العربية
Under attack? Get help nowActive incidents only
Talk to us

The technical audit cycle is coming. We prepare you for it.

For private banks on the Central Bank’s Pathways programme and for digital-bank applicants: a readiness programme for the technical audit under the Standards Booklet — core banking, online banking, digital security, payments and the development lifecycle — each domain benchmarked to ISO 27001, ISO 22301, COBIT 2019, NIST CSF and SWIFT CSP.

  1. Reform standards
  2. Audit cycle 1
  3. Technical audit cycle
  4. Final validation

The Central Bank has set the sequence. Reform standards, two audit cycles and a final validation follow, in that order. We prepare you for the technical audit cycle.

Which institutions the timeline applies to depends on your pathway and licence — ask us, or see Payment companies and wallets.

Dates to be confirmed against the CBI circular Last reviewed 28 September 2026

Is this you?

  • Your board approved the Stay pathway and asked who will run the technical audit.
  • You are merging, and two IT estates must pass one audit.
  • The CBI-approved auditor is booked and your evidence library is a shared drive.

What you get

  • Domain-by-domain readiness scorecard — core banking, online banking, digital security, payments, development lifecycle board
  • Mock audit, run in the order the approved auditor will run it auditor
  • Evidence library structure, indexed to the Booklet’s control areas auditor
  • Remediation sprint plan with owners and dates engineers
  • Board briefing deck in Arabic board

What it maps to

Regulation / standardWhat DigiFort delivers
Standards Booklet 2025 (private banks)2026 (digital banks)Readiness scorecardevidence indexremediation plancontinuity and recovery evidenceexercise recordcontrol mappingcommittee papersaudit trailrole evidencereporting linegap notes
Benchmarks: ISO 27001ISO 22301COBIT 2019NIST CSFSWIFT CSPCross-reference per domain

How we do it

  1. Scope and baseline — the domains in scope, the documents you already hold, the audit date. Your side: the CISO or IT head and internal audit. Ours: the practice lead.
  2. Readiness scorecard — each domain benchmarked and rated; the board sees one page.
  3. Evidence library — structure, naming, owners; every control has a home before it has a document.
  4. Remediation sprints — owners, dates, a weekly check-in; the scorecard is re-rated as items close.
  5. Mock audit and board briefing — a dry run in the auditor’s order; findings first, then the briefing deck in Arabic.

Boundaries

Assurance under the Standards Booklet is performed by a CBI-approved third-party firm. We are your readiness partner ahead of that auditor; the firm that prepares your evidence does not sign assurance on it.

This is not a certification audit and not a PCI DSS assessment; a certification body and a QSA do those parts.

SWIFT CSP

Attestation support, CSCF control mapping and independent-assessment readiness.

Service levels

Response to a readiness question
A named practice lead replies.
Reporting
Weekly during sprints and a scorecard at the end of each phase
Languages
Arabic and English
Coverage
Baghdad

FAQ

Where is our data handled?

Agreed with you in writing before the engagement starts: where each deliverable is stored, in which region, who can open it, and how it is handed back or deleted when we finish.

Can you also sign the assurance?

No; a CBI-approved firm signs assurance, and we prepare you for it.

Our audit is in six months. Is that enough?

Enough for a scorecard, an evidence library and one remediation sprint; the scoping call says which.

Talk to us

Request a confidential consultationA named practice lead replies.Send an RFPAcknowledged in writing, with the date you will have our go/no-go.