Bank Internal Control Flashcards
True or False. The internal control as defined by BSP states that Banks shall have in place adequate and effective internal control framework for the conduct of their business
True
The _____________________ shall embody management oversight and control culture; risk recognition and assessment; control activities; information and communication; and monitoring activities and correcting deficiencies.
internal control framework (BSP definition)
Is the process designated and effected by the BOD, senior management, and all levels of personnel to provide reasonable assurance on the achievement of objectives.
Internal Control – BSP Definition
Ultimately responsible for ensuring that senior management establishes and maintains an adequate, effective and efficient internal control framework
The Board
Ensure that the internal audit function has an appropriate stature and authority within the bank and is provided with adequate resources
The Board
Overseeing senior management in establishing and maintaining an adequate, effective and efficient internal control framework
Audit Committee
Ensure that systems and processes are designed to provide assurance in areas including reporting, monitoring compliance with laws, regulations and internal policies, efficiency and effectiveness of operations, and safeguarding of assets.
Audit Committee
maintaining, monitoring and evaluating the adequacy and effectiveness of the internal control system and reporting on the effectiveness of internal controls
Senior Management
develop a process that identifies, measures, monitors and controls risks; maintain an organizational structure that clearly assigns responsibility, authority and reporting relationship
Senior Management
ensure that delegated responsibilities are effectively carried out
Senior Management
Implement internal control policies and ensure that activities are conducted by qualified personnel
Senior Management
ensure that bank personnel undertake continuing professional development and that there is an appropriate balance in the skills and resources of the front office, back office, and control functions
Senior Management
shall promptly inform the internal audit function of the significant changes in the bank’s risk management systems, policies and processes.
Senior Management
need to understand their roles and responsibilities in the internal control process
All Personnel
should be fully accountable in carrying out their responsibilities effectively
All Personnel
should communicate to the appropriate level of management any problem in operations, action or behavior that is inconsistent with documented internal control processes and code of ethics.
All Personnel
Who are the responsible for management oversight and culture?
- the board
- audit committee
- senior management
- all personnel
Risk recognition and assessment involves:
- Internal control
- risk assessment
shall identify, evaluate and continually assess all material risks that could affect the achievement of the bank’s performance, information and compliance objectives.
Internal Control (Risk Recognition and Assessment)
the potential for fraud shall be considered in assessing the risks to the achievement of said objectives
Internal Control (Risk Recognition and Assessment)
risk assessment shall cover all risks facing the bank
Internal Control (Risk Recognition and Assessment)
identifies and considers both internal and external factors that could affect the internal control framework
Risk Assessment (Risk Recognition and Assessment)
shall be conducted at the level of individual business units and across all bank activities/groups/units and subsidiaries
Risk Assessment (Risk Recognition and Assessment)
Internal controls shall be revised to address any new or previously uncontrolled or unidentified risks.
Risk Assessment (Risk Recognition and Assessment)
Control Activities involves:
- System that provides for top and functional level reviews
- Checking compliance with exposure limits and follow-up on non-compliance
- System of approvals and authorizations, which shall include the approval process for new products and services
- System of verification and reconciliation
Internal Control under Control Activities involves:
- Clear arrangements for delegating authority
- Adequate accounting policies, records and processes
- Robust physical and environmental controls to tangible assets and access controls to information assets
- Segregation of conflicting functions.
Information and communication:
- Reliable management information system
- Effective channels of communication
- All personnel are cognizant of their duty to promptly report any deficiency to appropriate levels of management or to the board of directors,
Monitoring Activities and Correcting Deficiencies (Monitoring)
- Adequately defined by Management
- Integrated in the operating environment
- Should produce regular reports for review
Monitoring Activities and Correcting Deficiencies (Evaluation)
- Done by personnel from the same operational area or from other areas
- Adequately documented
- Internal control deficiencies and weaknesses identified shall be reported on a timely basis
Committee of Sponsoring Organizations (COSO) Internal Control-Integrated Framework
I. Internal control components
1. control environment
2. risk assessment
3. control activities
4. information & communication
5. monitoring
internal control components which is responsible for
• Demonstrates commitment to integrity and ethical values • Exercises oversight and responsibility
• Establishes structure, authority, and responsibility
• Demonstrates commitment to competence
• Enforces accountability
control environment
internal control components responsible for:
• Specifies suitable objectives
• Identifies and analyzes risks
• Assesses fraud risk
• Identifies and analyzes significant change
risk assessment
internal control components responsible for:
• Selects & develops control activities
• Selects & develops general controls over technology
• Deploys through policies and procedures
control activities
internal control components responsible for:
• Uses relevant information
• Communicates internally
• Communicates externally
information & communication
internal control components responsible for:
• Conducts ongoing and/or separate evaluations
• Evaluates and Communicates deficiencies
monitoring
Which part of the MORB is the BSP – Internal Control Framework referenced to?
MORB section 162