# Bangladesh Bank Introduces Updated ICMS Guidelines for Enhanced Banking Supervision

*Bangladesh Bank has issued comprehensive new Guidelines on the Internal Control Management System (ICMS) for all scheduled banks, replacing the decade-old Internal Control and Compliance (ICC) guidelines introduced in 2016.*

July 21, 2026 · business

## At a glance

- New ICMS guidelines replace decade-old ICC framework from 2016.
- Framework emphasizes Risk-Based Supervision and expanded internal audit coverage.
- Adoption of the Three Lines of Defense model for enhanced oversight.
- Detailed reporting and monitoring requirements introduced.

Bangladesh Bank (BB) has issued comprehensive Guidelines on the Internal Control Management System (ICMS) for all scheduled banks, replacing the decade-old Internal Control and Compliance (ICC) guidelines introduced in 2016. The new framework, issued by the Banking Regulation and Policy Department-2 (BRPD-2) under Section 45 of the Bank Company Act, 1991 (amended up to 2023), took effect on July 21, 2026, with full implementation required by December 31, 2026.

## Enhanced Risk Management Requirements

The revised framework establishes minimum regulatory standards for internal control and governance, requiring banks to develop more advanced systems based on their individual risk profiles. The new approach emphasizes Risk-Based Supervision (RBS), shifting the supervisory focus from compliance-based monitoring to a forward-looking assessment of risks. Banks must now evaluate business risk, control risk, and detection risk, while expanding internal audit coverage beyond financial matters to include ethical, technological, environmental, social, and governance (ESG) risks.

## Three Lines of Defense Model

Bangladesh Bank has formally adopted the Three Lines of Defense model. Business units serve as the first line, owning and managing risks through day-to-day controls. Compliance and risk management functions constitute the second line, independently overseeing and challenging business operations. Internal audit acts as the third line, providing independent assurance to the Board of Directors and the Audit Committee.

## Strengthened Independence and Oversight

The framework assigns overall responsibility for establishing and reviewing ICMS to the Board of Directors, which must conduct an annual assessment of the system's effectiveness and disclose the results to shareholders. The Audit Committee, which may have a maximum of five members including at least two independent directors, is tasked with evaluating the performance of the Head of Internal Audit. Digital banks must include at least one ICT expert on the committee. Senior management is responsible for implementing and monitoring the effectiveness of the internal control system and submitting annual certification to the Board.

## Detailed Reporting and Monitoring Requirements

Bangladesh Bank has introduced detailed reporting and monitoring requirements. Departmental Control Function Checklists and reports on single-borrower exposure, Value-at-Risk (VaR), and trade-based money laundering (TBML) alerts must be submitted by the fifth day of the following month. Quarterly Operations Reports and Loan Documentation Checklists must be submitted by the tenth day following the end of each quarter. The framework also encourages the adoption of advanced data analytics and automated monitoring tools.

## Sources

- BSS

---
Source: https://pulsetoday.com.bd/en/business/bangladesh-bank-new-icms-guidelines-for-banks
