AUDIT COMMITTEE’S ASSESSMENT OF THE FUNCTIONING OF INTERNAL CONTROL, INTERNAL AUDIT, AND RISK MANAGEMENT SYSTEMS AT TÜRK EXIMBANK, AND INFORMATION ON 2025 ACTIVITIES
As Türkiye’s official export credit agency providing support to the export sector through loan, guarantee, and insurance programs, Türk Eximbank does not primarily operate for profit. However, it strives to achieve an appropriate rate of return to preserve its capital and financial strength, and adheres to generally accepted banking and investment principles in all its activities. In this context, while fulfilling its legal function described as ‘providing support to the export sector,’ the Bank manages the level of risk it is required to assume in a manner that will not weaken its financial strength.
In accordance with the regulatory provisions published by the BRSA pursuant to Banking Law No. 5411, the necessary organizational structures and internal systems units have been established within the Bank and an Audit Committee has been formed. The Internal Audit Directorate, Internal Control Directorate, Risk Management Directorate and Regulatory Compliance Directorate operate under the Audit Committee, which consists of two members selected by the Board of Directors from among its own members.
In 2025, the Audit Committee held 22 meetings and passed 72 different resolutions.
Internal Audit
The Internal Audit Directorate, established to support the Board of Directors in effectively carrying out its audit and oversight activities and operating under the Board of Directors through the Audit Committee, functions within the framework of the Internal Audit Regulation, which was enacted under the Regulation on Internal Systems of Banks and the Internal Capital Adequacy Assessment Process.
Within this scope, the Internal Audit Directorate:
- Audits the compliance of the Bank’s activities with the Law and other relevant legislation, as well as with the Bank’s internal strategies, policies, procedures, and other internal regulations.
- The Bank’s internal control and risk management systems and governance processes are assessed using a risk-oriented approach.
- The accuracy and reliability of accounting records, financial statements, and internal reporting are examined.
- Audits the operation, reliability, and adequacy of the Bank’s information systems, information security, and communication infrastructure.
- The transactions, processes, and activities of Head Office units, regional directorates, and branches are audited.
- The Bank conducts examinations and investigations when deemed necessary.
The Internal Audit Directorate, tasked with the periodic and risk-based audit of all the Bank’s activities without any restrictions, adopts a working approach that ensures the effective use of available resources and the execution of activities in a manner that provides the maximum contribution to the Bank, while demonstrating impartiality, independence, and necessary professional diligence in fulfilling its duties.
Annual audit plans are prepared by the Internal Audit Directorate, taking into account risk matrices and other comprehensive criteria, and are implemented upon the approval of the Audit Committee and the Board of Directors.
Audit reports and activities conducted within the framework of the annual audit plan are submitted to the Board of Directors through the Audit Committee; actions taken in response to identified issues are systematically monitored and reported. The Board of Directors regularly monitors the activities of the Internal Audit Directorate through quarterly activity reports submitted via the Audit Committee.
In accordance with the relevant legislation published by the BRSA, the boards of directors of banks are required to prepare a Management Declaration each year and to subject it to independent audit. The declaration must include assessments of the effectiveness, adequacy and compliance with applicable legislation of internal controls over their information systems and business processes. In this context, control and audit activities for the information systems and business processes that form the basis of the Management Declaration were carried out in coordination with the Internal Control Directorate and the Internal Audit Directorate. The resulting report was submitted to the Board of Directors during the reporting period.
In 2025, the Internal Audit Directorate continued its audit and advisory activities in line with a risk-based audit approach, contributing to the strengthening of the Bank’s corporate governance structure, enhancing the effectiveness of its internal systems, and supporting regulatory compliance of its activities. Audit activities were carried out based on the principles of impartiality and independence, with professional diligence, and with the goal of creating added value for the Bank.
Internal Control
The Internal Control Directorate, which operates under the Board of Directors through the Audit Committee, in accordance with the Internal Control Directorate Regulation established under the Regulation on Internal Systems of Banks and the Internal Capital Adequacy Assessment Process, is responsible for:
- Establishing functional segregation of duties, allocation of responsibilities, and creation of workflow charts within the Bank,
- The integrity and reliability of the accounting and financial reporting system and information systems, and the timely availability of information,
- The functionality of internal communication channels that ensure the sharing of generated information and encountered problems with relevant personnel,
- Identifying deficiencies or weaknesses in the design or operation of internal control mechanisms embedded in information systems applications used during the execution of banking processes, including credit, insurance, treasury, accounting, financial reporting and payment systems,
- Whether manual and system-based approval mechanisms for critical transactions exist and operate and whether limitations are complied with,
- Controls related to the compliance of the Bank’s activities and products with the Law and other relevant legislation, as well as new product processes,
- The implementation of established rules for the recording, safekeeping, and accessibility of documents and assets held in physical vaults, including, in particular, collateral received,
- The existence and currency of business continuity management plans, including the information systems business continuity plan and contingency and emergency plans,
- The compliance of information systems management activities at the Bank and at its external service providers, the processes supporting these activities, and the established information systems controls with legislation and with the Bank’s internal policies, procedures, and standards and is tasked with monitoring and control activities that oversee these matters.
In this context, the Internal Control Directorate carried out control activities for the Bank’s units, branches, and processes within the framework of the internal control plan in 2025. The findings were shared with the relevant units, guidance was provided to remedy these deficiencies and correct shortcomings, and the outcomes of actions taken by the relevant units were monitored.
The Internal Control Directorate Activity Reports, prepared quarterly on these internal control activities, were submitted to the Audit Committee. Furthermore, the control and audit activities over information systems and banking processes that underpin the Management Declaration to be provided to the independent audit firm were carried out by the Internal Control Directorate and the Internal Audit Directorate, and the resulting report was submitted to the Board of Directors through the Audit Committee.
Risk Management
The duties of the Risk Management Directorate, within the framework of the Risk Management Directorate Regulation and Risk Management Policy approved and enacted by the Bank’s Board of Directors, are as follows:
- Within the framework of the principles approved by the Bank’s Board of Directors, to identify, measure, analyze, manage, and monitor all risks to which the Bank is exposed, taking into account the Board-approved risk appetite levels, and to establish and review risk policies and application procedures,
- To monitor the adequacy and effectiveness of the established risk management systems, to examine all risks within the framework of national and international regulations, to carry out profit and cost calculations for managing these risks in cooperation with the relevant departments, and to submit reports containing risk information to the relevant authorities in a timely manner.
The Bank’s risk management activities are carried out through the Credit Risk, Market and Other Risks, Credit Risk Control, and Credit Models Assessment Departments, in accordance with the Regulation on Internal Systems of Banks and the Internal Capital Adequacy Assessment Process and other relevant regulations, as well as BRSA Best Practice Guidelines. The aim is to embed a risk culture throughout the Bank, continuously improve systems and human resources, and align the risk management function with best practices.
Within the scope of risk management activities:
Under the heading of Credit Risk, risks arising from cash and non-cash loan transactions are monitored within the scope of regulatory and Bank-specific limits. The largest risk category undertaken by the Bank is credit risk, within which the largest share is composed of direct or indirect commercial bank risk. Therefore, cash and non-cash limits extended to banks are evaluated in detail and updated when necessary. Risk monitoring is also carried out on a customer basis using various concentration metrics. Reporting on credit risk to the BRSA is done using the standard method. Counterparty Credit Risk, a sub-component of credit risk that refers to losses arising from the default of banks involved in derivative and repo transactions and potential deteriorations in their creditworthiness, is measured using the Basel III Standardized Approach and included in capital adequacy calculations.
Market Risk is calculated monthly using the standard method determined by the BRSA and is included in the calculation of the Capital Adequacy Ratio. To effectively control interest rate risk and currency risk, which are the main components of market risk, it is essential to manage transactions in money and capital markets in a diversified manner, considering parameters such as instrument, maturity, currency, and interest rate type. At Türk Eximbank, a mission bank, the trading portfolio that underlies market risk accounts for a negligible share of risk-weighted assets; consequently, the market risk capital requirement is also very low. Türk Eximbank applies hedge accounting principles for derivative transactions.
Operational Risk involves identifying risks related to banking activities that arise from inadequate or failed internal processes, people, and systems, or from external events, as well as assessing and monitoring controls for these risks. Within the framework of policies set by the Board of Directors, the function of managing operational risk is carried out by the Operational Risk Committee. Operational risk, one of the capital adequacy items, is calculated annually using the basic indicator approach and reported to the BRSA. In addition, records subject to operational risk in the Operational Risk Loss Database are analyzed within the risk appetite framework, taking into account their materiality. IT risks, another source of Operational Risk, are managed through an independent risk management process and are included in the integrated risk matrix, which aggregates the impact and probability of all the Bank’s risks.
In addition to the Pillar I risks defined under the Basel framework—namely credit, market, and operational risks—qualitative and/or quantitative studies are also conducted for Pillar II risks. These include country risk, concentration risk, structural interest rate risk, liquidity risk, sustainability- and climate-related financial risks, and reputational risk. All risks to which the Bank is exposed are closely monitored within the framework of early warning, risk appetite, and limit levels approved by the Board of Directors. The Sustainability and Climate-Related Financial Risks Committee was established by a Board of Directors resolution to monitor the Bank’s compliance with sustainability and climate-related financial risks and to undertake improvement efforts, taking into account TSRS studies.
The ICAAP Report, prepared based on previous year-end actuals and including capital planning for the next three years, together with the attached Stress Tests, was approved by the Board of Directors and submitted to the BRSA by the end of March in accordance with the BRSA’s applicable legislation. Risk appetite levels approved by the Board of Directors have been established for the risk types the Bank considers significant, as set out in the Risk Appetite section of the ICAAP Report, and it has been decided that action plans will be triggered if those levels are exceeded.
In the Stress Tests and Scenario Analyses, economic capital and capital requirement calculations are performed for Credit Risk under scenarios of country rating downgrade, increased loss given default rates in the event of default and exchange rate increase; for Market Risk, Value at Risk is calculated using the Historical Simulation Method under currency shocks for informational purposes; for Liquidity Risk, idiosyncratic and systemic stress tests as well as reverse stress tests are conducted; for Sustainability and Climate-Related Financial Risks, stress tests are run under various scenarios; and for Operational Risk, capital requirement calculations are also performed by deriving various scenarios from the loss database in which units record data, in line with the Basel III Standard Method.
The results of stress tests conducted using internal models in addition to standard methods also demonstrate that the Bank can operate smoothly even under intense stress factors, thanks to its stable and strong capital structure.
For Liquidity Risk, which is closely monitored at the Bank, real-time cash inflows and outflows are tracked, and the continuity and sustainability of liquidity adequacy are ensured through gap analyses, scenario analyses, and stress/reverse stress tests conducted within the framework of the Liquidity Risk Management Policy. Additionally, the Contingency and Emergency Plan includes a set of rules that categorizes the actions to be taken based on the severity of the event in case of a liquidity squeeze.
Regulatory Compliance
The Regulatory Compliance Directorate monitors legal regulations to ensure the Bank’s activities comply with applicable legislation and informs relevant units of changes in legal regulations through announcements. Before draft legislation related to banking comes into effect, information is provided about the drafts to determine their potential impact on the Bank, and the Bank’s opinions and suggestions are obtained and shared with regulatory authorities.
When necessary, notification and coordination processes are carried out to ensure the participation of relevant units in meetings held at the Banks Association of Türkiye. The Bank participates in working groups established within the Association with the relevant business units. Coordination processes are carried out to respond on behalf of the Bank to requests for opinions submitted to the Banks Association of Türkiye, based on the views received from the relevant business units.
The Directorate establishes the legislative framework to which the Bank is subject, regularly reviews it to ensure that it remains up to date, and assesses the regulatory compliance of products and services that will be developed or of existing products and services to be revised within the Bank.
Efforts are made to write and regularly review regulations, policies, procedures, and guidelines that explain the work and transactions carried out within the Directorate.
Opinions are provided to ensure that the Bank’s activities are carried out in accordance with the Banking Law and related legislation, internal policies and rules, and the Bank’s Articles of Association. Coordination with relevant units is maintained to update processes in line with regulatory changes to ensure compliance.
Key points of legislative changes are shared with the entire Bank through monthly and annual Legislation Bulletins.
Regulatory Compliance checks are performed to determine the impact of regulatory changes on the Bank’s operations and the actions that need to be taken, and they are reported semiannually.
Compliance activities to prevent, monitor, and control risks related to money laundering, Counter-Terrorist Financing (CTF), and the proliferation of weapons of mass destruction are carried out within the Directorate. In this context, to monitor international sanctions, controls are carried out regarding the decisions of institutions and organizations such as the United Nations Security Council, the US Office of Foreign Assets Control (OFAC), and the European Union.
The Bank identifies and classifies its potential risks in Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) matters, defines measures to mitigate these risks, and evaluates the effectiveness and efficiency of these measures. Additionally, current compliance risk trends are monitored, and the Bank’s products/services and customer profile are systematically subjected to risk analysis in light of these risks.
As part of compliance processes, the Bank responds to requests for information and questionnaires from related parties, as well as information and document requests from official institutions—primarily MASAK—relating to money laundering and Counter-Terrorist Financing (CTF). Asset freeze decisions published by Turkish authorities are monitored, and necessary actions are taken.
Awareness of the Anti-Bribery, Anti-Corruption and Ethics Policy, which aims to clearly state the Bank’s commitments on these issues; identify and prevent potential actions that could be considered in this context; establish rules and responsibilities; raise employee awareness; and ensure compliance with national and international regulations, is promoted and the related processes are implemented.
Training for Bank personnel on topics covered by national and international legislation and regulations is organized in cooperation with Human Resources. Training content is updated, taking into account the minimum requirements set by legislation and international developments. In addition, Directorate personnel attend seminars, training sessions and workshops related to their business activities.
In accordance with the Regulation on the Compliance Program for Obligations Regarding the Prevention of Money Laundering and Counter-Terrorist Financing (CTF), published in the Official Gazette No. 32994 on August 22, 2025, which subjects the Bank to the Compliance Program, efforts have been made to meet the requirements stipulated in the legislation; the corporate compliance infrastructure for preventing money laundering, Counter-Terrorist Financing (CTF), and the financing of the proliferation of weapons of mass destruction has been strengthened. In this context, corporate policies and procedures have been prepared and enacted, a Compliance Officer and Deputy Compliance Officers have been appointed, and authorization processes have been completed. Monitoring and control activities have been established within the scope of the Compliance Program, and processes for suspicious transaction reporting, reporting obligations, and the retention of documents and records have been established in accordance with the legislation; compliance training for personnel has been planned and implemented, and the effectiveness of the processes has been evaluated through internal audit activities.
Corporate compliance activities are carried out by participating in the Bank’s internal committees, serving as secretariat and as a member.
Compliance activities related to interest-free banking transactions are carried out within the Directorate. These transactions are governed by Article 77 of the Banking Law and the Regulation on Credit Operations of Banks published by the Banking Regulation and Supervision Agency (BRSA) in the Official Gazette No. 30666 dated January 25, 2019 (as amended, Official Gazette No. 32406 dated December 21, 2023), and are based on the provision that development and investment banks and participation banks may provide financing in accordance with regulations governing their fund utilization methods and restricted to funds they have provided exclusively through interest-free methods.
In this context, opinions and assessments regarding the compliance of transactions with participation finance activities are shared with the relevant units, necessary information is provided, and compliance checks are performed.
In line with the Directorate’s activities, the aim is to ensure the Bank’s compliance with current national/international legislation, internal policies and procedures, organizational management, and ethical standards, and to contribute to the protection of the Bank’s reputation.
Nail Olpak,
Audit Committee Member
D. Bahar Özgün Yılmaz,
Audit Committee Member