Trust is the basis of any relationship, but from a bank that trades in other people’s money, supervisory authorities require a more specific control system. In Poland, this system is shaped by Recommendation H of the Polish Financial Supervision Authority, which contains recommendations on the internal control system in banks. In this article, we explain what Recommendation H requires: how the three lines model works (previously the three lines of defence model), what controls and the control function matrix are, what role the compliance unit and internal audit play, and how to implement the whole thing without drowning in spreadsheets.
From Circular to Foundation: What is Recommendation H and Why Does It Matter?
Recommendation H, defined as a set of good practices, is the so-called soft law, issued on the basis of Article 137(1)(5) of the Banking Law. Formally, it is non-binding, but in practice it is difficult not to apply it: this is expected by KNF inspections, and deviations must be convincingly justified.
The latest version of Recommendation H from 2017 (replacing the older version from 2011) has completely rebuilt the entire system. The new recommendation emphasised that internal control should not be a separate department, but a process involving each employee. The new Polish regulations have been closely correlated with the EBA (European Banking Authority) guidelines on internal governance and the recommendations of the Basel Committee, thanks to which banks have begun to apply safety and control standards consistent with those of the largest financial institutions in Europe and the world. Recommendation H was issued in accordance with the Regulation of the Minister of Development and Finance of 6 March 2017 on the risk management system and the internal control system in banks. The regulation is a hard law, and Recommendation H is a soft one: an instruction on how to implement these regulations effectively.
The PFSA, when issuing Recommendation H, explicitly indicated that its provisions should be applied in proportion to the scale, complexity and risk profile of a given institution. Thus, for a small cooperative bank, Recommendation H does not mean the need to build a “mini corporation” with dozens of controllers. Thanks to proportionality and the support of institutional protection systems, it can settle for simpler mechanisms that actually protect its local activities.
Why is Recommendation H important? Because it sets the benchmark according to which the PFSA assesses banks and links solutions from related recommendations (e.g. Z – internal governance or M – operational risk).
Four goals, one system: what does the PFSA expect from internal control?
Article 9c of the Banking Law sets four statutory objectives for the internal control system – to ensure: the effectiveness and efficiency of the bank’s operations; the reliability of financial reporting; compliance with the bank’s risk management rules; compliance of the bank’s operations with the law, internal regulations and market standards. The Bank divides these general objectives into specific objectives related to processes, especially the so-called material processes, on a list approved by the Management Board. The internal control system and the risk management system are two separate systems with different mechanisms that must work together.

Triple Guard: What is the three lines model?
This is the essence of Recommendation H. The system should be based on three lines. The first line is operational activity and operational risk management. The second is dedicated units responsible for risk management and a compliance unit. The third line is internal audit. The basic principle is that control and monitoring mechanisms work on all three lines. Each employee applies and supervises control mechanisms as part of their job duties.
| Line | Who | Main tasks | Exampe |
|---|---|---|---|
| The first | Business and operational units | risk management in day-to-day operations, use of control mechanisms | advisor verifying credit documentation (self-checking) |
| Second | Risk Management Units, Compliance Unit | independent first-line monitoring (ongoing verification, vertical testing), non-compliance risk management | Testing compliance with credit limits |
| Third | Internal Audit Unit | independent assessment of the adequacy and effectiveness of both systems | audit of the reporting process |
Who is responsible for what: the three lines in practice
The first line comprises process owners and the employees carrying out day-to-day tasks, who are expected to implement control mechanisms, apply them in daily operations and respond to irregularities. Control is built into the daily operational duties of each frontline employee who, while performing his or her work, implements the basic control mechanisms: self-control, verification by a second person, compliance with specific risk limits. Recommendation H puts a lot of emphasis on how errors and anomalies are treated on the front line. If an employee detects a significant or critical irregularity, he has no right to conceal it or try to fix it “silently”, but must launch a formalised escalation path provided for in the bank’s procedures; Critical irregularities are immediately sent to the management board, and the report is followed by corrective and disciplinary measures.
Second-line units have a dual mandate and operate at two complementary levels: operational (verification and testing) and management (the risk management and compliance processes). At the operational level, it conducts vertical ongoing verification and vertical first-line testing where the risk of non-compliance is greatest, including consumer protection, anti-money laundering, and conflicts of interest. At the management level, it conducts the process of managing the risk of non-compliance and reports the results to the management and supervisory boards on a quarterly basis. The independence of the compliance unit is protected: its head reports directly to the president or a designated member of the management board, and their variable remuneration cannot depend on the financial results of the areas they control. The regulations and access to the information of the compliance unit are guaranteed by the Management Board and the Supervisory Board.
Internal audit, i.e. the third line, independently evaluates three systems: risk management, compliance management and internal control. It operates on the basis of an audit charter and plans its work according to the audit universe (a full list of areas, processes and entities that may be subject to audit) and a risk map (an ordered picture of threats with a specific severity). Organizationally, he reports to the President of the Management Board, and the results of the research are sent to the supervisory board or audit committee. The Management Board designs and implements the system, and the Supervisory Board supervises it and annually assesses its adequacy and effectiveness; It can entrust ongoing monitoring to the audit committee, but not to the assessment itself.
From procedure to self-control: what are control mechanisms?
The heart of Recommendation H is the control function: all control mechanisms in the bank’s processes, independent monitoring of their compliance and reporting of results. The recommendation lists eleven main types of mechanisms: procedures, division of responsibilities (the “two-eyes principle”), authorisation, access control, physical control, records of operations, inventory, documentation of deviations, performance indicators, training and self-control.
The mechanism can act preventively (the limit of permissions blocks too large a transaction), detection (reconciliation of balances reveals discrepancies) or corrective (corrective procedure after an error is detected). It can be automatic, semi-automatic or manual, with the Recommendation explicitly warning against relying solely on manual mechanisms in any process.
For example, a credit limit is a risk control mechanism (risk management system), and the procedure to ensure compliance with it is a control mechanism (internal control system). Control mechanisms keep an eye on the guards. Key control mechanisms are a special category. If they fail, the goals of the system may not be achieved. They must be assigned to at least relevant processes, monitored with appropriate frequency and audited.

The whole system in one table: what is the control function matrix?
A control function matrix is a document (usually a table) that links the general and specific objectives of the internal control system to the bank’s essential processes, key controls, and the independent monitoring assigned to them. The matrix is managed by a designated second-line unit, and keeping it up to date is the responsibility of the employees named in individual units of the bank, who are obliged to report any changes to it without delay. Cooperative banks in the protection system may be satisfied with a simplified matrix.
The matrix is the operational centre of the entire system and the first document requested by an auditor or an inspection by the Polish Financial Supervision Authority. This one document proves that the bank knows what and how it controls and who checks it.
Control as the highest form of trust: how to monitor and test mechanisms?
Independent monitoring of control mechanisms has two methods and two directions. Ongoing verification takes place before the start or during the activity (e.g. approval of the operation by the supervisor), and testing after its completion, on a selected sample and with a documented result. Horizontal monitoring takes place within the same line; vertical means checking the first line by the second.
In important processes, vertical testing of key mechanisms is the most important, while also in horizontal monitoring, the principle applies that no one monitors their own work. Testing requires internal adjustments (plan, responsible cells, scope, frequency, sample selection), and each test leaves evidence of control: signatures, reports, etc. What has not been documented could just as well not have been.
What the management hears: reporting and supervision of the control system
Detected irregularities are categorised (at least into significant and critical) and have specific escalation paths. Critical ones are immediately sent to the management board and if detected by the audit, also to the supervisory board. The results of vertical testing are regularly reported, along with the status of corrective measures. The compliance unit reports on the risk of non-compliance on a quarterly basis, and the audit informs at least once every six months on the implementation of the plan.
The whole is connected by an annual assessment of the adequacy and effectiveness of the system by the supervisory board, based on information from the management board, reports of the compliance and audit unit, the findings of the statutory auditor and the results of the KNF inspection. Each bank also publishes a description of its internal control system, usually on its website.
Easy to recommend, harder to implement: common challenges
After eight years, all banks have formally implemented Recommendation H, but practitioners assess the quality of implementations as uneven. Compliance units can be independent on paper, but in practice they are too thin to really test the front line. Smaller banks can hardly fill three lines without a conflict of roles. Continuity is also a challenge: the matrix, testing evidence and cascade of reports need to be kept up to date, not ticked off once a year, which can be problematic with a limited number of employees.
Finally: The recommendation was created before the era of GRC tools and is silent about GRC platforms, automation, artificial intelligence or DORA. Translating the expectations of 2017 into the technological realities of 2026 remains the task of the banks themselves.
From Sheets to System: How Does GRC Support Recommendation H Compliance?
Recommendation H does not require the use of any tool, but its requirements correspond to exactly what the GRC (Governance, Risk, and Compliance) software was created for. In it, the matrix becomes a central registry with owners and version history, tests have workflows with evidence scheduled, and escalation starts automatically by category. Quarterly and annual reports are created from the same data, and the audit trail is recorded by itself.
Meanwhile, the matrix in Excel quickly loses its relevance, because no one forces updates; there is no history of changes or automatic escalation. The compliance management platform makes the update obligation enforceable. GRC software also fills a gap pointed out by practitioners: the AI assistant can summarise regulatory changes, prepare a draft description of the mechanism, and signal anomalies in test results. Decisions are made by a human, but the paperwork is handled by a machine.
Good practices at the end: how to build an effective internal control system?
Start with the essential processes, not everything at once – these are the ones that the PFSA focuses on the most and they determine the achievement of the system’s goals. Define key mechanisms sparingly: if everything is crucial, then nothing is. Give the compliance unit real resources and a real reporting path – independence on paper means little if the team is too thin to test the front line and its boss does not have direct access to the board and supervisory board. Treat the matrix as a living document with specific owners of updates: any change to a process or mechanism should be reported without delay by a specific, named person. Automate evidence collection before adding more checks – without signatures, confirmations, and reports, the supervisor test simply doesn’t exist, and manually collecting these traces with each testing cycle quickly becomes a bottleneck. Treat the annual review of the supervisory board as a term that disciplines year-round activities: it is better to work for this review throughout the year than to catch up on everything a few weeks before it.