Eldik Bank, a financial institution based in Kyrgyzstan, has officially obtained the ISO 27001:2022 certification for its Information Security Management System (ISMS). The certification validates the bank's adherence to internationally recognized standards for protecting sensitive customer and financial data.
Eldik Bank (Элдик Банк) has officially achieved ISO 27001:2022 certification, a globally recognized standard for Information Security Management Systems (ISMS). The announcement, dated September 26, 2026, marks a significant milestone for the Kyrgyz financial institution in its ongoing effort to safeguard customer information and strengthen operational resilience against cyber threats.
Eldik Bank underwent a comprehensive audit of its information security policies, procedures, and controls by an accredited certification body. The successful completion of this audit resulted in the issuance of the ISO 27001:2022 certificate, confirming that the bank's ISMS meets the rigorous requirements of the latest version of the standard. The ISO 27001:2022 revision, released in October 2022, introduced updated controls addressing modern threats such as cloud security, threat intelligence, and data leakage prevention.
The certification covers the bank's core banking operations, data processing activities, and supporting IT infrastructure. By aligning with the updated 2022 framework, Eldik Bank demonstrates that its security controls have been reviewed and enhanced to meet contemporary threat landscapes, rather than relying on outdated practices from the previous 2013 version of the standard.
The certification directly impacts several stakeholder groups:
For a financial institution, ISO 27001:2022 certification carries substantial compliance weight. The standard requires implementing 93 controls across four themes: organizational, people, physical, and technological. Eldik Bank must now maintain continuous compliance through annual surveillance audits and a full recertification audit every three years.
The 2022 revision places stronger emphasis on:
Financial institutions and other organizations seeking ISO 27001:2022 certification, or looking to strengthen their information security posture, should consider the following steps:
1. Conduct a gap analysis: Compare current security controls against ISO 27001:2022 requirements, paying particular attention to new controls added in the 2022 revision. 2. Secure executive sponsorship: ISMS implementation requires sustained leadership commitment and resource allocation from the board and C-suite. 3. Define ISMS scope: Clearly document which business processes, systems, and locations will be covered under the certification. 4. Perform risk assessment: Identify information security risks, evaluate their potential impact, and select appropriate treatment options. 5. Implement controls and documentation: Develop policies, procedures, and records that demonstrate compliance with Annex A controls. 6. Train employees: Security awareness training ensures staff understand their roles in maintaining the ISMS. 7. Engage a certified auditor: Select an accredited certification body to perform the Stage 1 and Stage 2 audits leading to certification.
Achieving ISO 27001:2022 certification is not a one-time event but the beginning of an ongoing security commitment. Eldik Bank must now maintain its ISMS through regular internal audits, management reviews, and continuous improvement cycles. The bank's leadership has signaled that this certification is part of a broader digital transformation strategy aimed at delivering secure, modern banking services to the Kyrgyz market.
As cyber threats targeting financial institutions continue to grow in sophistication, certifications like ISO 27001:2022 provide a structured framework for resilience. Eldik Bank's achievement sends a clear message to the regional banking community: international security standards are attainable and essential for building customer trust in the digital age.
ISO 27001:2022 is an international standard published by ISO and IEC that specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). Certification confirms an organization has independently verified security controls meeting global best practices.
ISO 27001:2022 reduced 114 controls to 93 controls organized into four themes (organizational, people, physical, technological) and added 11 new controls addressing cloud security, threat intelligence, data masking, and ICT readiness for business continuity.
ISO 27001:2022 certification is valid for three years, subject to annual surveillance audits by the certification body. A full recertification audit is required at the end of each three-year cycle to maintain certification.
Banks in Kyrgyzstan pursue ISO 27001 certification to demonstrate international security standards compliance to customers, regulators, and international partners, reducing due diligence friction and building trust in cross-border financial operations.
Key benefits include reduced risk of data breaches, regulatory compliance alignment, enhanced customer trust, competitive differentiation, improved incident response capabilities, and streamlined vendor security assessments through a recognized international certification.
PoliWriter creates all the policies and documentation you need for compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free