The technical audit cycle is coming. We prepare you for it.
For private banks on the Central Bank’s Pathways programme and for digital-bank applicants: a readiness programme for the technical audit under the Standards Booklet — core banking, online banking, digital security, payments and the development lifecycle — each domain benchmarked to ISO 27001, ISO 22301, COBIT 2019, NIST CSF and SWIFT CSP.
- Reform standards
- Audit cycle 1
- Technical audit cycle
- Final validation
The Central Bank has set the sequence. Reform standards, two audit cycles and a final validation follow, in that order. We prepare you for the technical audit cycle.
Is this you?
- Your board approved the Stay pathway and asked who will run the technical audit.
- You are merging, and two IT estates must pass one audit.
- The CBI-approved auditor is booked and your evidence library is a shared drive.
What you get
- Domain-by-domain readiness scorecard — core banking, online banking, digital security, payments, development lifecycle board
- Mock audit, run in the order the approved auditor will run it auditor
- Evidence library structure, indexed to the Booklet’s control areas auditor
- Remediation sprint plan with owners and dates engineers
- Board briefing deck in Arabic board
What it maps to
| Regulation / standard | What DigiFort delivers |
|---|---|
| Standards Booklet 2025 (private banks)2026 (digital banks) | Readiness scorecardevidence indexremediation plancontinuity and recovery evidenceexercise recordcontrol mappingcommittee papersaudit trailrole evidencereporting linegap notes |
| Benchmarks: ISO 27001ISO 22301COBIT 2019NIST CSFSWIFT CSP | Cross-reference per domain |
How we do it
- Scope and baseline — the domains in scope, the documents you already hold, the audit date. Your side: the CISO or IT head and internal audit. Ours: the practice lead.
- Readiness scorecard — each domain benchmarked and rated; the board sees one page.
- Evidence library — structure, naming, owners; every control has a home before it has a document.
- Remediation sprints — owners, dates, a weekly check-in; the scorecard is re-rated as items close.
- Mock audit and board briefing — a dry run in the auditor’s order; findings first, then the briefing deck in Arabic.
Boundaries
Assurance under the Standards Booklet is performed by a CBI-approved third-party firm. We are your readiness partner ahead of that auditor; the firm that prepares your evidence does not sign assurance on it.
This is not a certification audit and not a PCI DSS assessment; a certification body and a QSA do those parts.
SWIFT CSP
Attestation support, CSCF control mapping and independent-assessment readiness.
Service levels
- Response to a readiness question
- A named practice lead replies.
- Reporting
- Weekly during sprints and a scorecard at the end of each phase
- Languages
- Arabic and English
- Coverage
- Baghdad
FAQ
Where is our data handled?
Agreed with you in writing before the engagement starts: where each deliverable is stored, in which region, who can open it, and how it is handed back or deleted when we finish.
Can you also sign the assurance?
No; a CBI-approved firm signs assurance, and we prepare you for it.
Our audit is in six months. Is that enough?
Enough for a scorecard, an evidence library and one remediation sprint; the scoping call says which.