SBV Circular 83: Having a Policy Is Not the Same as Knowing Whether Decisions Follow It
Banks do not normally lack policies. Circular 83 raises a harder question: six months later, can the bank show that an actual decision followed the policy that applied to it?
Summary
Circular 83/2025/TT-NHNN was issued by the State Bank of Vietnam on 31 December 2025 and took effect on 1 July 2026. Article 11 requires control activities across the bank to comply with the Circular and with the bank’s own internal regulations, and Article 10 requires records relating to the internal control system to be retained.
Banks do not normally lack policies, so this paper examines a narrower operational question: when a case was closed six months ago, can the bank show that the approval its own policy required was completed, by someone with the authority to give it, before the case was allowed to close?
The term policy conformance and the practical test set out here are Blitz Research interpretations, not explicit requirements of Circular 83, and this paper is not legal advice.
Banks do not normally lack policies.
They have internal regulations, procedures, approval limits, escalation rules and exception processes.
The harder question is what happens after those rules are approved.
How does the bank know that an actual decision followed the policy that applied to it?
Consider a simple example.
A bank's internal policy says that a high-risk case must receive supervisory approval before it can be closed.
Six months later, Internal Audit selects the case for review. The bank can show the policy. It can show who closed the case and when it was closed.
But can it show that the required supervisory approval was completed, by a person with the bank-defined authority, before the case was allowed to close?
This is where having a policy and following a policy become two different things.
1. What Circular 83 says
Circular 83/2025/TT-NHNN does not only deal with how banks write internal rules.
Article 11 requires control activities across the bank to ensure compliance with the Circular and with the bank's own internal regulations.
Article 10 also requires records and documents relating to the internal control system to be retained so they can be provided to internal audit, independent audit and competent authorities.
In simple terms, the bank needs internal rules, controls to support those rules, and evidence of how its internal control system operated.
Circular 83 does not say that every decision must be checked by a central software platform. It does not prescribe a particular technology.
2. Knowing the rule is only the first step
A policy-management process can answer important questions.
What is the current policy? Who approved it? When did it take effect? Which version replaced the old one?
But those questions do not tell us what happened in an actual case.
Return to the high-risk case. The policy may clearly require supervisor review. The policy may have been properly approved and still be current.
None of that proves that the bank's required supervisory approval was completed before the case was allowed to close.
The policy tells us what should happen. The decision record should show whether the required control was satisfied before the decision was allowed to proceed.
3. This is what we mean by policy conformance
Blitz Research uses the term policy conformance for this simple question:
Did the actual decision follow the policy that applied to it?
Here, conformance means evidence that the bank-defined control step was satisfied. It does not mean proving that a supervisor read every document carefully or that the person's judgement was correct.
This is different from deciding what the bank's policy should be.
The bank defines its policy. It decides its limits, approval requirements, escalation rules, exceptions and responsibilities.
The conformance question starts after that: when a decision is made, were those bank-defined conditions followed?
4. A workflow can be correct and the policy can still be missed
Banks use workflows to move work from one step to another. These workflows are important and may already enforce many internal rules.
But not every policy condition necessarily sits inside the same workflow.
For example, a case-management system may know that a case is ready for closure. A separate risk system may hold the risk classification. An authority matrix may sit elsewhere. An exception may require approval by another function.
The workflow can therefore complete its configured steps correctly while a relevant policy condition has not been checked.
So the question is not only:
Did the workflow complete?
It is also:
Did the decision follow the policy conditions that applied to it?
5. Exceptions make the problem easier to see
Normal cases usually follow the normal path. Exceptions are where the difference becomes clearer.
Suppose a transaction is normally within an officer's approval limit. During review, however, a condition is identified that the bank's policy treats as an exception.
The policy says the matter must now be escalated.
The practical questions are simple. Was the exception recognised? Was the matter escalated? Was the required approval obtained before the decision proceeded?
The bank may have a perfectly good exception policy. The issue is whether that policy was followed in this particular decision.
6. The policy version also matters
Policies change over time.
A limit may increase or decrease. An approval requirement may change. A new exception may be introduced. Responsibility may move from one function to another.
If an auditor reviews a decision made six months ago, today's policy may not be the right policy to test it against.
The relevant question is: what rule was in force when the decision was made?
This is why policy versioning can matter at the decision level, not only in the policy library.
7. A simple test for banks
A bank does not need to turn every sentence in every policy into a software rule to examine this problem.
It can start with a sample of important decisions and ask:
- What decision was made?
- Which internal policy or rule applied at that time?
- Which version was in force?
- What control did that policy require before the decision could proceed?
- Was the required approval, escalation or other recorded control step completed?
- Was there an exception or override?
- If there was, was it handled according to the bank's rules?
- Can the bank produce the evidence?
This is a Blitz Research test. Circular 83 does not prescribe this checklist.
8. This does not mean every policy should be automated
Some banking rules define clear conditions that can be checked automatically. Other rules depend on human judgement.
A rule such as 'approval above this limit requires Level 2 authority' may be relatively easy to test.
A rule requiring an investigator to decide whether activity is unusual still depends on professional judgement. A system may record that the required decision or approval occurred, but that does not prove the quality of the person's judgement.
The objective should therefore not be to turn the entire policy library into software.
A more practical starting point is to identify the rules that directly affect whether a decision can proceed, must be reviewed, must be escalated or must stop.
9. More automation does not remove the policy question
As banks automate more processes, it may become easier to see what the system did.
Logs can show that a button was clicked. A workflow can show that a step was completed. An AI system can show that a recommendation was generated.
But the bank still has to ask whether the resulting decision followed its own rules.
Automation changes how decisions are made. It does not remove the bank's policies.
10. The question worth asking
Banks already know how to write and approve policies.
The harder operational question is whether those policies can be seen in the decisions the bank actually makes.
That gives us a simple distinction:
Policy: What does the bank require?
Conformance: Did the actual decision follow what the bank required?
Circular 83 requires control activities to ensure compliance with the bank's internal regulations. It does not prescribe one method for checking every individual decision.
For banks, the practical question remains:
When policy says what must happen, how does the bank know that it actually happened?
Research note
This paper discusses selected operational implications of Circular 83/2025/TT-NHNN. It is not legal advice.
The term policy conformance and the practical test in this paper are Blitz Research interpretations. They are not terms presented as explicit requirements of Circular 83.
Banks should assess the official Vietnamese text of Circular 83 against their own internal regulations, control arrangements, systems and regulatory obligations.
Primary references
State Bank of Vietnam, Circular 83/2025/TT-NHNN, issued 31 December 2025, effective 1 July 2026.
Article 10 - retention of records and documents relating to the internal control system.
Article 11 - control activities across the bank, including compliance with the Circular and the bank's internal regulations.
The official Vietnamese text should be treated as the controlling reference.
Discuss your institution’s governance journey
Talk to our team about operationalising Circular 83/2025 in your environment.
Contact an expert