Credit risk governance is more than credit approval
Credit governance is often described through approval authorities, committee terms of reference and portfolio limits. Those matter, but they are only the visible structure. Effective governance also depends on whether risk appetite reaches day-to-day underwriting, whether deteriorating exposures are identified early, whether classifications and provisions withstand challenge, and whether control failures are escalated and closed.
This is where internal audit belongs in the model. It should not own credit policy, approve lending decisions or operate portfolio monitoring. Its role is to provide independent assurance that the board-approved framework is suitably designed and working in practice. That distinction is especially important as Gulf regulators deepen their focus on asset quality, governance and the effectiveness of banks' control functions.
The UAE sets out a direct assurance role
The Central Bank of the UAE is explicit about internal audit's place in credit risk governance. Its Credit Risk Management Standards require internal audit to review and report on the suitability and efficiency of the credit risk management framework across the licensed financial institution.
The prescribed minimum scope is notable. It includes samples of material credit facilities, wholesale restructurings, decisions not to identify a significant increase in credit risk, material Stage 3 facilities and breaches of credit requirements. A separate provision on credit risk oversight functions and roles reinforces that internal audit, compliance and external audit must play an active control and oversight role throughout the institution.
The practical implication is that a generic audit of policy compliance is unlikely to be enough. Assurance should test judgement-heavy decisions and trace them from origination through monitoring, classification, restructuring and recovery. It should also assess whether issues found in individual files point to wider weaknesses in underwriting standards, data, delegated authorities or management information.
Oman takes a broader, principle-led route
Oman's framework reaches a similar governance outcome through a less prescriptive route. Royal Decree 2/2025 replaced the former Banking Law and modernised the legal basis for financial stability, institutional governance and CBO supervision. The Central Bank of Oman's regulatory framework combines lending and concentration limits, asset-classification and provisioning requirements, and an expectation that licensed banks apply international standards in internal audit, risk management, compliance and corporate governance.
The CBO's supervisory framework then tests how those arrangements operate. Annual on-site examinations and regular off-site analysis consider asset quality, risk management, internal controls and governance, while monitoring compliance with personal-loan, mortgage and lending-ratio limits. Deficiencies in financial condition, controls or systems can be escalated to the board for corrective action.
Unlike the UAE standard, the public Oman material does not set out the same detailed minimum sample of credit decisions for internal audit. The sound Oman interpretation is that internal audit should independently assess whether the bank's credit governance, controls and regulatory compliance are adequate for its portfolio and risk profile, using recognised international practice to determine the depth of coverage.
A clear three-lines operating model
For both jurisdictions, accountability works best when each line has a distinct mandate. The business owns the credit decision and the continuing performance of the exposure. Credit risk provides independent challenge, portfolio oversight, policy ownership and escalation. Internal audit assesses whether both lines, and the governance above them, are working as intended.
A credible audit universe should cover governance and risk appetite; underwriting and delegated authority; collateral and covenant controls; early-warning and watchlist processes; IFRS 9 staging and provisioning; restructuring and forbearance; concentration and connected-party risk; problem-credit management; regulatory reporting; model and data governance; and the closure of earlier findings.
Audit coverage should also be risk-based rather than mechanically cyclical. Rapid portfolio growth, policy exceptions, repeated overrides, sector stress, weak collateral data, rising arrears or unusual staging outcomes should all influence where assurance is directed and how quickly it is performed.
What boards should ask for now
Boards and audit committees should be able to see the line from risk appetite to individual credit outcomes. That requires reporting which distinguishes isolated file defects from systemic weaknesses, explains the financial and regulatory consequence of findings, identifies accountable executives and tracks remediation to verified closure.
Management should also confirm that internal audit has the credit expertise, data access and organisational independence needed to challenge complex judgements. In the UAE, that capability must support the specific assurance scope set by the CBUAE. In Oman, it should translate the CBO's broader standards and supervisory focus into coverage proportionate to the bank's products, concentrations and emerging risks.