News Flash

DHAKA, July 21, 2026 (BSS) - Bangladesh Bank (BB) has issued comprehensive
Guidelines on the Internal Control Management System (ICMS) for all scheduled
banks, replacing the decade-old Internal Control and Compliance (ICC)
guidelines introduced in 2016.
The new framework, issued by the Banking Regulation and Policy Department-2
(BRPD-2) under Section 45 of the Bank Company Act, 1991 (amended up to 2023),
took effect on July 21, 2026, with full implementation required by December
31, 2026, said a press release.
The central bank said the revised framework establishes minimum regulatory
standards for internal control and governance while requiring banks to
develop more advanced systems based on their individual risk profiles.
The previous guidelines issued through BRPD Circulars No. 03 and 06 of 2016
have been withdrawn.
The ICMS framework is designed to support Bangladesh Bank's transition to
Risk-Based Supervision (RBS) by shifting supervisory focus from compliance-
based monitoring to a forward-looking assessment of risks. Under the new
approach, banks must evaluate business risk, control risk and detection risk
while expanding internal audit coverage beyond financial matters to include
ethical, technological, environmental, social and governance (ESG) risks.
The guidelines identify three primary objectives of internal control:
achieving operational efficiency and safeguarding assets, ensuring reliable
financial and non-financial reporting, and maintaining compliance with
applicable laws, regulations and internal policies.
Bangladesh Bank has also formally adopted the Three Lines of Defense model.
Business units will serve as the first line by owning and managing risks
through day-to-day controls.
Compliance and risk management functions will constitute the second line by
independently overseeing and challenging business operations. Internal audit
will act as the third line, providing independent assurance to the Board of
Directors and the Audit Committee.
The framework assigns overall responsibility for establishing and reviewing
ICMS to the Board of Directors, which must conduct an annual assessment of
the system's effectiveness and disclose the results to shareholders.
The Audit Committee of the Board may have a maximum of five members,
including at least two independent directors. Digital banks must include at
least one ICT expert on the committee.
Bangladesh Bank also stipulated that only the Audit Committee may evaluate
the performance of the Head of Internal Audit, and management cannot alter
that appraisal without the committee's approval.
Senior management has been tasked with implementing and monitoring the
effectiveness of the internal control system and submitting annual
certification to the Board.
The Head of Internal Audit must attend all senior management meetings as an
observer to strengthen independent oversight.
The guidelines strengthen the independence of key control functions. The Head
of Internal Audit must report directly to the Audit Committee, remain no more
than two reporting levels below the Chief Executive Officer and have
unrestricted access to all records and personnel. Similarly, the Head of
Compliance must operate independently from business units, report significant
findings directly to the Audit Committee or Board where necessary and also
remain within two reporting levels of the CEO.
The Internal Audit Function must be organized into on-site audit, off-site
surveillance and a Quality Assurance and Improvement Program (QAIP).
Meanwhile, the compliance function will be required to conduct annual
Compliance Risk Assessments and prepare risk-based monitoring plans.
Bangladesh Bank has introduced detailed reporting and monitoring
requirements. Departmental Control Function Checklists and reports on single-
borrower exposure, Value-at-Risk (VaR) and trade-based money laundering
(TBML) alerts must be submitted by the fifth day of the following month.
Quarterly Operations Reports and Loan Documentation Checklists must be
submitted by the tenth day following the end of each quarter.
The framework also encourages the adoption of advanced data analytics and
automated monitoring tools, including TBML Red Flag Analyzers, real-time VaR
and limit breach systems for treasury operations, and cyber-security control
effectiveness dashboards.
For Islamic banks, the guidelines require dedicated Shariah audits, with
high-risk business units subject to audits twice a year.
Any non-halal income must be transferred for corporate social responsibility
purposes. Banks must also establish confidential whistleblower mechanisms and
protect whistleblowers from retaliation.
The new guidelines distinguish forensic audits from traditional financial
audits, describing forensic audits as specialized investigations intended to
identify fraud, bribery, willful default and quantify financial losses for
legal proceedings. Banks are also required to develop institution-specific
Information System Audit manuals focusing on cyber risks, ICT infrastructure
and data privacy.
Bangladesh Bank further directed that unresolved disagreements between senior
management and ICMS functions be referred to the Board of Directors. Any
irregularities involving the Board or the Managing Director/Chief Executive
Officer must be reported confidentially and directly to BRPD-2.
The central bank warned that banks failing to comply with the new ICMS
framework may face regulatory action under Section 109(11) of the Bank
Company Act, while the willful submission of false information may attract
penalties under Section 109(2).
All scheduled banks have been instructed to complete the required
organizational restructuring and fully comply with the guidelines by December
31, 2026.