Pakistan — Banking
SBP Enterprise Technology Governance & Risk Management (ETGRM) Compliance
The State Bank of Pakistan's technology governance framework applies to every commercial bank, Islamic bank, development finance institution and microfinance bank it supervises. We assess where you stand against it and what it will take to close the gap.
What the framework requires
The State Bank of Pakistan issued its Enterprise Technology Governance and Risk Management Framework for Financial Institutions under BPRD Circular No. 05 of 2017. It draws on established international standards for technology governance, risk management and cyber security, and applies across commercial banks including public and private sector banks, Islamic banks, development finance institutions and microfinance banks.
Critically, the framework is explicitly not one-size-fits-all. Implementation is expected to be risk-based and proportionate to the size, nature and complexity of each institution's operations. In practice this means a supervisor will assess whether your implementation is defensible for your risk profile — not whether you have ticked every clause identically to a larger peer.
Senior management is required to monitor implementation on an ongoing basis, and the Board of Directors is required to review the implementation process on a quarterly basis. That board-level cadence is one of the most commonly missed obligations we encounter.
- Technology governance — board and senior management oversight, organisational structure and accountability.
- Information security — the security programme, controls and monitoring.
- IT service delivery and operations.
- System acquisition, development and implementation.
- Business continuity and disaster recovery.
- IT audit — including audit scope, reporting methodology and post-closure monitoring.
Where institutions most often fall short
Based on the pattern of findings across this framework, the recurring weaknesses are less about missing technology and more about missing evidence and governance discipline.
- Board review of implementation happening annually, or informally, rather than quarterly with a documented record.
- A technology risk register that exists but is not reconciled to the enterprise risk framework or escalated to the board.
- IT audit coverage that has not been risk-assessed, so the same low-risk areas are audited repeatedly while material areas go untouched.
- Post-closure monitoring of audit findings not evidenced — findings marked closed without validation.
- Outsourcing and third-party technology arrangements governed by contract but not by ongoing monitoring.
- Business continuity recovery objectives stated in policy but never validated against actual recovery capability.
- Segregation of duties gaps in the core banking application, particularly around privileged and emergency access.
What the framework covers
How we approach the assessment
We map every requirement in the framework to a control objective and a specific evidence expectation, then test. The output is a requirement-by-requirement position — compliant, partially compliant, or non-compliant — with the evidence we saw, the gap, and what closure requires.
Where the framework allows proportionality, we assess whether your interpretation is defensible for your institution's size and risk profile, and we say so explicitly. A finding that says "you have not implemented control X" is unhelpful if control X was never proportionate for you. What matters is whether you can justify the position to a supervisor.
Supporting an SBP inspection
We also support institutions responding to inspection observations — helping structure the management response, validating that remediation actually closes the observation, and providing independent confirmation before you report closure. We do not represent institutions before the regulator; we provide the assurance work that underpins what you tell them.
How the engagement runs
-
1
Requirement mapping
Map every framework requirement to a testable control objective and defined evidence expectation.
-
2
Proportionality assessment
Establish what implementation is defensible given your size, complexity and risk profile.
-
3
Evidence gathering
Collect and review documentation, board minutes, registers and system configuration.
-
4
Testing
Test control operation across the period, not just at a point in time.
-
5
Gap rating
Rate each requirement with evidence and a defined closure condition.
-
6
Board reporting
Report in a form that supports the quarterly board review the framework requires.
What you receive
Primary source
Frequently asked questions
Related services
Not sure this is the framework that binds you?
Six questions, ninety seconds, runs in your browser. It will tell you which frameworks apply and why.
Request a proposal