IT Audit for BPR
IT audit services for BPR and BPRS: meeting POJK 34/2025 requirements
In short
POJK 34/2025 requires periodic IT audit for BPR and BPRS, plus an independent external review every three years. Audit scope and what the report covers.
Most BPR leadership understands that POJK 34/2025 brings new IT obligations. What receives less attention is the audit requirement specifically: not a one-off assessment before the deadline, but a programme that runs periodically, with an external review component that must be carried out by an independent party at least every three years. This is not something you can defer to the months before December 2026. An audit done in a rush rarely surfaces findings that the bank can genuinely act on, and it leaves the institution in a weaker position than if the work had been paced from the start.
This page covers Alpha Code's IT audit service for BPR and BPRS: what gets assessed, how the process works, and why auditor independence is a requirement that cannot be set aside. For the complete picture of POJK 34/2025 obligations, including IT governance, risk management, and cyber resilience, see the BPR IT and cybersecurity compliance page.
The IT audit obligations in POJK 34/2025
POJK 34/2025 requires BPR and BPRS to carry out periodic IT audit. The obligation has two components: an internal audit conducted annually, and a review by an independent external party at least every three years. Both are mandatory, not discretionary.
The obligation applies from the regulation's effective date of 18 December 2026. Banks without a running IT audit programme need to design one before that date: defining scope, selecting who will conduct it, and building the documentation infrastructure that supports a repeating audit cycle.
| IT audit obligation | Status |
|---|---|
| Annual internal IT audit | Mandatory |
| Independent external review at least every three years | Mandatory |
| Scope covers governance, IT risk, information security, and service continuity | Mandatory |
| Findings reported to the board of directors and commissioners | Mandatory |
| Follow-up action on audit findings and recommendations | Mandatory |
The three-year cycle: understanding the rhythm
A question that frequently comes up when we speak with BPR directors is the difference between the annual internal audit and the three-year external review. They are not the same thing, and both must happen.
The annual internal audit is typically conducted by the bank's internal audit function or with the assistance of a firm contracted by the bank. Its purpose is to confirm that IT controls are working as intended and that no deterioration has gone undetected. In year three, that internal audit is supplemented by a review from an external party: one that has no involvement in implementing or managing the systems being assessed.
Preparing for an external review is different from an ordinary internal audit. Policy documentation, system logs, change records, and disaster recovery test results all need to be available and organised. An external reviewer arrives to assess that material, not to help compile it. Banks that wait until the third year to start getting organised tend to find that most of the preparatory work needed to happen in year one and year two.
What an IT audit covers
The scope of an IT audit follows the areas POJK 34/2025 regulates. IT governance is the starting point: whether clear policies exist, whether roles and responsibilities are assigned at the right level, and whether technology decisions are made with a structure the board can oversee.
IT risk management is assessed for process: whether the bank identifies the risks that come from using technology, measures them consistently, and maintains mitigation steps proportionate to those risks. Information security covers the protection of customer and operational data, access controls, and detection of unauthorised attempts against systems.
Service continuity is assessed through the existence and quality of the disaster recovery plan: whether it is documented, whether it has been tested, and whether the results are recorded and acted on. Third-party IT providers are also in scope, because POJK 34/2025 requires the bank to retain accountability for services managed by vendors, not only for systems operated in-house.
How Alpha Code runs IT audit for BPR
Every engagement starts with a scoping session to map the system architecture, define the boundaries of the review, and identify the risk areas most relevant to that particular bank. Good scoping prevents the audit from becoming too broad to be useful or too narrow to catch what matters.
Evidence collection happens through document review, interviews with key staff, and targeted technical inspection of in-scope systems. We do not ask banks to produce documentation that should not already exist. A missing document is recorded as a finding, not papered over or excused.
Assessment and analysis produces a findings list ranked by risk level. The issues with the most impact on POJK 34/2025 compliance and on the bank's operational security appear first, with enough explanation that directors can understand why a finding matters without needing a technical background to read it.
The final report contains findings, context, and recommendations the bank can act on. We provide a clarification session after delivery so that management and the IT team can ask questions and build a remediation plan with a clear foundation.
Why auditor independence cannot be set aside
An external review carries different value from an internal audit, not because an external auditor is inherently more capable, but because they have no conflict of interest in the result. A person who built or manages the system being assessed naturally tends to see its strengths and overlook its weaknesses. This is not a question of honesty; it is how an insider's perspective works.
POJK 34/2025 explicitly requires the external review to be conducted by an independent party. That means whoever sold, implemented, or routinely manages the systems being assessed cannot simultaneously serve as the external reviewer for those same systems. Alpha Code works as an external party with no attachment to any core banking vendor or specific product used by the BPR. We assess the practices in place, not the interests of a commercial relationship.
Where Alpha Code has previously assisted a bank with certain aspects that fall within the audit scope, we discuss this upfront and establish a clear contractual separation before the engagement begins.
Next steps
Building a sustainable IT audit programme is easier done in stages than all at once before a deadline. Banks that start now have time to address findings from the first audit before the three-year external review arrives, and will have organised documentation that makes each subsequent cycle less demanding.
If you want to discuss the right scope for your BPR or BPRS, or understand what needs to be in place before a first audit, our team is ready to assess your starting position and help you map a structured path forward.
References
Frequently asked questions
POJK 34/2025 requires periodic IT audit. In practice, BPR run an internal audit annually and involve an independent external party at least every three years.
Related
Solutions
From the blog
Our services
Ready to strengthen your security posture?
Talk to our Jakarta-based team about your requirements.
Jakarta-based team. We reply within one business day.