Financial institutions in Pakistan are the most heavily supervised technology operators in the country. Their obligations are not general good practice — they are enforceable regulatory requirements, examined on inspection, with consequences for the institution and for its senior management.

This is written for banks, microfinance banks, EMIs, PSOs and PSPs, and for the vendors that serve them.

The framework

The State Bank of Pakistan issues and updates frameworks and circulars governing technology in the sector, addressing in substance:

  • Governance — board and senior management accountability for technology risk, with a defined risk management function
  • Information security, access control and segregation of duties
  • Outsourcing, including cloud, with materiality assessment, due diligence, approval requirements and continuing oversight. The institution remains responsible for the outsourced function
  • Business continuity and disaster recovery, with tested plans and defined recovery objectives
  • Incident reporting to the regulator within specified timelines
  • Digital payment security — authentication, transaction limits, monitoring and customer notification
  • Customer protection and complaint handling, including for unauthorised transactions
  • Audit — internal, and independent assessment

Requirements are updated regularly, so the current instructions must be confirmed rather than assumed from an earlier framework.

Payment system operators and providers, and EMIs, operate under the payment systems regime with its own conditions. See fintech licensing.

The obligations institutions most often trip on

Outsourcing without the assessment. Engaging a vendor for a material function — core banking, hosting, card processing, a customer-facing app — without the materiality assessment, due diligence and approvals the framework requires. The contract is signed by procurement; the regulator asks compliance.

Vendor contracts missing regulatory clauses. The agreement must give the institution, its auditors and the regulator the access, audit and information rights the framework contemplates, along with security, sub-contracting, continuity, incident notification and exit provisions. Standard vendor paper contains none of this. See cloud contracts and data localisation.

Late incident reporting. Reporting windows are short and are measured from detection. An institution that spends three days establishing the facts before notifying has already breached.

Access not withdrawn for leavers and for vendor staff — the most common finding in every inspection, everywhere.

Untested continuity plans. A documented plan nobody has exercised does not satisfy the requirement and does not work when needed.

Weak customer authentication or notification on digital channels, which then determines liability when a customer disputes a transaction. See card and ATM fraud and bank liability.

When an incident happens

The sequence matters, and it runs in parallel rather than in series:

  1. Contain without destroying evidence — isolate rather than wipe, and preserve logs before they rotate
  2. Report to the State Bank within the required window, with what is known, updating as the picture develops
  3. Report to law enforcement — unauthorised access, data theft and ransomware are PECA offences and go to the FIA
  4. Notify affected customers where their accounts or data are involved, and tell them what to do
  5. Notify insurers within the policy period
  6. Preserve the record of every decision, with timestamps — the regulator will review your response as closely as the breach

See responding to a data breach and reporting online fraud and cybercrime.

Do not pay a ransom before taking advice — it carries AML and sanctions exposure of its own, quite apart from whether it works.

Customer disputes and liability

Where a customer suffers an unauthorised transaction, the institution's position depends heavily on whether it met its own obligations: was the transaction properly authenticated, were alerts sent, was the customer's report acted on promptly, and did monitoring flag anomalous activity?

Institutions that can evidence compliance defend these claims. Those that cannot face the Banking Mohtasib, the regulator and the courts at once.

Handle complaints through the prescribed grievance process and within its timelines. A complaint mishandled internally becomes a regulatory finding about complaint handling, which is worse than the original dispute.

AML and fraud monitoring overlap

Technology controls and AML obligations intersect constantly — transaction monitoring, customer due diligence, suspicious transaction reporting, and the freezing and unfreezing of accounts. Getting the technology right is part of getting AML right, and failures in either surface in the same inspection.

See AML compliance for smaller businesses, a frozen bank account and asset freezing and release.

Personal exposure of senior management

Regulatory frameworks in this sector place responsibility on named individuals — the board, the chief executive, and the officers responsible for risk, compliance and information security.

Directors and senior officers should understand what has been certified to the regulator in their name, and should ensure that concerns raised internally are recorded and escalated. A person who raised the issue in writing is in a very different position from one who did not. See directors' duties and personal liability.

For vendors serving the sector

If you sell technology to Pakistani banks or payment institutions, expect the institution to pass its regulatory obligations down to you: security standards, audit and regulator access rights, incident notification within hours, restrictions on sub-contracting and data location, continuity commitments, and exit assistance.

Price accordingly, and make sure you can actually perform. A breach notification clause requiring notice within four hours is an operational commitment, not boilerplate. See software development and SaaS agreements and call centres and BPO operations.

Where AI comes in

Institutions are deploying AI in credit decisioning, fraud detection and customer service. Regulated use raises explainability, record-keeping, bias and human oversight questions, and a customer refused credit is entitled to a decision the institution can explain.

Assume that whatever is deployed must be documented, tested and overseen by a human decision-maker. See using AI in your business.

How the firm can help

We advise institutions on technology risk and outsourcing requirements, review and negotiate vendor and cloud agreements so they carry the clauses the framework requires, prepare incident response and reporting procedures, act during live incidents including regulator and FIA engagement, and represent institutions in regulatory proceedings and customer disputes.

We also act for technology vendors negotiating with regulated institutions.

See banking and finance or regulatory and compliance, or contact the firm.