2026-07-03
Added · Updated
This Regulation establishes requirements for the accounting and external audit of payment institutions and electronic money institutions registered by the Central Bank of the Republic of Kosovo. External auditors must be licensed by the Kosovo Council for Financial Reporting and approved by the Central Bank, possessing at least three years of relevant experience, with approval limited to one institution per financial year and applications due before June 30. The same auditor may not serve continuously for more than five years or five consecutive audits, after which a two-year cooling-off period applies. The Central Bank may impose administrative penalties, including written warnings or a prohibition on approval for up to three years, for violations of these provisions.
CBK published 3 documents in the last 30 days — get each new one by email the day it lands.
Pursuant to Article 35, paragraph 1 subparagraph 1.1 and Article 65 of the Law No. 03/L-209 on Central Bank of the Republic of Kosovo (Official Gazette of the Republic of Kosovo, No.77 / 16 August 2010), as amended and supplemented by Law No. 05/L –150 (Official Gazette of the Republic of Kosovo, No. 10 / 03 April 2017) and, as well as Article 136, and Article 19, paragraph 6 of the Law No.10/L-026 on Payment Services (Official Gazette of the Republic of Kosovo,No.10 / 14 May 2026), the Board of the Central Bank, at meeting held on June 29, 2026, approved the following:
REGULATION ON THE ACCOUNTING AND EXTERNAL AUDIT OF PAYMENT INSTITUTIONS AND ELECTRONIC MONEY INSTITUTIONS
Article 1
Purpose and Scope
1.5. Law on accounting, financial reporting and auditing – means Law No. 06/L-032 on
Accounting, Financial Reporting and Auditing, as amended and supplemented by Law No. 10/L-025 on Amending and Supplementing Law No. 06/L-032 on Accounting, Financial Reporting and Auditing, and/or the Law in force for accounting, financial reporting and auditing;
1.6. PI – means a payment institution as defined in the Law on Payment Services;
1.7. EMI – means an electronic money institution as defined in the Law on Payment Services;
1.8. Institution – means PI and EMI.
Article 3
General Conditions
3.5. A relevant document that proves sufficient experience of external auditor or its staff which
carries out the auditing in the field of audit of PIs, EMIs or other financial institutions;
3.6. A certificate issued by the Kosovo Council for Financial Reporting (KCFR) regarding the
results of the latest quality control for the external auditor (this certificate shall not be required by the CBK until the KCFR begins to issue such a certificate); and
3.7. A written declaration of the external auditor for meeting the criteria set forth in Article 7 of
this Regulation.
4. The audit program and the use of resources in the audit mission shall be appropriate in relation to
the character and size of the PI and EMI.
5. The continuous engagement of the same external auditor is limited to five (5) years or five (5)
consecutive audits, and may again participate in the audit of the same PI or EMI after the lapse of at least two (2) years.
Article 5
Good Repute
The CBK shall grant approval as an external auditor of a PI or EMI to external auditors of good repute who are not engaged in any activity which is incompatible with the external audit function.
Article 6
Re-auditing
CBK shall reserve the right to request a re-audit carried out by another external auditor, at the expense of the PI or EMI, in cases when significant issues or deficiencies are identified in the initial audit or when the existing external auditor of the PI or EMI has carried out an audit or has submitted a report which is inconsistent with the requirements of the Law No.10/L-026 on Payment Services, applicable CBK regulations, the International Standards on Auditing (hereinafter: the ISA) applicable via Law on accounting, financial reporting and auditing, and do not reflect the true and accurate financial position of the PI or EMI.
Article 7
Professional Ethics
External auditors shall be subject to principles of professional ethics defined by the International Federation of Accountants’ “Code of Ethics for Professional Accountants”.
Article 8
Independence and Objectivity
and informed third party would conclude that the independence of the external auditors is compromised.
2. The approved external auditors must also be in accordance with the provisions of the Law on
accounting, financial reporting and auditing as well as the by-laws issued pursuant to this law on the issue of auditor independence.
3. The external auditors shall document in the audit working papers all the interference to their
independence, as well as the safeguards applied to mitigate such interference.
Article 9
Independence and Objectivity of Auditors Carrying Out an Audit on Behalf of Audit Firms The owners or shareholders of an approved audit firm, as well as the members of the administrative, management and supervisory bodies of such a firm, or of an affiliated firm, shall not interfere in the execution of an audit in any way that might jeopardize the independence and objectivity of the auditor(s) who carries out the audit on behalf of the audit firm.
Article 10
Audit Fees
and applicable CBK regulations, and whether or not the information is consistent with the annual accounts.
3. External auditors shall assess the adequacy of risk management systems of the PI or EMI, based
on the assessment of:
3.1. Compliance with the requirements for the organizational structures with regard to any special
risk management;
3.2. Policies and procedures on any special risk management and their implementation;
3.3. Adequacy of identification, measure and monitoring of any special risk;
3.4. Adequacy and efficiency of internal audit system regarding the management of any special
risk.
4. Specific risks include credit risk, market risk, operational risk, liquidity risk and other risks to
which PI or EMI are exposed.
5. External auditors shall ensure that PI and EMI have arranged for satisfactory asset management
and that proper internal controls are in place.
6. External auditors shall ensure that PI and EMI have in place satisfactory framework that includes
various tools, procedures and practices for safeguarding funds.
7. Audit of PI and EMI should cover areas such as the adequacy of internal controls over financial
reporting.
8. External auditors shall, through audits, contribute to the prevention and disclosure of irregularities
and errors.
Article 13
External Auditors’ Duties
4.3. Irregularities and errors that may lead to erroneous information in the annual accounts.
Article 14
Documentation of Assignment
As required by ISA 230, “Audit Documentation,” external auditors must document how an audit was carried out, as well as the result of the audit in a sufficient manner. Matters that indicate possible irregularities or errors must be documented separately.
Article 15
Maintenance of Audit Working Papers
Audit working papers shall be prepared and maintained in accordance with relevant ISA.
Article 16
External Auditors’ Report
Article 17
Management Letter
External auditors shall, in accordance with CBK's primary and secondary legislation, provide a
management letter to the financial institution regarding the conclusions of the audit process. The management letter shall include any conclusions the external auditor may have reached on the activity or the financial position of the financial institution, and information on the diligence they have performed in the scope of the audit mission.
In the final management letter, the external auditors shall make a specific statement concerning
the internal controls system in order to provide specific assurance on, and for the purpose of disclosing material matters in, the internal control structure. The specific statement shall also include comments on the internal audit function.
Article 18
Confidentiality
External auditors and other audit engaged staff have a duty of confidentiality regarding everything
of which they have gained knowledge through their activities unless otherwise stipulated by law, or the person the information concerns has consented the duty of professional secrecy does not apply. External auditors and external auditors’ co-workers may not use such information in their own activities or in the service or employment of others.
Without limitations by the paragraph 1 of this Article or an agreed duty of confidentiality, external
auditors are allowed to submit explanations and present documentation regarding an audit assignment when required by the legislation in force in the Republic of Kosovo.
The duty of confidentiality continues to apply after the assignment has been concluded.
Article 19
Duty to Inform
External auditor shall, within the framework of an assignment, provide information about matters
regarding the PI and EMI that the external auditor has become aware of during the audit when this is required by general meeting of shareholders, Board of Directors, senior management, an audit committee or by a person authorized by the CBK.
The external auditor shall immediately inform the Audit Committee or the Board of Directors of
the PI or EMI and the CBK when the auditor, while carrying out the audit of the PI and EMI, establishes that:
2.1. A serious conflict exists within the decision-making bodies or a manager in a key function
unexpectedly departed;
2.2. Information exists that may indicate a material breach of laws, regulations, instructions and
CBK Regulations as well as of the statute and by-laws of the PI and EMI; or
2.3. the intention of the internal auditor is to resign or that there are intentions to dismiss external
auditor; that there are negative or material changes that pose a risk to PI and EMI work and that there is a possibility that the risk continues.
External auditor shall, upon request from the CBK, provide the CBK with any information, during
the full audit mission, concerning to its performance of audit services to a PI and EMI.
The CBK shall maintain regular contacts and may initiate meetings with external auditor of the PI
and EMI in any time when such contacts are deemed necessary.
Article 20
Quality Control and Its Review
External auditors approved by the CBK shall apply adequate quality control policies and
procedures that address all significant aspects of the audit.
External auditors approved by the CBK shall be subject to quality assurance review from the CBK.
The quality review of an approved external auditor shall cover one specific audit assignment and
shall be executed by the CBK or by one reviewer designated by the CBK.
During the quality review, the CBK or the reviewer shall determine the extent to which the external
auditor has adequate quality control policies and procedures that address all significant aspects of auditing. During the review, the CBK or the reviewer shall have access to the working papers of the external auditor as far as necessary to conduct a sufficient and adequate quality control.
Concerning obligations on confidentiality, Article 18 of this Regulation applies equally to the CBK
and the quality reviewer (external auditor).
Aggregate results of the quality assurance review shall be published by the CBK, including
recommendations, follow up of recommendations and, if the case arises, sanctions.
Article 21
Dismissal and Resignation
External auditors of PI and EMI may only be dismissed where there are proper grounds.
Divergence of opinions on accounting treatments or audit procedures shall not be a proper ground for dismissal.
Both the audited PI or EMI and the external auditors shall inform the CBK about the dismissal or
resignation and shall give an adequate explanation of the reasons thereof.
Article 22
Revoking of Approval
Approval of an external auditor shall be revoked if the good reputation of that audit firm has been seriously compromised or any of the requirements of this Regulation are no longer fulfilled.
Article 23
Enforcement, Remedial Measures and Administrative Penalties
Any violation of the provisions of this Regulation shall be subject to administrative penalties as
defined within article 67 of the Law No. 03/L-209 on Central Bank of the Republic of Kosovo, as
amended and supplemented by Law No. 05/L–150 and article 125 of the Law No. 10/L-026 on Payment Services.
2. If external auditors of the PI and EMI have violated any legal provisions regarding the auditor’s
duties pursuant to the provisions of this Regulation and other relevant Law and CBK Regulations, the CBK can impose a written warning to the external auditor, with a copy of it being sent to the audited PI and EMI.
3. If the violations described in paragraph 1 of this Article are repeated, the CBK shall have the right
to:
3.1. Refuse the approval of the external auditor to engage in carrying out an audit of financial
institutions licensed by the CBK to operate in the Republic of Kosovo; the prohibition for the approval of the external auditor may last up to three (3) years;
3.2. Require the removal or replacement of an external auditor;
3.3. Directly appoint, remove or replace an external auditor, or
3.4. Require re-auditing according to Article 6 of this Regulation.
Article 24
Entry into Force
This Regulation shall enter into force 15 days from the date of its approval. Dr.sc. Bashkim Nurboja Chairman of the Board of the Central Bank of the Republic of Kosovo
Read the rest free
Source: Central Bank of the Republic of Kosovo — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CBK
CBK published 3 documents in the last 30 days. We email you each new one the day it's published.