Bangladesh Bank has ordered all scheduled banks to overhaul their internal control systems by the end of the year, replacing decade-old compliance guidelines with a new governance framework aimed at strengthening risk management, internal audit and regulatory oversight in line with international standards.
Under the new framework, banks have been instructed to complete the necessary restructuring of their organisational arrangements by 31 December 2026 to comply with the newly introduced Guidelines on Internal Control Management System (ICMS) in Banks. The central bank has simultaneously withdrawn the Internal Control and Compliance (ICC) guidelines issued in 2016.
Bangladesh Bank issued the directive through a circular on Tuesday, saying the revised framework has been introduced to support the implementation of Risk-Based Supervision (RBS) by making banks’ internal control systems more comprehensive and up to date.
The new guidelines require banks to adopt an integrated Internal Control Management System, bringing together internal audit, compliance and risk management functions under a strengthened governance framework. The policy has been developed in line with internationally accepted standards and the Basel Core Principles for Effective Banking Supervision, with the objective of improving transparency, accountability and operational resilience across the banking sector.
As part of the reforms, banks will be required to implement the internationally recognised Three Lines of Defence model. Under this approach, business units will serve as the first line of defence by managing operational risks, compliance and risk management functions will provide independent oversight as the second line, while internal audit will independently assess the effectiveness of controls as the third line.
The framework also establishes separate organisational structures for the heads of Internal Audit and Compliance. Dedicated functions, including on-site audit, off-site surveillance, quality assurance, compliance monitoring, management information systems (MIS) and data analytics, have been incorporated to strengthen oversight and improve the early detection of operational and compliance risks.
In the preamble to the guidelines, Bangladesh Bank said an effective internal control management system is essential to safeguarding the stability and resilience of the banking sector amid growing technological transformation, increasingly complex financial products and evolving risk environments.







