Iraq’s Banking Reform Plan: independent audit at the heart of sector transformation

The Central Bank of Iraq’s Banking Reform Plan is redefining what it takes to operate a bank in Iraq. Independent financial, operational and technical audits sit at the centre of the plan, and BDO in Iraq has been appointed across all three.

A binding reform plan

In April 2025, the Central Bank of Iraq launched a comprehensive reform of the private banking sector, developed with international advisors and backed by the Iraqi government. The reform rests on three pillars: expanding financial inclusion, enhancing the efficiency and productivity of private banks, and building a competitive, resilient banking environment that reconnects Iraqi institutions to the global financial system.
Unlike earlier initiatives, the reform is binding. Effective from August 2025, the 2025 Standards Booklet, the Detailed Assessment Guidelines and the Pathways Circular set mandatory requirements covering governance, business model sustainability, financial soundness, and risk and regulatory compliance. Every licensed private bank, commercial and Islamic alike, must choose one of three pathways: Stay, Merge or Exit. The standards were designed to address the root causes of the foreign currency restrictions facing many Iraqi banks, with compliance confirmed by reputable third-party assessors representing the route back to international correspondent banking.

Three independent audit streams

The credibility of the reform rests on independent verification by approved audit firms across three complementary streams:

Financial audit. Capital, capital adequacy, liquidity and related financial metrics must be audited by a CBI approved third-party auditor, with the first reform cycle audits due in 2026 and annually thereafter.
Operational audit. An independent examination of each bank’s internal control environment; whether the three lines of defense model is genuinely embedded, whether roles and responsibilities are clear, whether policies and procedures are adequate, whether controls operate effectively, and whether staff are capable of running them. The output is a documented gap analysis and a prioritized remediation plan.

Technical audit. An independent audit of the technology estate across five domains, under the CBI Technical Audit Assessment Framework; the core banking system, the online banking platform, digital security, payment systems, and the system development life cycle.

Business continuity and disaster recovery plans are also subject to third party audit. Findings are benchmarked against international standards including ISO 27001, ISO 22301, COBIT 2019, NIST CSF and the SWIFT Customer Security Program.

What banks should be doing now

Whether a bank is preparing for its first assessment cycle or responding to findings from a completed cycle, priorities remain the same:
  • Treat the reform as a board-level exercise with clear ownership, a cycle-by-cycle roadmap and regular reporting through to the final assessment cycle in December 2028.
  • Prepare for Cycle 1, due September 2026, where capital and composition, capital adequacy, liquidity, related parties, audit transparency, AML/CFT/sanctions and internal controls will be assessed by the CBI’s approved assessor.
  • Enhance governance structures, business and operational resilience, and the four technology domains of core banking, online banking, infrastructure and data, and payment systems to achieve compliance with their respective controls before the Cycle 2 assessment in March 2027.
  • Treat the middle cycles as the remediation window, closing the gaps identified in the diagnostics in order of risk so that final validation confirms compliance rather than exposing weaknesses.
  • Invest in the people who operate controls. Assessments repeat across every cycle and weigh staff competency alongside policy and technology.

How BDO can help

BDO supports banks across the full scope of the reform, both as an independent third-party assessor and as an implementation partner. The activities BDO currently delivers for its clients include:
  • Financial audit covering capital and composition, capital adequacy, liquidity, related parties and transparency of reporting, delivered through the official CBI submission templates.
  • Operational audit covering governance structure, business and operational resilience, AML/CFT and sanctions, and internal controls across the three lines of defense, with a clear gap analysis and a prioritized remediation plan.
  • Technology assurance across core banking, online banking, infrastructure and data, and payment systems, benchmarked against international standards.
  • Preparation of the five-year business plan, a key milestone required by the CBI, including market analysis, customer segmentation, pricing, product roadmap and geographic expansion strategy.
  • Implementation support to close identified gaps, from policies, procedures and operating models to governance, compliance and resilience frameworks, preparing the bank for validation with confidence.

Key contacts

Jafar Al-Qaryouti

Partner, Business & Technology Consulting  |  Jordan and Iraq

Executive summary
Jafar is a Partner at BDO, leading the Business & Technology Consulting practice across Jordan and Iraq.
He is the Engagement Partner for BDO's work on the Central Bank of Iraq’s Banking Reform Plan, with partner-level responsibility across the financial, operational and technology assurance streams, from scope and methodology through to risk ratings and final conclusions. He has over 28 years of experience, spanning audit, risk, AML/CFT, IT governance, information security and cybersecurity for banking and regulated sectors, including 19 years as a Senior Director with EY in Baghdad.
Jafar has an extensive record in managing AML/CFT and enterprise risk assessments and in leading the implementation programs that follow, helping banks translate findings into effective frameworks, policies and controls. He works with regulators, banks and financial institutions across Iraq and Jordan, ranging from the Central Bank of Iraq and the country's largest state-owned banks to private commercial and Islamic banks.
Areas of expertise
  • Engagement leadership across financial, operational and technology audit streams.
  • Operational audits covering governance, AML/CFT and sanctions, internal controls and business and operational resilience.
  • AML/CFT and enterprise risk assessments and remediation implementation.
  • Technical IT audits under the CBI Technical Audit Assessment Framework.
  • IT governance, information security and cybersecurity advisory.
  • SWIFT Customer Security Program assessments.
  • Core banking and enterprise system selection.
  • Engagement quality control and audit methodology.
Experience
  • Engagement Partner for audits of Iraqi banks under the CBI Banking Reform Plan across financial, operational and technology assurance streams.
  • Partner on operational audits covering governance structure, AML/CFT and sanctions compliance, the three lines of defense and business and operational resilience.
  • Managed AML/CFT and risk assessment engagements for banks and financial institutions and led the implementation of the resulting remediation and compliance programs.
  • Directed technical audits covering core banking, online banking, digital security, infrastructure and data, payment systems and the system development life cycle.
  • Sector-wide IT assessment for the Central Bank of Iraq across all licensed electronic payment companies.
  • SWIFT Customer Security Program assessments for more than fifty banks in Iraq.
  • Core banking and enterprise system selection for Al-Rafidain, Al-Rasheed and the Trade Bank of Iraq.
Qualifications and affiliations
  • ISO 27001 and ISO 22301 Lead Implementer.
  • COBIT 2019 Foundation, ISACA.
  • Project Management Professional (PMP).
  • Oracle Certified Professional.
  • Ph.D. candidate, University of the Basque Country, Spain.
  • M.Sc. in Computer Science, University of Jordan.
  • B.Sc. in Computer Engineering, Princess Sumaya University for Technology.