Information Security Audit — NRB & NIA Regulatory Compliance
Independent information security audits aligned to Nepal Rastra Bank (NRB) and Nepal Insurance Authority (NIA) requirements. Includes SWIFT Customer Security Programme (CSP) assessment capability for financial institutions on the SWIFT network.
This service is distinct from ISO certification work. We assess against what your regulator expects — not only what a certification body checklist requires.
If you need ISO 27001, 27701, or 42001 implementation and certification readiness, see ISMS / PIMS / AIMS: Gap Assessment, Implementation & Audit.
Who this is for
Methodology
- 01
Engagement & Scope
Align audit scope to your regulatory filing, prior audit findings, and NRB/NIA circular requirements — including SWIFT CSP controls where applicable.
- 02
Document Review
Review IS policies, risk assessments, access management records, change logs, incident registers, and vendor due diligence evidence.
- 03
Control Testing & Fieldwork
Test key controls through sampling, configuration review, and interviews with IT, security, and business process owners.
- 04
Findings Validation
Validate observations with your team before finalisation — factual, evidence-backed findings rated by risk and regulatory impact.
- 05
Audit Report & Management Letter
Issue the formal audit report and management letter in a format suitable for board, regulator, and remediation tracking.
What you get
- Information systems audit report aligned to NRB or NIA supervisory expectations
- Findings register with risk ratings and regulatory reference where applicable
- Management letter for board and senior leadership
- Remediation tracking sheet for follow-up and closure evidence
- SWIFT CSP gap assessment report and remediation plan (for SWIFT member institutions)
Or email contact@trinitytech.com.np