9.4 Shariah Control Functions & SNC Management

Key Takeaways

  • SGPD 2019 requires three ongoing Shariah control functions: Shariah risk management, Shariah review, and Shariah audit. Shariah research and day-to-day advice are performed by the Shariah committee secretariat (SGF 2010 had listed research as a fourth function).

  • The secretariat provides in-depth Shariah research and daily advice based on SAC rulings and SC decisions. Shariah review, part of the compliance function, regularly assesses whether operations comply with Shariah.

  • Shariah risk management is integrated into enterprise-wide risk management. Shariah audit, part of internal audit, gives independent assurance and reports results to the board and the Shariah committee.

  • Under Section 28(3) of IFSA 2013, an institution that becomes aware of Shariah non-compliance must immediately notify BNM and its Shariah committee, immediately cease the activity, and submit a rectification plan within 30 days.

  • Shariah non-compliant income (SNCI) cannot be recognised as income or distributed to shareholders; it is purified by channelling it to charitable purposes approved by the Shariah committee.

Last updated: October 2026

Shariah Control Functions & SNC Management

A robust Shariah governance policy is only as effective as the operational machinery designed to enforce it. Bank Negara Malaysia's Shariah Governance Policy Document (SGPD 2019) requires every Islamic financial institution (IFI) to perform three control functions on an ongoing basis: Shariah risk management, Shariah review and Shariah audit (paragraph 16.3). Shariah research is now the job of the Shariah committee secretariat, which must be staffed by Shariah-qualified officers. The earlier Shariah Governance Framework (SGF 2010) had listed research as a fourth function.

The control functions sit within the Three Lines of Defence model: the business is the first line, risk management and compliance the second, and internal audit the third. Each senior officer running a control function has direct, unimpeded access to the Shariah committee. Control functions must be independent of business lines and must not take part in revenue-generating activities.


Shariah Research, Secretariat Support and the Control Functions

+--------------------------------------------------------------------------+
|              Shariah Governance Support & Control (SGPD 2019)            |
+--------------------+--------------------+--------------------------------+
| Function           | Where it sits      | Core Focus                     |
+--------------------+--------------------+--------------------------------+
| Shariah research & | Secretariat to the | In-depth research, day-to-day  |
| advice             | Shariah committee  | advice, SC meeting support     |
+--------------------+--------------------+--------------------------------+
| Shariah risk       | Risk management    | Identify, measure, monitor and |
| management         | (second line)      | report SNC risk                |
+--------------------+--------------------+--------------------------------+
| Shariah review     | Compliance         | Regular assessment of actual   |
|                    | (second line)      | compliance with Shariah        |
+--------------------+--------------------+--------------------------------+
| Shariah audit      | Internal audit     | Independent assurance on       |
|                    | (third line)       | controls and compliance        |
+--------------------+--------------------+--------------------------------+

1. Shariah Research and Advice (Secretariat)

Under SGPD 2019 the secretariat to the Shariah committee performs in-depth research on Shariah issues, gives day-to-day advice based on SAC rulings and the committee's decisions, disseminates those decisions, and supports the committee administratively. Officers doing the research and advisory work must be Shariah-qualified. Typical duties include:

  • Preliminary Juristic Research: Conducting comprehensive Fiqh studies on proposed banking products, analyzing classical jurisprudential treatises across the major madhahib, and comparing contemporary resolutions from the SAC BNM, SAC SC, AAOIFI, and the International Islamic Fiqh Academy (IIFA);
  • Product Structuring Support: Collaborating with product development teams, treasury desks, and legal counsel to engineer Shariah-compliant alternatives to conventional financial instruments;
  • Secretariat Support: Preparing detailed research papers, legal memos, and transaction dossiers for Shariah Committee meetings, while meticulously recording meeting minutes, deliberations, and formal rulings; and
  • Day-to-Day Fiqh Inquiries: Providing immediate guidance to front-line business units on routine operational questions within parameters pre-approved by the SC.

2. Shariah Review (Continuous Operational Monitoring)

Shariah Review is part of the IFI's compliance function (second line of defence), led by the senior officer responsible for compliance. While Research focuses on product design prior to launch, Review focuses on execution fidelity during live operations. Its core responsibilities include:

  • Continuous Assessment: Conducting regular, concurrent examinations of business activities, operational workflows, customer onboarding files, executed contract agreements, and marketing materials to ensure adherence to SC decisions;
  • Transaction Testing & Branch Sampling: Periodically visiting physical branches, business centers, and digital operations to sample live customer files, verify asset delivery documentation, and confirm that sale sequences (e.g., purchasing the commodity before executing Murabahah sales) were strictly executed;
  • Pre-Execution Vetting: Reviewing customized, non-standard transactions and complex syndicated corporate facilities prior to drawdown; and
  • Reporting: Regularly reports Shariah non-compliance issues and findings to the board, the Shariah Committee and senior management, and updates them on new SAC rulings and regulatory developments. It also ensures staff are trained on relevant Shariah requirements.

3. Shariah Risk Management (Identification & ERM Integration)

Shariah Risk Management (SRM) is the responsibility of the senior officer accountable for risk management, and it embeds Shariah non-compliance risk into the institution's Enterprise Risk Management (ERM) framework. Operating alongside conventional credit, market, and operational risk teams, SRM ensures that Shariah risks are systematically managed through recognized risk tools:

  • Risk Identification: Systematically identifying vulnerabilities where operational failures could trigger Shariah Non-Compliance (SNC) events (e.g., executing sales without valid asset ownership, late payment penalty calculation flaws, or documentation mismatches);
  • Measurement and Key Risk Indicators (KRIs): Establishing quantitative and qualitative KRIs to monitor potential SNC exposures, tracking metrics such as operational exception logs, staff compliance training completion rates, and documentation error frequencies;
  • Control and Mitigation: Formulating internal risk control standards, risk appetite statements, and contingency remediation workflows; and
  • Integration: Ensuring that Shariah risk is recognized as an integral component of the institution's Internal Capital Adequacy Assessment Process (ICAAP) and overall operational risk profile.

4. Shariah Audit (Independent Ex-Post Assurance)

Shariah Audit functions as the Third Line of Defense, delivering independent, objective assurance to the highest levels of governance. Unlike Review officers (who may possess pure Shariah backgrounds), Shariah Auditors are internal audit professionals who possess specialized competency in Shariah auditing methodologies. Key attributes include:

  • Ex-Post Periodic Examination: Conducting retrospective, scheduled audits of business units, control systems, IT infrastructure, and governance processes after transactions have settled;
  • Assessing Internal Control Effectiveness: Evaluating whether the first and second lines of defense (Research, Review, and Risk Management) are operating effectively to mitigate SNC risks;
  • Independence and Reporting: Shariah audit is part of the internal audit function, which reports to the Board Audit Committee (BAC). SGPD 2019 requires audit results to be communicated to the board and the Shariah Committee through audit reports with findings, recommendations, and management's action plans; and
  • Comprehensive Audit Program: Executing a multi-year, risk-based Shariah audit plan approved by both the BAC and the Shariah Committee.

Comparative Matrix: Shariah Review vs. Shariah Audit

A clear understanding of the distinction between Shariah Review and Shariah Audit is essential for regulatory compliance and professional examination success:

DimensionShariah ReviewShariah Audit
Defense LineSecond Line of DefenseThird Line of Defense
Timing & CadenceContinuous, regular, concurrent, and ongoing monitoringPeriodic, scheduled, retrospective (ex-post) assurance
Primary ObjectiveDetect operational deviations and ensure daily compliance with SC rulingsIndependently evaluate the adequacy and effectiveness of internal controls and governance
Primary Reporting LineReports regularly to the board, the Shariah Committee and senior management; sits under compliancePart of internal audit, reporting to the Board Audit Committee (BAC); results also go to the SC
MethodologyWorkflow vetting, pre-execution checks, transaction sampling, branch spot-checksRisk-based audit testing, internal control evaluations, substantive testing, process re-performance
Independence LevelOperationally independent from business units; part of risk management infrastructureHighest level of independence; completely detached from executive and risk operations
Staff ProfileOfficers qualified for compliance work with sound knowledge of Shariah requirements (may include Shariah-qualified officers)Internal auditors qualified to audit, with the requisite knowledge of Shariah requirements

Shariah Non-Compliance (SNC) Governance under IFSA 2013

Under Malaysia's legal architecture, Shariah compliance is not a mere voluntary ethical guideline; it is a strict statutory obligation. The Islamic Financial Services Act 2013 (IFSA 2013, Act 759) establishes the most comprehensive and punitive statutory regime for SNC management in the world:

1. Statutory Mandate (Section 28(1) IFSA 2013)

Section 28(1) of IFSA 2013 imposes an affirmative, non-delegable statutory duty on every licensed institution:

"An institution shall at all times ensure that its aims and operations, business, affairs and activities are in compliance with Shariah."

2. Severe Criminal Penalties (Section 28(5) IFSA 2013)

To eliminate willful negligence and underscore the gravity of Shariah compliance, Section 28(5) establishes severe criminal sanctions. Any financial institution or officer who contravenes Section 28 commits an offense and shall, upon conviction, be liable to:

  • Imprisonment for a term not exceeding eight (8) years; or
  • A fine not exceeding twenty-five million Malaysian Ringgit (MYR 25,000,000); or
  • Both imprisonment and fine.

3. Immediate Operational Cessation (Section 28(3) IFSA 2013)

Under Section 28(3), once an institution becomes aware that it is carrying on any business, affair or activity that does not comply with Shariah, its Shariah committee's advice, or an SAC ruling, it must immediately cease that activity and any similar new business. The institution cannot wait for board approval, external legal advice, or scheduled committee meetings before halting the non-compliant process.

4. Statutory Notification Timelines

Section 28(3) sets the sequence:

  [ Institution becomes aware of SNC ]
              |
              v
  Immediately: notify BNM AND the Shariah committee
              |
              v
  Immediately: cease the activity and any similar new business
              |
              v
  Within 30 days (or a longer period BNM specifies):
  submit a rectification plan to BNM
  1. Immediate Notification: Notify BNM and the Shariah committee immediately on becoming aware of the non-compliance.
  2. Immediate Cessation: Stop the non-compliant business, affair or activity at once, and take on no similar business.
  3. 30-Day Rectification Plan: Within thirty days of becoming aware (or such further period as BNM specifies), submit a plan to rectify the non-compliance. BNM may assess whether the rectification has been completed (s.28(4)).

Do not confuse these with the 14-day notice in Sections 33 and 34 of IFSA, which applies when a Shariah committee member resigns or is disqualified.


Shariah Non-Compliant Income (SNCI) Purification

When a transaction is executed in violation of Shariah—such as selling an asset under Murabahah before acquiring ownership or constructive possession (qabd), collecting unauthorized compounding penalty charges, or investing funds in non-compliant commercial assets—the revenue generated from that transaction is legally classified as Shariah Non-Compliant Income (SNCI).

Accounting and Balance Sheet Treatment

Under BNM guidelines and Malaysian Accounting Standards Board (MASB) standards, tainted funds are subject to strict non-recognition rules:

  • Zero Revenue Recognition: SNCI cannot be credited to the institution's statement of comprehensive income as bank revenue, profit, or fee income;
  • Zero Shareholder Distribution: SNCI cannot be capitalized into retained earnings, distributed to shareholders as dividends, or utilized to calculate executive performance bonuses;
  • Zero Expense Offset: The bank cannot use SNCI to offset its own operational expenses, administrative overhead, legal fees, or taxes; and
  • Immediate Segregation: Tainted funds should be identified and kept apart from the bank's own income, typically in a dedicated account, until they are disposed of.

Charitable Purification and Disposal Protocols

The entire balance of SNCI must be purged from the banking institution through charitable purification:

  1. Eligible Beneficiaries: Funds are channelled to charitable bodies or public-benefit purposes approved by the Shariah Committee (e.g., poverty alleviation, disaster relief, medical facilities for the underprivileged, or educational aid for low-income students);
  2. No Commercial Advantage: Purification is not charity by the bank. The bank should not use it to gain marketing publicity or other commercial benefit; and
  3. Disclosure: Under SGPD 2019, where a material SNC event has occurred, the Shariah Committee's annual opinion must disclose its nature, status, and the measures taken to address it. Islamic banks also typically report the amount of non-compliant income and how it was purified in their financial statements.
Test Your Knowledge

Which internal Shariah control function acts as the Third Line of Defense by delivering independent, periodic ex-post assurance directly to the Board Audit Committee (BAC)?

A

Shariah Research

B

Shariah Audit

C

Shariah Review

D

Shariah Risk Management

Test Your Knowledge

An Islamic bank discovers on 1 October that a branch executed RM15 million of Murabahah financing before acquiring the underlying assets. What does Section 28(3) of IFSA 2013 require?

A

Notify BNM and the Shariah committee and stop the activity at once; rectification plan within 30 days

B

Notify BNM in writing within 14 days and submit a rectification plan within 30 days

C

Notify BNM within 30 days and submit a rectification plan within 60 days

D

Report the matter in the next annual report and keep booking the profit until the Shariah committee meets

Test Your Knowledge

What is the mandatory accounting and disposal treatment for Shariah Non-Compliant Income (SNCI) generated from an invalid transaction?

A

The income must be excluded from earnings and given in full to charitable causes approved by the Shariah committee

B

The income may be retained by the bank provided it is fully allocated to offset the bank's annual staff training budget

C

The income must be credited to shareholders as a special one-time cash dividend with an explanatory footnote in the annual report

D

The income must be transferred directly to Bank Negara Malaysia to pay statutory regulatory licensing fees

Sections you finish are checked off in the contents.