The risks of outsourcing information technology by a bank must be balanced by the secrecy obligations set forth under the Turkish Banks' Act Number 4389, which is not wholly clear on this matter. The Turkish Banking Regulation and Supervision Agency (BRSA) had issued a regulation in 2001, the Regulation on Banks' Internal Control and Risk Management Systems, which set forth the principles and procedures of the internal monitoring, control and risk management systems that banks must set up to monitor and control the risks to which they are exposed. Following this, the BRSA has announced a draft regulation on its website, the Draft Communiqué regarding the application of the Banks' Internal Control and Risk Management Systems Regulation.
July 31 2003