2026-07-03
Added · Updated
This Regulation establishes mandatory internal control and internal audit requirements for payment institutions and electronic money institutions registered by the Central Bank of the Republic of Kosovo. It mandates the establishment of efficient internal control systems aligned with the nature and risk of activities, covering management oversight, risk assessment, control activities, information systems, and monitoring. The document requires an independent internal audit function with specific competencies, a written charter, and annual plans, while stipulating that the head of internal audit is appointed by the Central Bank and that their dismissal must be reported within seven working days. Violations are subject to corrective measures and administrative penalties under the relevant Central Bank and Payment Services laws, with the Regulation entering into force 15 days after approval.
CBK published 3 documents in the last 30 days — get each new one by email the day it lands.
Pursuant to Article 35, paragraph 1 subparagraph 1.1 and Article 65 of the Law No. 03/L-209 on Central Bank of the Republic of Kosovo (Official Gazette of the Republic of Kosovo, No.77 / 16 August 2010), as amended and supplemented by Law No. 05/L –150 (Official Gazette of the Republic of Kosovo, No. 10 / 03 April 2017) and, Article 136, and Article 19 paragraph 2 of the Law No.10/L026 on Payment Services (Official Gazette of the Republic of Kosovo,No.10 / 14 May 2026), the Board of the Central Bank, at meeting held on June 29, 2026, approved the following:
REGULATION ON INTERNAL CONTROLS AND INTERNAL AUDIT OF PAYMENT INSTITUTIONS AND ELECTRONIC MONEY INSTITUTIONS
Article 1
Purpose and Scope
Article 3
Requirements
PIs and EMIs shall establish an efficient internal control system for the purpose of preventing
losses, maintaining reliable financial and management reporting, enhancing their prudent operation, and promoting stability in the financial system of the Republic of Kosovo.
PIs and EMIs shall have an effective system of internal controls that is consistent with the nature,
complexity, and inherent risk in their on- and off-balance sheet activities and that responds to changes in their environment and conditions.
The goals of the system of internal controls should be to prevent fraud, misappropriation and
errors, and to mitigate other risks faced by the PIs and EMIs, which shall:
3.1. Promote the efficiency and effectiveness of activities and measures that protect user funds in
PIs and EMIs, ensuring they are safeguarded from fraud, misappropriation, and errors.
3.2. Promote the efficiency and effectiveness of activities and measures that protect the PIs and
EMIs in using its assets and other resources and protecting it from losses;
3.3. Ensure the reliability, completeness and timelines of financial and management information,
so that administrators, directors, shareholders, external parties, and supervisors can rely on for decisions-making; and
3.4. Ensure compliance with applicable laws and regulations.
An effective internal control system consists of following interrelated components:
4.1. Management oversight and the control culture;
4.2. Risk recognition and assessment;
4.3. Control activities and segregation of duties;
4.4. Information and communication; and
4.5. Monitoring activities and correcting deficiencies.
Article 4
Oversight and Control Culture
The Board of Directors, if applicable, and persons responsible for management shall be responsible
for promoting high ethical and integrity standards, and for establishing a culture within the organization that emphasizes and demonstrates to all levels of personnel the importance of internal controls. Persons responsible for management shall ensure that all personnel understand their role in the internal controls system and shall be fully engaged in the process.
The Board of Directors, if applicable, and persons responsible for management (in absence of the
Board of Directors) shall be responsible for providing direction, guidance and oversight to PIs and EMIs and ensuring that the affairs of the entity are carried out in the best interest of the institution. The Board of Directors if applicable, and persons responsible for management (in absence of the Board of Directors) has a duty to act carefully in fulfilling the important task of directing and monitoring the activities of management, ensuring that the institution’s day to day operations is in the hands of qualified, honest and competent management.
Specific internal control duties of the Board of Directors if applicable, and persons responsible for
management (in absence of the Board of Directors) shall be obliged to:
3.1. Approve and annually review the institution's overall business strategy and significant
policies;
3.2. Determine the payment institution or electronic money institution’s structure, management,
operational units, functions, and supervisory roles;
3.3. Establish a committee to oversee the internal audit function to ensure its effectiveness;
3.4. Identify major institutional risks, setting acceptable risk levels, and oversee person responsible
for management's monitor of the internal control system's effectiveness (only for institutions that have a Board of Directors);
3.5. Conduct an annual review of the internal audit function;
3.6. Ensure the establishment and maintenance of an adequate and effective internal control
system.
The persons responsible for management shall be ultimately responsible for the PIs and EMIs
organizational and procedural controls, by ensuring the integrity of internal controls and by having in place an effective management team that is characterized by a culture of control and that is accountable for the performance of its responsibilities.
Persons responsible for management have specific internal control duties including:
5.1. Implementing strategies and policies approved by the Board of Directors if applicable, and
persons responsible for management (in absence of the Board of Directors);
5.2. Developing processes to identify, measure, monitor, and control risks faced by the Institution;
5.3. Maintain an organizational structure that clearly assigns responsibility, authority and reporting
relationships;
5.4. Ensure that delegated responsibilities are effectively carried out; set appropriate internal
control policies; and monitor the adequacy and effectiveness of the internal control system;
5.5. Ensure that outsourced services of any kind are with reputable companies that they have an
adequate internal control system. The contracts for these services shall stipulate that external auditors, internal auditors and CBK examiners have access to any documentation or information source or system that may be requested in the discharge of their respective function.
Article 5
Risk Recognition and Assessment
PIs and EMIs are required to establish risk management systems that are specifically aligned with
their licensed activities, considering the nature, volume, and complexity of these activities. The risk management system within a PIs and electronic money institution comprises policies, procedures, rules, and structures designed to facilitate effective risk management. This includes the identification, measurement, monitoring, control, and reporting of all types of risks across the institution's activities.
All material risks that could adversely affect the achievement of the PIs and EMIs goals shall be
recognized and continually assessed. This assessment shall cover all risks with which the PIs and EMIs is faced (including credit risk, liquidity risk, operational risk, and reputation risk) depending on the activities for which it has been registered.
Internal controls shall be reviewed at least annually by the Board of Directors and/or the Audit
Committee, if applicable, to appropriately address any new previously uncontrolled risks.
Effective risk assessment shall identify and consider internal factors (such as the complexity of the
organizational structure, the nature of its activities, the quality of personnel, organizational changes and employee turnover) as well as external factors (such as fluctuation of economic conditions, changes in the industry and technological advances) that could adversely affect the achievement of the Institution’s goals.
The risk assessment shall be conducted at all levels of individual activities and across the wide
spectrum of activities. Risk assessment shall address both measurable and no measurable aspects of risks and shall weigh costs of controls against the benefits they provide.
The risk assessment process shall also include the evaluation of risks to determine which are
controllable and non-controllable by the Institution. For those risks that are controllable, the PIs and EMIs must assess whether to accept those risks or the extent to which it wishes to mitigate the risks through control procedures. For those risks that cannot be controlled, the Institution must decide whether to accept these risks or to withdraw from or reduce the level of business activity concerned.
Article 6
Control Activities and Segregation of Duties
Control activities shall be an integral part of the daily activities of PIs and EMIs. Person
responsible for management shall establish an appropriate control structure, with control activities defined at every business level, including top level reviews; appropriate activity controls for different departments or divisions; physical controls; checking for compliance with exposure limits and follow-up on non-compliance; a system of approvals and authorizations; and a system of verification and reconciliation.
Control activities shall be designed and implemented to address the risks identified by the PIs and
EMIs through its risk assessment process. Control activities shall involve two steps:
2.1. Establishment of control policies and procedures, and
2.2. Verification and monitoring of compliance with these control policies and procedures.
Control activities shall involve all levels of personnel of the institution, including person
responsible for management as well as front line personnel.
Duties shall be allocated appropriately and personnel shall not be assigned responsibilities that
would result in conflict of interest. Areas of potential conflicts of interest shall be identified, minimized, and subject to careful, independent monitoring, particularly in those instances related to approval and disbursement of funds, costumer and accounts assessment and monitoring of loans and any other areas where significant conflicts of interest emerge and are not mitigated by other factors.
Article 7
Information and Communication
2.3. Review of the management and financial information systems;
2.4. Review of the accuracy and reliability of the accounting records and financial reports;
2.5. Review of the means of safeguarding assets, including, where applicable, customers’ funds;
2.6. Testing of both transactions and the functioning of specific internal control procedures;
2.7. Review of the systems established to ensure compliance with legal and regulatory
requirements, codes of conduct and the implementation of policies and procedures;
2.8. Testing of the reliability and timeliness of the regulatory reporting; and
2.9. Carrying out of special audit tasks.
3. Person responsible for management is responsible to ensure that the internal audit function is kept
fully informed of new developments, initiatives, products, and operational changes.
4. Each payment institution and electronic money institution should have a permanent and
independent audit function in order to fulfil its duties and responsibilities. The Board of Directors if applicable, and persons responsible for management (in absence of the Board of Directors) shall be responsible for ensuring the independence of the audit function and that sufficient human and material resources are available for the adequate performance of its functions and duties. The Board of Directors if applicable shall appoint the Committee that supervises the internal audit function as well as the head of the internal audit function, or the contracting of the internal audit
5. The internal audit function shall be independent of the activities audited and from the everyday
internal control processes. The head of the internal audit department should have the authority to communicate directly, and on his/her own initiative, to the Board of Directors if applicable, and persons responsible for management (in absence of the Board of Directors), or through the Audit Committee if applicable, which shall also set his or her compensation.
6. The internal auditor shall be appointed by the CBK in accordance with the definitions for person
responsible for management in the Regulation on the authorization, granting preliminary approvals and governance of payment institutions and electronic money institutions and for the registration of account information service providers.
7. The dismissal or resignation of the head of internal audit department and its causes shall be
communicated to the CBK within seven working days after it was decided.
8. Each payment institution and electronic money institution should have a written statute of audit
setting out the mandate and authorizations of the internal audit function within the institution.
9. The internal audit charter should contain at least:
9.1. The objectives and scope of the internal audit function;
9.2. The internal audit function’s position within the organization, its powers, responsibilities and
relations with other control functions; and
9.3. The accountability of the head of the internal audit function.
10. The audit charter should be drawn up – and reviewed periodically – by the internal audit function;
it should be approved by the Audit Committee and subsequently confirmed by the Board of Directors if applicable as part of its supervisory role.
The audit charter shall mandate the internal audit function with the right to initiate and authorizes
it to have access to and communicate with any member or staff, to examine any activity or units of the PIs and EMIs, as well as to access any records, files or data, including management information and the minutes of all consultative and decision-making bodies, whenever relevant to the performance of its assignments.
The charter shall specify the terms and conditions for the internal audit function to provide
advisory services or to perform other specific tasks.
The professional competence of every internal auditor and of the internal audit function as a whole,
which will vary depending on the size and complexity of PIs and EMIs operations, is essential for the proper functioning of the internal audit function.
The members of the internal audit function must at least fulfil the following qualities and
capabilities:
14.1. Professional capability to implement and adhere to procedure standards and auditing
techniques in the operating fields of the PIs and EMIs;
14.2. Knowledge and experience with International Financial Reporting Standards;
14.3. Knowledge of risk administrating principles and prudent internal auditing techniques of the
PIs and EMIs.
The head of the internal audit function shall be an individual with a high ethical and professional
reputation and with adequate experience in the auditing fields.
The head of the internal audit function shall prepare an audit plan for assignment and performance
of tasks, which will be approved by the Board of Directors and/or its Committee, if applicable supervising the internal audit function. PIs and EMIs shall make the appropriate resources available to the internal audit function.
The annual audit plan shall include in detail the timing and frequency of planned internal audit
work, the necessary resources in terms of personnel and it shall be based on an evaluation of internal controls and on a written assessment of material risks, updated annually.
The reports of the internal audit function, which contain the findings and recommendations as well
as the responses of person responsible for management, should be presented to the committee overseeing the internal audit function and/or the board of directors, if applicable.
Internal audit reports and working papers shall be kept for at least five years, as of the reporting
date.
The internal audit function shall follow up its recommendations to verify whether they are
implemented.
Article 10
Outsourcing of Internal Audit
An internal audit outsourcing agreement may be outsourced between a PIs or EMIs and a qualified
professional or a business organization which, as a primary activity, provides professional services related to internal auditing. In these cases, the business organization must have at least one qualified professional who meets the criteria of this Regulation for the head of internal audit.
Outsourcing of Internal Audit should be in line with Regulation on outsourcing arrangements for
PIs and EMIs.
Article 11
Penalties and Remedial Measures
Any violation of the provisions of this Regulation shall be subject to corrective measures and administrative penalties set forth in Article 67 of Law No. 03/L-209 on the Central Bank of the Republic of Kosovo and Article 125 of Law No.10/L-026 on Payment Services.
Article 12
Entry in Force
This Regulation shall enter into force 15 days from the date of its approval. Dr.sc. Bashkim Nurboja Chairman of the Board of the Central Bank of the Republic of Kosovo
Read the rest free
Source: Central Bank of the Republic of Kosovo — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CBK
CBK published 3 documents in the last 30 days. We email you each new one the day it's published.