Course Details


Information System Audit in Banks for IT Officials

  • Title : Information System Audit in Banks for IT Officials
  • Course TYPE : Training Course
  • Course No : TC23/2025
  • Duration : 05 Working Days
  • Frequency : 01
  • Time : Sunday 18th of May 2025 - Thursday 22nd of May 2025
  • Nature: Residential
  • Target Group : Senior Officer or Equivalent Officer and above who are working in the ICC/Audit department having IT Background
  • Methods : Lecture, Group Discussion, Case Study and Practical Demonstration.
  • Resource Person: BIBM Faculty and Professionals from Financial and other Institutions
  • Coordination Team :
    1 . Md. Shihab Uddin Khan
    2 . Md. Foysal Hasan
  • Objectives:

    a.   To Enable the Participants to Understand IS Audit Highlighting Security and Control Concerns.

     b.   To Enhance the Skill of the Participants to Conduct IS Audit in Banks with Care and Confidence.

  • Contents:
    • IT Based Products and Services in Banks.
    • Fundamentals of Information Security in Banks, Cyber Attack and Online Frauds in Banks and Preventive Measures.
    • Concept of IS Audit and Audit Process in Banks: Planning, Audit opening meeting, creating auditing program and set the scope.
    • IS Audit Checklist in Banks: ICT Operation Management, ADCs Management, Asset Management and Devices Controls, ICT Security Management, Physical and Environment Security Management, Information Security Standard, IT Risk Management, Software Development and Acquisition, Business Continuity and Disaster Recovery Management, Impact of Last Inspection Report.
    • Inspection of Data Access Control and Malware Management of Online Bank.
    • Inspection of Network Security.
    • Practical Demonstration on Vulnerability Assessment and Penetration Testing (VAPT).
    • IT Risk Management Audit: Risk IT Framework for the and control of Business Solutions and
    • Audit of Outsourcing and Service Provider Management in Banks.
    • Case Study on IS Audit and Inspection in Banks.
    • Case study on IT Risk Assessment: Risk Register, Risk Mapping/Matrix and Risk Mitigation Plan.
    • Implementation of Cyber Law: Cyber Security Act. 2023 and Digital Security Act.

a. BIBM member banks can access the online nomination form before forty (40) days of the commencement of programs. BIBM member banks can nominate a maximum number of three (03) participants for a Training Course/Training Workshop. The maximum number of participants in each Training Course/Training Workshop is 40. However, if the number of total nominees exceeds the maximum number, a final list of 40 participants will be prepared by the BIBM authority which will be available online five (05) days prior to the commencement of the Training Course/Training Workshop. Information in regard to rejection of any nomination will be communicated to the concerned bank at least three (03) days before the commencement of the Training Course/Training Workshop. No participant under the target group/level is allowed to participate in any Training Course/Training Workshop.

b.  As per the decision of the BIBM Governing Board, BIBM Member Banks (except Bangladesh Bank) are required to pay BDT 1800 per day per participant including holidays (if any) as training fees which also include Accommodation, Food, and other miscellaneous expenses. 

For Non-member Banks  and Non-Bank Financial Institute (NBFIs) are required to pay BDT 7,000/- for one week program (up to 5 woking days), BDT 10,000 for two weeks program (up to 10 working days) and BDT 15,000 for Three weeks program (up to 15 working days) per participant. Besides, all non-members banks and non-bank financial institutions (NBFIs) have to pay BDT. 960 (800+20%) per day (including holidays) per participant as food and hostel charges.

For Bangladesh Bank, the fee is BDT 500 per day per participant. All Fees are excluding VAT and Tax. 

c. The pay order/bank draft drawn in favor of ‘Bangladesh Institute of Bank Management’ has to be sent at least seven (07) days prior to the commencement of the Training Course/TrainingWorkshop.