
Bangladesh Bank (BB) has issued comprehensive Guidelines on the Internal Control Management System (ICMS) for all scheduled banks, replacing the decade-old Internal Control and Compliance (ICC) guidelines introduced in 2016.
The new framework, issued by the Banking Regulation and Policy Department-2 (BRPD-2) under Section 45 of the Bank Company Act, 1991 (amended up to 2023), took effect on July 21, 2026, with full implementation required by December 31, 2026, said a press release.
The central bank said the revised framework establishes minimum regulatory standards for internal control and governance while requiring banks to develop more advanced systems based on their individual risk profiles.
The previous guidelines issued through BRPD Circulars No. 03 and 06 of 2016 have been withdrawn.
The ICMS framework is designed to support Bangladesh Bank's transition to Risk-Based Supervision (RBS) by shifting supervisory focus from compliance-based monitoring to a forward-looking assessment of risks. Under the new approach, banks must evaluate business risk, control risk and detection risk while expanding internal audit coverage beyond financial matters to include ethical, technological, environmental, and social and governance (ESG) risks.
The guidelines identify three primary objectives of internal control: achieving operational efficiency and safeguarding assets, ensuring reliable financial and non-financial reporting, and maintaining compliance with applicable laws, regulations and internal policies.
Bangladesh Bank has also formally adopted the Three Lines of Defense model. Business units will serve as the first line by owning and managing risks through day-to-day controls.
Compliance and risk management functions will constitute the second line by independently overseeing and challenging business operations. Internal audit will act as the third line, providing independent assurance to the Board of Directors and the Audit Committee.
The framework assigns overall responsibility for establishing and reviewing ICMS to the Board of Directors, which must conduct an annual assessment of the system's effectiveness and disclose the results to shareholders.
The Audit Committee of the Board may have a maximum of five members, including at least two independent directors. Digital banks must include at least one ICT expert on the committee.
Bangladesh Bank also stipulated that only the Audit Committee may evaluate the performance of the Head of Internal Audit, and management cannot alter that appraisal without the committee's approval.
Senior management has been tasked with implementing and monitoring the effectiveness of the internal control system and submitting annual certification to the Board.
The Head of Internal Audit must attend all senior management meetings as an observer to strengthen independent oversight.�"BSS