Wed, 22 July 2026
The Daily Ittefaq

BB issues new ICMS guidelines for banks

Update : 21 Jul 2026, 19:36

Bangladesh Bank (BB) has issued comprehensive Guidelines on the Internal Control Management System (ICMS) for all scheduled 
banks, replacing the decade-old Internal Control and Compliance (ICC) guidelines introduced in 2016. 

The new framework, issued by the Banking Regulation and Policy Department-2 (BRPD-2) under Section 45 of the Bank Company Act, 1991 (amended up to 2023), took effect on July 21, 2026, with full implementation required by December 31, 2026, said a press release.

The central bank said the revised framework establishes minimum regulatory standards for internal control and governance while requiring banks to develop more advanced systems based on their individual risk profiles. 

The previous guidelines issued through BRPD Circulars No. 03 and 06 of 2016 have been withdrawn.

The ICMS framework is designed to support Bangladesh Bank's transition to Risk-Based Supervision (RBS) by shifting supervisory focus from compliance-based monitoring to a forward-looking assessment of risks. Under the new approach, banks must evaluate business risk, control risk and detection risk while expanding internal audit coverage beyond financial matters to include ethical, technological, environmental, social and governance (ESG) risks.

The guidelines identify three primary objectives of internal control: 
achieving operational efficiency and safeguarding assets, ensuring reliable financial and non-financial reporting, and maintaining compliance with applicable laws, regulations and internal policies.

Bangladesh Bank has also formally adopted the Three Lines of Defense model. Business units will serve as the first line by owning and managing risks through day-to-day controls. 

Compliance and risk management functions will constitute the second line by independently overseeing and challenging business operations. Internal audit will act as the third line, providing independent assurance to the Board of Directors and the Audit Committee.

The framework assigns overall responsibility for establishing and reviewing ICMS to the Board of Directors, which must conduct an annual assessment of the system's effectiveness and disclose the results to shareholders. 

The Audit Committee of the Board may have a maximum of five members, including at least two independent directors. Digital banks must include at least one ICT expert on the committee. 

Bangladesh Bank also stipulated that only the Audit Committee may evaluate the performance of the Head of Internal Audit, and management cannot alter that appraisal without the committee's approval.

Senior management has been tasked with implementing and monitoring the effectiveness of the internal control system and submitting annual certification to the Board. 

The Head of Internal Audit must attend all senior management meetings as an observer to strengthen independent oversight.

The guidelines strengthen the independence of key control functions. The Head of Internal Audit must report directly to the Audit Committee, remain no more than two reporting levels below the Chief Executive Officer and have unrestricted access to all records and personnel. Similarly, the Head of Compliance must operate independently from business units, report significant findings directly to the Audit Committee or Board where necessary and also remain within two reporting levels of the CEO.

The Internal Audit Function must be organized into on-site audit, off-site surveillance and a Quality Assurance and Improvement Program (QAIP). Meanwhile, the compliance function will be required to conduct annual Compliance Risk Assessments and prepare risk-based monitoring plans.

Bangladesh Bank has introduced detailed reporting and monitoring requirements. Departmental Control Function Checklists and reports on single-borrower exposure, Value-at-Risk (VaR) and trade-based money laundering (TBML) alerts must be submitted by the fifth day of the following month. 

Quarterly Operations Reports and Loan Documentation Checklists must be submitted by the tenth day following the end of each quarter.

The framework also encourages the adoption of advanced data analytics and automated monitoring tools, including TBML Red Flag Analyzers, real-time VaR and limit breach systems for treasury operations, and cyber-security control effectiveness dashboards.

For Islamic banks, the guidelines require dedicated Shariah audits, with high-risk business units subject to audits twice a year. 

Any non-halal income must be transferred for corporate social responsibility purposes. Banks must also establish confidential whistleblower mechanisms and protect whistleblowers from retaliation.

The new guidelines distinguish forensic audits from traditional financial audits, describing forensic audits as specialized investigations intended to identify fraud, bribery, willful default and quantify financial losses for legal proceedings. Banks are also required to develop institution-specific Information System Audit manuals focusing on cyber risks, ICT infrastructure and data privacy.

Bangladesh Bank further directed that unresolved disagreements between senior management and ICMS functions be referred to the Board of Directors. Any irregularities involving the Board or the Managing Director/Chief Executive Officer must be reported confidentially and directly to BRPD-2.

The central bank warned that banks failing to comply with the new ICMS framework may face regulatory action under Section 109(11) of the Bank Company Act, while the willful submission of false information may attract penalties under Section 109(2). 

All scheduled banks have been instructed to complete the required organizational restructuring and fully comply with the guidelines by December 31, 2026.

More on this topic

More on this topic