). The new Methodology, adopted by the NBRM on 24 April 2025, requires from the banks to (i) establish and implement an IT strategy aligned with their business strategy, including risk assessment and regular revision; (ii) to maintain ? comprehensive IT risk management system including documentation, risk identification, classification, evaluation, and mitigation measures, with annual or more frequent reassessment if needed; (iii) to develop and regularly update information security policies and controls to ensure the confidentiality, integrity, and availability of IT assets and critical data; (iv) to perform regular testing of information system security, including independent assessments and real-world scenarios, and to update security measures based on the results ; (v) to define and regularly review access controls; (vi) to establish procedures for managing IT incidents, as well as comprehensive incident response and reporting processes; (vii) to establish business continuity management processes, in order to guarantee uninterrupted provision of IT services, including backup, disaster recovery, and regular impact analysis of IT interruptions; (viii) to cover risk management processes for use of external IT service providers, ensuring compliance with all security standards and proper data protection; and (ix) to implement continuous employee training in information security awareness at least once per year.
Additional comments regarding the legal situation for online-banking services or what FinTech’s must be aware of in this business area
The Strategy for Financial Education and Financial Inclusion of the Republic of North Macedonia, 2021-2025 was adopted, whereas it is envisaged that measures in relation to a legal framework for protection of consumers in the area of finance are required.
Economic conditions
Market size for online-banking services and biggest companies in this business area
The banking sector in North Macedonia has been consolidating. The biggest banks by assets, as of 31 December 2024, are Komercijalna Banka, Stopanska Banka and NLB Banka, whereas all three (3) banks exceed the amount of MKD 100 billion of assets. Percentage wise, Komercijalna Banka has 21,66%, Stopanska Banka has 17,46%, NLB Banka has 15,93%, followed by Halk banka with 13,83% and Sparkasse Banka with 13,04%. Banks that have less than 10% of market participation are Prokredit Banka, Univerzalna Investiciona Banka, Stopanska Banka AD Bitola, Razvojna Banka na Severna Makedonija, Centralna Kooperativna Banka, TTK Banka, Silk Roud Banka and Kapital Banka.
Additional comments regarding the economic situation for online-banking services or what FinTech’s must be aware of in this business area
The use of online-banking services is on the rise in North Macedonia. In 2020, only 15,2% of the population used online-banking services, while during 2024, the number of people using online-banking services reached approx. 42%. Overall, it is expected for this trend to continue to rise.