Risk-based, data-driven, board-led: The new era of internal control in banking

Bangladesh Bank’s July 2026 “Guidelines on Internal Control Management System in Banks” reflects an important regulatory milestone for the country’s financial sector.
This comprehensive guideline goes beyond checklist regulation to reframe how banks should manage governance, risk, compliance and assurance in an era of rapid technological change, complex products, and heightened global expectations.
If effectively implemented, this guideline will raise the resilience, transparency and public trust of our banking system — but success will depend on translating detailed instructions into sustained cultural, capability and technological shifts within banks.
A modern, holistic internal control framework
At its core the guideline reasserts a simple truth: robust internal control is not an optional add-on, but the foundation of safe, sound banking.
The preamble says that Internal Control Management System (ICMS) as essential to depositor protection and financial stability.
The document formally adopts the Three Lines of Defense model clarifying responsibilities: business units own controls and risks; compliance and risk functions, set frameworks and monitor; internal audit provides independent assurance.
This formalization is very important: unclear accountabilities have often been the root of recurring failures.
Raising the bar for governance and assurance
The Guidelines strengthen board and audit committee duties. Boards are charged with oversight, approving ICMS structures and regularly reviewing effectiveness.
The Audit Committee is prescribed clear membership, meeting frequency and responsibilities. That emphasis on board-level accountability is important — effective control begins at the top.
The internal audit function receives pronounced protection and elevation.
The Guidelines require internal audit independence, a formal charter, direct access to the Audit Committee, and a Quality Assurance and Improvement Program (QAIP) with external assessments every five years.
These moves align internal assurance with international IIA standards and the Basel Core Principles (referred in the preamble), and will make internal audit a credible, value-adding third line — provided banks resource and staff it properly.
From static controls to risk-based, technology-enabled supervision
A remarkable strength of the Guidelines is the shift from box-ticking to risk-based and continuous assurance.
The Risk-Based Internal Audit (RBIA) model requires dynamic, prioritized audit plans that respond to emerging threats.
Complementing this is a sophisticated monitoring architecture— departmental control checklists, Quarterly Operations Reports, Loan Documentation Checklists, concentration dashboards, trade-based money-laundering analyzers, VaR and limit-breach systems, and IT/cyber dashboards.
These tools enable real-time detection and focused intervention, reducing the lag between incident and remediation.
Equally the guideline has given importance on explicitly incorporating data analytics, CAATs and virtual/remote audit techniques which reflects a practical, modern recognition that auditors and compliance cannot rely solely on physical presence or manual checks in a digital, distributed banking environment.
However, the Guidelines also sensibly attach strict data security, privileged-access and evidence-preservation requirements to virtual methods, acknowledging the new risks that come with remote auditing.
Strengthening compliance, anti-fraud and Shariah assurance
The Guidelines significantly expand compliance expectations such as: a dedicated Compliance Function, annual Compliance Risk Assessments, a risk-based Compliance Monitoring Plan, regulatory change management, and role-based training.
This institutionalizes compliance as a proactive, enterprise-wide discipline rather than a reactive reporting chore.
For Islamic banking, the document introduces an organized Shariah Audit framework with risk ratings, defined scopes, and clear reporting lines to SSCs and boards.
This is a good move that balances faith-based obligations and regulatory rigour — vital for protecting depositors and preserving market trust.
Forensic audit: A dynamic value addition
Forensic audit is a specialized, investigative examination of financial records and transactions designed to detect, analyze, and produce evidence of fraud, embezzlement, money laundering, or other economic offences; it goes beyond routine financial or internal audits by using in-depth substantive techniques, digital forensics, and legal-grade evidence collection to quantify losses and identify perpetrators, often supporting legal action.
The Guidelines emphasize that forensic audits are appropriate for large advances, NPAs, wilful default cases and major frauds, require higher professional skepticism and technical capability (including computer forensics), and may be performed by internal teams or external specialists (with Bangladesh Bank approval) to establish facts, trace illicit flows, access control breakdowns, and recommend remedial and disciplinary measures.
Practical enforcement and consequences
The Guidelines has also given emphasis on enforcement: Non-compliance may trigger punitive action under the Bank Company Act.
That carrot-and-stick approach is necessary: rules alone cannot change behaviour without clear consequences and supervisory follow-through.
Implementation challenges — and the path forward
The Guidelines are ambitious. Their success will hinge on five practical imperatives: Resourcing and capability building. Many banks must deepen bench strength in internal audit, compliance, MIS and IT security.
The document calls for professional qualifications and training. Regulators and industry bodies should support bank-level capability building specially on forensic accounting through targeted training, certification incentives, and technical assistance.
Technology investment. Real-time dashboards, VaR systems, data analytics, and secure remote audit platforms require significant IT upgrades and disciplined data governance. Banks must prioritize secure, auditable architectures and ensure audit/compliance units have appropriate system access.
Cultural change. The Guidelines emphasize “tone from the top”. Boards and senior management must visibly support ICMS, reward ethical behaviour, and avoid short-term incentives that undermine controls.
Proportionality. Not every requirement will be appropriate to every bank. The Guidelines rightly allow proportional implementation based on size, complexity and risk profile.
Smaller banks will need practical, scaled approaches and supervisory guidance on proportionality.
Supervisory partnership. Bangladesh Bank must pair expectations with pragmatic, phased supervisory support — helping banks transition through capability assessments, pilot programs, and clear timelines rather than only punitive measures.
Bangladesh Bank’s ICMS Guidelines are forward-looking and comprehensive. They reflect modern supervisory thinking — embedding risk-based assurance, elevating internal audit and compliance, embracing technology, and setting clear governance expectations.
If banks invest in people, systems and culture — and if the regulator supports a phased, collaborative implementation — these Guidelines can materially strengthen the integrity, resilience and reputation of Bangladesh’s banking system.
The work ahead is substantial, but so too is the opportunity: a banking sector better able to protect depositors, manage risks, and underpin sustainable economic growth.
(The author is Managing Director & CEO of NRBC Bank and fellow cost & management accountant)
