Skip to content

Industries

Banking, Islamic Banking and Development Finance

Supervised institutions carry the heaviest technology assurance burden in the market — a supervisory framework with a quarterly board obligation, an external auditor testing ITGC every year, and an audit committee that needs answers it can defend.

What we do for banks

  • Independent gap assessment and internal audit against the SBP technology governance framework.
  • IT general controls audit over core banking, the surrounding infrastructure and the directory service.
  • Application control and segregation of duties review within the core banking platform.
  • Digital channel assurance — internet banking, mobile, and the APIs behind them.
  • Penetration testing of internet-facing and internal infrastructure.
  • SWIFT CSP independent assessment supporting the annual attestation.
  • Business continuity and disaster recovery audit, including live invocation observation.
  • Third-party and outsourcing assurance, including cloud service arrangements.
  • Co-sourced IT internal audit for institutions without in-house technology audit capability.

The recurring issues in this sector

Across banking engagements the same weaknesses recur, and they are rarely exotic. Privileged access to core banking that was granted for a migration and never revoked. Emergency access procedures that are used routinely rather than exceptionally. User access recertification performed as a formality, with managers approving lists they have not read. Change management that works well for planned releases and collapses for emergency fixes. And recovery objectives in the continuity plan that the backup regime has never been capable of meeting.

The supervisory frame

Board of Directors — quarterly review Senior management monitors implementation on an ongoing basis BPRD Circular No. 05 of 2017 · risk-based and proportionate Technology governance Information security IT service delivery System acquisition Business continuity IT audit
Six domains under a board review the framework requires quarterly.

Working alongside your external auditor

Where the objective is to support external audit reliance, we recommend introducing us at planning so scope, sampling basis and documentation standards are agreed in advance. Reliance is always the external auditor's decision, but it is far more likely when the approach was agreed before fieldwork rather than justified afterwards.

Related services

Related regulatory frameworks

Tell us what you are actually being asked for

Describe the situation rather than the service. Working out the right scope is part of what we do, and it costs nothing to ask.

Request a proposal
Top