNet 的提交流程及抄送要求。
  5. 建立內部追蹤清單,確保各類申報均在《條例》規定的法定時限內完成。
詳細摘要
  1. 文檔概述 本文件為《保護關鍵基礎設施(電腦系統)條例》下的三份標準申報表格,用於規範指定認可機構(Designated AI)在發生特定事件時,向金管局提供標準化數據。
  1. 主要要求
  • 提交渠道 必須使用 ICLNet 安全電郵發送至 pcicso_ai@hkma.iclnet.hk
  • 抄送要求 須同時抄送至機構所屬的金管局技術風險團隊及個案管理團隊。
  • 審核與聲明 所有表格須經「電腦系統安全管理單位」主管審核,並在提交時簽署符合條例的聲明。
  1. 關鍵變更與具體申報項目
  • 營運者變更(第 20 條) 需說明原因(如出售、合併、重組、清算)、對必要服務的影響對比(變更前後),以及新營運者的詳情。
  • 安全主管任命(第 21 條) 需提供受聘人的資格證明(專業資格、相關經驗)及任命生效日期,並附上證明文檔。
  • CCS 重大變更(第 22 條) 涵蓋 CCS 設計、配置、安全性或操作的重大變更,包括系統移除、新增或功能擴充。需提供變更技術細節、部署日期、影響分析及更新後的系統文檔。
  1. 重要日期與過渡安排
  • 各類通知的提交時限應嚴格參照《條例》第 20(1)、21(4)、21(6) 及 22(1) 條之規定。
  1. 對機構的影響與風險
  • 合規風險 未按時申報或提交不完整資料將直接違反條例。
  • 營運影響 機構需調整變更管理流程(Change Management),確保所有涉及 CCS 的系統變更在部署前即具備報備條件及風險評估文件。
  • IT 與資料風險 需妥善管理個人資料(依據 PICS 個人資料收集聲明),處理相關受影響人員的存取與更正權請求。
  1. 合規動作清單(Checklist)
  • [ ] 確定觸發條例申報義務的事件類別。
  • [ ] 填寫對應的指定表格。
  • [ ] 完成內容審核,由主管簽署聲明。
  • [ ] 準備佐證文件(如風險評估報告、專業資格證明)。
  • [ ] 透過 ICLNet 發送郵件,並正確抄送相關團隊。
  • [ ] 存檔確認郵件及提交紀錄。
  1. 附件/附錄摘要
  • 本文檔包含三類特定表單: 營運者變更通知表(頁 1-2)、安全主管任命通知表(頁 3-4)、CCS 重大變更通知表(頁 5-7)。
  • 這些表格均包含《個人資料收集聲明》(PICS),明確規範金管局及相關監管機構處理個人資料之權限與用途。