Background: ATMs and EDCs remain critical infrastructure components within Indonesia’s national payment system. However, their extensive utilization exposes commercial banks to various technological, operational, human, physical, and third-party risks. Despite recurring incidents comprehensive studies that formulate ATM and EDC risk scenarios and corresponding control measures within the Indonesian banking context remain limited. Objective: This study formulates risk scenarios and corresponding control measures for ATM and EDC electronic banking channels in Indonesian commercial banks. Methods: A structured literature review was conducted using six academic databases: Google Scholar, ScienceDirect, ResearchGate, Scopus, Wiley Online Library, and MDPI. The identified risks were analyzed using the ISACA Risk IT Framework and mapped to the NIST Cybersecurity Framework (CSF) 2.0 and ISO/IEC 27001:2022 standards. The proposed model was validated by six Subject Matter Experts (SMEs) with expertise in banking operations, IT risk management, information security, and payment systems using a 1–5 Likert scale. Results: The study identified 25 risk scenarios across six categories and formulated 25 consolidated control measures. Each scenario links risk sources or threat actors, risk events, potential impacts, and corresponding controls. The controls were classified as preventive, detective, and corrective measures and mapped across the people, process, and technology dimensions. Expert validation produced an average score of 4.13/5.00 (83%), indicating a high level of acceptance. Conclusion: As a proposed model derived from a systematic literature review and expert validation, this study provides a structured reference framework for risk management practitioners and policymakers in Indonesian commercial banking institutions.