Risk consulting in Bangladesh covers a wider range of work than many boards expect. It includes internal audit, enterprise risk management, governance, risk and compliance (GRC) frameworks and the measurement of financial risks such as credit and liquidity. This article explains what each area involves, when audit committees and boards usually call for outside help and what a well-run engagement looks like. It reflects the position at the time of writing.
What risk consulting in Bangladesh covers
- Internal audit: independent, risk-based assurance over processes and controls, run in-house, outsourced or co-sourced.
- Enterprise risk management (ERM): a framework for identifying, assessing and reporting risks against strategy, including risk appetite.
- Governance, risk and compliance (GRC): policies, control frameworks, compliance monitoring and reporting lines to the board.
- Financial risk: credit, liquidity, market and model risk, including the data and models behind them.
- Technology and cyber risk reviews, often alongside IT audit.
In practice these areas overlap. The ERM framework tells internal audit where to focus. Internal audit then tests the controls and open issues recorded in GRC, and financial risk models need independent validation. A board that buys each piece separately often ends up with gaps between them, so it should decide early who owns the overall picture.
Three reference points recur in these engagements. The COSO 2017 ERM framework has five components: governance and culture; strategy and objective-setting; performance; review and revision; and information, communication and reporting. COSO states that ERM is not a function or department but the culture, capabilities and practices applied to strategy and performance.
ISO 31000:2018 gives principles, a framework and a process for risk management. ISO says it cannot be used for certification. The Institute of Internal Auditors' 2024 Global Internal Audit Standards took effect on 9 January 2025 and are organised into five domains and 15 principles.
The regulatory pull in Bangladesh
For banks, Bangladesh Bank's Risk Management Guidelines (DOS Circular No. 04 of 8 October 2018) require a board-approved risk management guideline reviewed at least once a year and a Chief Risk Officer heading the Risk Management Department. Banks must also report to the regulator, including a board-approved Risk Appetite Statement each year and a half-yearly stress test report.
Bangladesh Bank's Guideline on ICT Security, version 4.0 (2023), adds an internal information system audit at least once a year on a risk-based approach, and an external information system audit at least annually.
For listed companies, the BSEC Corporate Governance Code (notification dated 3 June 2018) requires an audit committee of at least three members, including an independent director. The committee monitors the internal audit and compliance process and reviews the adequacy of the internal audit function. As reproduced in listed-company compliance statements, the code also bars the statutory auditor from providing internal audit services to the company.
When boards and audit committees bring in outside help
- There is no internal audit function yet, or the existing one lacks specialist skills such as IT, treasury or credit.
- A new or tightened regulatory expectation requires a gap assessment or a new framework.
- The board wants an independent view before a financing, acquisition, listing or regulatory inspection.
- A control failure, fraud allegation or audit finding calls for an objective look at root causes.
- The in-house team cannot cover the audit plan in a busy period.
- The audit committee wants a periodic independent assessment of the internal audit function or the ERM framework.
Outside help does not replace management's ownership of risk. COSO's guidance treats risk management as part of how the business is run, so the better engagements leave management more able to run the process itself.
What a good engagement looks like
- A written scope agreed with the audit committee, covering objectives, entities, period and exclusions.
- A reporting line that reaches the audit committee or board as well as the executives whose areas are reviewed.
- A risk-based plan that explains why areas were selected and uses the company's own risk register and incident history.
- Findings rated by significance, with root causes, practical recommendations and named management owners.
- A tracking process so that findings are followed up and closed with evidence.
- Knowledge transfer: templates, methodology and training for in-house staff.
Independence should be settled at the outset. If the same firm is the statutory auditor, check which services the applicable rules and the audit committee allow. For a listed company the code excludes internal audit from the statutory auditor's services.
Ask who will do the work, how much senior time is included and what you will receive at each stage. A good proposal answers these in writing and shows how the team will work with your own staff.
Questions an audit committee can ask before commissioning work
- What decision or assurance need does this work serve, and who will act on the result?
- Which of the company's top risks does the proposed scope cover, and which does it leave out?
- Who will staff the engagement, and what is their experience in our sector and under our regulator's rules?
- How will the findings reach the audit committee without being filtered by the areas reviewed?
- What will our own team be able to do on its own once the work ends?
Choosing between outsourced, co-sourced and one-off reviews
Outsourced internal audit suits organisations that want the whole function run externally, for example a newly established company or the local subsidiary of a foreign group. Co-sourcing keeps a core team in-house and brings in specialists for areas such as IT, credit or fraud risk. A one-off review suits a defined question, for example an ERM maturity assessment or a control health-check. In each case the audit committee should own the plan and the follow-up.
RRH's Risk Consulting service provides risk-based internal audit and compliance services for boards, audit committees and management in Bangladesh. Related services include Internal Control & Compliance Review and IT Advisory. IT Advisory covers IT audit, technology risk and cybersecurity.
This article gives general information. It does not constitute legal, regulatory or tax advice. Rules and timelines change, so readers should confirm current requirements with an adviser before acting.






