Circular
Medium
IFRS / Accounting Standards

Circular 83/2025/TT-NHNN on the Internal Control System of Commercial Banks and Foreign Bank Branches

RegHub explainer by New MarketerLast updated:

Based on:83/2025/TT-NHNN - Government Official Gazette

This explanation was generated by AI and checked by an automated AI review, not by a human expert. It is not legal, tax or accounting advice and may contain errors. Check the official document before you rely on it.

The State Bank of Vietnam (SBV) has issued Circular 83/2025/TT-NHNN (signed 31 December 2025), a comprehensive regulation on the internal control systems that commercial banks and foreign bank branches operating in Vietnam must maintain. It requires every bank to build its internal control system on a "three lines of defense" model: revenue-generating business units that create risk, a bank-wide compliance and risk management function, and an internal audit function. The rules set detailed requirements for managing material risk categories - credit, market, operational, liquidity, concentration, interest rate risk in the banking book, and model risk - along with an internal capital adequacy assessment process (ICAAP), stress testing, and mandatory annual reporting to the SBV on control results, risk management, and internal audit findings, due 60 to 90 days after each fiscal year end. This is an internal banking-sector governance circular that creates obligations directly for commercial banks and foreign bank branches, not for SMEs, household businesses, individuals, or foreign investors generally. Business owners and accountants have no action to take under this circular; any effect on them would only be indirect, through banks applying stricter credit-assessment procedures.

Scope and applicability

Circular 83/2025/TT-NHNN (signed 31 December 2025, published in Official Gazette No. 114 on 19 February 2026) sets out requirements for the internal control system that commercial banks and foreign bank branches operating in Vietnam must maintain. Commercial banks placed under special control are exempt from Section 9 of Chapter III.

The circular is issued under the Law on the State Bank of Vietnam No. 46/2010/QH12, the Law on Credit Institutions No. 32/2024/QH15 (as amended by Law No. 96/2025/QH15), and Decree 26/2025/ND-CP on the functions, tasks, and organizational structure of the State Bank of Vietnam (SBV).

General requirements for the internal control system

Each bank's internal control system must: comply with the Law on Credit Institutions, this circular, and related legislation; be appropriate to the scale, nature, and complexity of the bank's business; have adequate financial, human, and information-system resources; build and maintain a control culture; and operate a management information system that is reliable, complete, and timely.

The three-lines-of-defense model

  • First line: revenue-generating business units that make risk-taking decisions and are responsible for identifying and controlling risk at the source.
  • Second line: at minimum a compliance function and a risk management function, which set bank-wide risk policy and monitor risk across the institution.
  • Third line: internal audit, which independently assesses the effectiveness of the first two lines.

Model risk management follows its own separate three-lines-of-defense arrangement under the circular's detailed provisions.

Organizational structure and internal policy

A commercial bank must have a Board of Directors/Members' Council, a Supervisory Board, and a CEO (General Director), supported by working committees: a Risk Committee, an Asset/Liability Management Committee (ALCO), a Capital Management Committee, and optionally a Credit Approval Committee. Foreign bank branches have a simpler structure, and their internal audit function follows the parent bank's own rules.

Internal policies must clearly allocate decision-making authority according to risk level. Board members may not approve risk-taking decisions that fall within the CEO's authority (except where a board member also serves as CEO, subject to conflict-of-interest controls), and every bank must adopt a professional code of ethics binding on all staff.

Management information system

Banks must operate a system to collect, process, store, and supply information for management and decision-making, including IT infrastructure, backup systems to prevent disruption, and data-security mechanisms, all of which must be reviewed and reassessed at least once a year.

Reporting to the State Bank of Vietnam

Each year banks must submit four types of reports to the SBV: a self-assessment of control activities, a risk management report, and an internal capital adequacy assessment report (all within 90 days of fiscal year-end), plus an internal audit report (within 60 days; ad hoc audit reports within 7 working days of completion). Supporting records must be kept in full to support SBV inspection and supervision.

Control activities and senior management oversight

Control activities must cover every transaction and business process at the bank. Accounting entries must be checked and reconciled to catch and correct errors promptly. Head offices must be able to oversee branches and dependent units through reporting mechanisms and control personnel who remain independent of, and free from conflicts of interest with, the units they oversee.

Management of material risks

The circular requires banks to manage all material risk categories: credit risk (customer and counterparty); market risk (interest rate, foreign exchange, equity price, commodity price); operational risk; liquidity risk; concentration risk; interest rate risk in the banking book (including gap risk, basis risk, and option risk); and model risk.

For operational risk specifically, banks must adopt a dedicated management strategy, set financial and non-financial loss limits, classify business activities into six groups (interest income, interest expense, services, foreign-exchange trading, trading/investment securities, and other activities), and fully identify risk sources such as internal fraud, external fraud, labor-policy violations, and products or services that do not align with customer interests.

Who is affected

Every obligation in the circular applies directly to commercial banks and foreign bank branches. It does not create any compliance obligation for SMEs, household businesses, individuals, or other non-bank entities.

83/2025/TT-NHNNEffective: July 1, 2026