Skip to content

Regulatory

An SBP ETGRM readiness checklist for boards and audit committees

The framework requires the board to review implementation quarterly. Here are the questions worth asking in that meeting, and the evidence that should exist behind each answer.

Published · 9 min read · Regulatory

In short

  • The board review obligation is quarterly, and it is the requirement most often missed — usually because the review happens informally and leaves no record.
  • Implementation is explicitly risk-based and proportionate. Proportionality is a valid defence only if the reasoning was documented at the time.
  • Most gaps are governance discipline, not missing technology. They cost little to fix and require a dated record.
  • Map your position requirement by requirement before spending anything on remediation.

Start with the obligation, not the controls

The State Bank's Enterprise Technology Governance and Risk Management Framework, issued under BPRD Circular No. 05 of 2017, applies to commercial banks, Islamic banks, development finance institutions and microfinance banks. Two structural features shape everything else about how a board should approach it.

First, implementation is explicitly risk-based and proportionate to the institution's size, nature and complexity. There is no single correct implementation. What a supervisor assesses is whether your interpretation is defensible for your institution.

Second, the board is required to review implementation on a quarterly basis, with senior management monitoring continuously. This is the obligation most often missed — not because institutions ignore technology, but because the review happens informally or annually and leaves no record.

Questions worth asking in the quarterly review

  • Is our implementation position documented requirement by requirement? If the answer is a summary rather than a mapped position, you cannot demonstrate proportionality and you cannot show progress between quarters.
  • Where we have not implemented something, is the rationale recorded? Proportionality is a legitimate defence only if the reasoning was documented at the time, not reconstructed during an inspection.
  • Has the technology risk register been reviewed this quarter, and did anything escalate? A register where nothing has changed in four quarters is not being used.
  • What did IT audit cover this period, and how was that coverage chosen? Coverage should follow a risk assessment. If the same areas are audited every year while others have never been examined, the plan is not risk-based.
  • How many findings were reported closed, and who validated closure? Post-closure monitoring is an explicit framework expectation. Self-certified closure by the function that owned the finding does not satisfy it.
  • Have our stated recovery objectives been tested against actual capability? A documented four-hour RTO alongside a nightly backup cycle is a contradiction that surfaces during an incident, not before.
  • Which critical technology services are outsourced, and how is the provider monitored? Contractual control requirements are necessary but not sufficient. Ongoing monitoring is the control.
  • Who holds privileged access to the core banking system today, and when was that list last reviewed by someone outside IT?

What the framework covers

Board of Directors — quarterly review Senior management monitors implementation on an ongoing basis BPRD Circular No. 05 of 2017 · risk-based and proportionate Technology governance Information security IT service delivery System acquisition Business continuity IT audit
Six domains, under a board review the framework requires quarterly.

Evidence that should exist

For each of the above, there should be a document with a date on it. Board minutes recording the review and the decisions taken. A dated risk register with a change history. An audit plan with the risk assessment that produced it. Validation records for closed findings. A restoration test report — not a backup completion report, a restoration test. An access recertification record showing who reviewed and what they changed.

The distinction that matters throughout is between having a control and being able to evidence it. Supervisors assess the second.

The most common gaps

Across assessments against this framework, the recurring shortfalls cluster in a narrow set of areas: board review happening less frequently or less formally than quarterly; audit coverage not demonstrably risk-driven; finding closure not independently validated; recovery objectives never reconciled to actual capability; and outsourcing governed at contract signature but not thereafter.

None of these require significant investment to fix. They require discipline and a record.

Where to start if you are behind

Map your current position against every requirement before doing anything else. Institutions that begin with remediation rather than assessment routinely spend budget on controls that were already proportionate while leaving genuine gaps untouched. The mapping exercise typically takes a few weeks and changes the remediation plan substantially.

The distinction that matters throughout is between having a control and being able to evidence it. Supervisors assess the second.

Related pages

Want an independent view of your ETGRM position?

We map every framework requirement to an evidenced compliance position and report in a form that supports the quarterly board review.

Request a proposal
Top