Skip to content

Pakistan — Banking

SBP Enterprise Technology Governance & Risk Management (ETGRM) Compliance

The State Bank of Pakistan's technology governance framework applies to every commercial bank, Islamic bank, development finance institution and microfinance bank it supervises. We assess where you stand against it and what it will take to close the gap.

What the framework requires

The State Bank of Pakistan issued its Enterprise Technology Governance and Risk Management Framework for Financial Institutions under BPRD Circular No. 05 of 2017. It draws on established international standards for technology governance, risk management and cyber security, and applies across commercial banks including public and private sector banks, Islamic banks, development finance institutions and microfinance banks.

Critically, the framework is explicitly not one-size-fits-all. Implementation is expected to be risk-based and proportionate to the size, nature and complexity of each institution's operations. In practice this means a supervisor will assess whether your implementation is defensible for your risk profile — not whether you have ticked every clause identically to a larger peer.

Senior management is required to monitor implementation on an ongoing basis, and the Board of Directors is required to review the implementation process on a quarterly basis. That board-level cadence is one of the most commonly missed obligations we encounter.

  • Technology governance — board and senior management oversight, organisational structure and accountability.
  • Information security — the security programme, controls and monitoring.
  • IT service delivery and operations.
  • System acquisition, development and implementation.
  • Business continuity and disaster recovery.
  • IT audit — including audit scope, reporting methodology and post-closure monitoring.

Where institutions most often fall short

Based on the pattern of findings across this framework, the recurring weaknesses are less about missing technology and more about missing evidence and governance discipline.

  • Board review of implementation happening annually, or informally, rather than quarterly with a documented record.
  • A technology risk register that exists but is not reconciled to the enterprise risk framework or escalated to the board.
  • IT audit coverage that has not been risk-assessed, so the same low-risk areas are audited repeatedly while material areas go untouched.
  • Post-closure monitoring of audit findings not evidenced — findings marked closed without validation.
  • Outsourcing and third-party technology arrangements governed by contract but not by ongoing monitoring.
  • Business continuity recovery objectives stated in policy but never validated against actual recovery capability.
  • Segregation of duties gaps in the core banking application, particularly around privileged and emergency access.

What the framework covers

Board of Directors — quarterly review Senior management monitors implementation on an ongoing basis BPRD Circular No. 05 of 2017 · risk-based and proportionate Technology governance Information security IT service delivery System acquisition Business continuity IT audit
Six domains, under a board review the framework requires quarterly.

How we approach the assessment

We map every requirement in the framework to a control objective and a specific evidence expectation, then test. The output is a requirement-by-requirement position — compliant, partially compliant, or non-compliant — with the evidence we saw, the gap, and what closure requires.

Where the framework allows proportionality, we assess whether your interpretation is defensible for your institution's size and risk profile, and we say so explicitly. A finding that says "you have not implemented control X" is unhelpful if control X was never proportionate for you. What matters is whether you can justify the position to a supervisor.

Supporting an SBP inspection

We also support institutions responding to inspection observations — helping structure the management response, validating that remediation actually closes the observation, and providing independent confirmation before you report closure. We do not represent institutions before the regulator; we provide the assurance work that underpins what you tell them.

How the engagement runs

  1. 1

    Requirement mapping

    Map every framework requirement to a testable control objective and defined evidence expectation.

  2. 2

    Proportionality assessment

    Establish what implementation is defensible given your size, complexity and risk profile.

  3. 3

    Evidence gathering

    Collect and review documentation, board minutes, registers and system configuration.

  4. 4

    Testing

    Test control operation across the period, not just at a point in time.

  5. 5

    Gap rating

    Rate each requirement with evidence and a defined closure condition.

  6. 6

    Board reporting

    Report in a form that supports the quarterly board review the framework requires.

What you receive

Requirement-by-requirement compliance position across all framework domains
Evidence register supporting every assessed position
Gap analysis with proportionality rationale documented
Prioritised remediation roadmap sequenced against supervisory cycles
Board reporting pack structured for the quarterly review obligation
Independent validation of remediation before you report closure

Frequently asked questions

Yes. The framework applies to all financial institutions supervised by the State Bank of Pakistan, expressly including microfinance banks alongside commercial banks, Islamic banks and DFIs. The proportionality principle means a microfinance bank is not expected to implement identically to a large commercial bank — but it is expected to implement, and to be able to justify how.

The board is required to review implementation quarterly, which implies a reporting position must exist at least that often. A full independent gap assessment annually, with quarterly internal monitoring against it, is a defensible cadence for most institutions. After any material change to the technology estate, reassess the affected domains.

It can, if it has the IT audit capability. Many internal audit functions in Pakistani institutions do not, which is why co-sourcing the technology portion is common. What matters to the supervisor is that the assessment is competent and independent of the function being assessed — not that it was performed by an external firm.

No, though they overlap substantially in the information security domain. ETGRM is a supervisory framework covering technology governance broadly, including IT audit and service delivery. ISO 27001 is a certifiable management system standard focused on information security. An organisation certified to ISO 27001 will have covered a good portion of the ETGRM security requirements but not the governance, audit or service delivery obligations.

Related services

Not sure this is the framework that binds you?

Six questions, ninety seconds, runs in your browser. It will tell you which frameworks apply and why.

Request a proposal
Top