Bank of Ireland hit with €24.5 million fine over IT failures
The bank failed to implement frameworks to ensure services continued in the event of IT disruption


Ireland’s Central Bank has fined the Bank of Ireland €24.5 million (£20.8 million) for IT failures that took over a decade to be appropriately recognised, addressed, and fixed.
The bank was found to have a failed to implement a robust framework to ensure continuity of service for customers in the event of significant IT disruption.
These deficiencies were repeatedly identified from 2008 onwards but, due to the bank's internal control failings, only began to be appropriately recognised and addressed in 2015, before being completed in 2019.
The Bank of Ireland has admitted five contraventions that occurred between 2008 and 2019, including failing to demonstrate an ability to ensure continuity of service in the event of significant IT disruption and failing to have effective internal controls to identify deficiencies in the IT service continuity framework.
It also admitted to failing to properly engage and oversee the management of third party IT service providers with respect to IT service continuity.
RELATED RESOURCE
How virtual desktop infrastructure enables digital transformation
Challenges and benefits of VDI
Firms and their boards are responsible for having an effective IT service continuity framework and associated internal controls, said the Central Bank. These are regarded as core parts of a company's operational resilience and will continue to be an area of focus as part of the Central Bank’s and the European Central Bank’s supervisory strategy.
“Today’s banks and financial services firms are wholly dependent on effective, reliable, and resilient IT systems,” said Seána Cunningham, the Central Bank’s director of Enforcement and Anti-Money Laundering. “It is vital that firms have a framework in place so that they can ensure continuity of critical IT services and minimise the impact of any significant disruption.”
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Cunningham said that significant IT disruptions could have a very serious impact on millions of customers who rely on ready access to their funds and services to keep their everyday lives and businesses moving.
She added that the extent and duration of the Bank of Ireland’s breaches were particularly serious given the ‘always-on’ nature of the services it provides and how pivotal IT is to the entirety of its business operations.
“Bank of Ireland fully acknowledges, and sincerely apologises for, each of these breaches which should not have arisen,” a spokesperson said to IT Pro. They added that to address the various issues, the bank has invested heavily in IT service continuity, including infrastructure and network upgrades, and enhanced testing, planning, and internal procedures.
The Central Bank determined the appropriate fine to be €35 million, which has been reduced by 30% to €24.5 million in accordance with a settlement discount scheme provided for in the Central Bank’s Administrative Sanctions Procedure.
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Better together
Whitepaper Achieve more with Windows 11 and Surface
By ITPro
-
Transforming the enterprise
Whitepaper With Intel and CDW
By ITPro
-
The top trends in money remittance
Whitepaper Tackling the key issues shaping the money remittance industry
By ITPro
-
How Kantar revamped its IT infrastructure after being sold off
Case Study Being acquired by a private equity firm meant Kantar couldn’t rely on its parent company’s infrastructure, and was forced to confront its technical shortcomings
By Rene Millman
-
Deutsche Bank wraps up Postbank IT integration after bug-laden migrations
News The IT merger is expected to generate annual savings of €300 million by 2025
By Daniel Todd
-
Analyzing the economic benefits of Dell Technologies with VMware Tanzu & Intel
Whitepaper ESG economic validation
By ITPro
-
Defra needs £726 million to modernize pervasive legacy IT issues
News A significant portion of IT systems are reportedly still in extended support or are fully unsupported
By Ross Kelly
-
Former TSB CIO fined £81,000 for botched IT migration
News It’s the first penalty imposed on an individual involved in the infamous migration project
By Ross Kelly