Bank Internal Control Flashcards

1
Q

True or False. The internal control as defined by BSP states that Banks shall have in place adequate and effective internal control framework for the conduct of their business

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The _____________________ shall embody management oversight and control culture; risk recognition and assessment; control activities; information and communication; and monitoring activities and correcting deficiencies.

A

internal control framework (BSP definition)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Is the process designated and effected by the BOD, senior management, and all levels of personnel to provide reasonable assurance on the achievement of objectives.

A

Internal Control – BSP Definition

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Ultimately responsible for ensuring that senior management establishes and maintains an adequate, effective and efficient internal control framework

A

The Board

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Ensure that the internal audit function has an appropriate stature and authority within the bank and is provided with adequate resources

A

The Board

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Overseeing senior management in establishing and maintaining an adequate, effective and efficient internal control framework

A

Audit Committee

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Ensure that systems and processes are designed to provide assurance in areas including reporting, monitoring compliance with laws, regulations and internal policies, efficiency and effectiveness of operations, and safeguarding of assets.

A

Audit Committee

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

maintaining, monitoring and evaluating the adequacy and effectiveness of the internal control system and reporting on the effectiveness of internal controls

A

Senior Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

develop a process that identifies, measures, monitors and controls risks; maintain an organizational structure that clearly assigns responsibility, authority and reporting relationship

A

Senior Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

ensure that delegated responsibilities are effectively carried out

A

Senior Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Implement internal control policies and ensure that activities are conducted by qualified personnel

A

Senior Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

ensure that bank personnel undertake continuing professional development and that there is an appropriate balance in the skills and resources of the front office, back office, and control functions

A

Senior Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

shall promptly inform the internal audit function of the significant changes in the bank’s risk management systems, policies and processes.

A

Senior Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

need to understand their roles and responsibilities in the internal control process

A

All Personnel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

should be fully accountable in carrying out their responsibilities effectively

A

All Personnel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

should communicate to the appropriate level of management any problem in operations, action or behavior that is inconsistent with documented internal control processes and code of ethics.

A

All Personnel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Who are the responsible for management oversight and culture?

A
  1. the board
  2. audit committee
  3. senior management
  4. all personnel
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Risk recognition and assessment involves:

A
  1. Internal control
  2. risk assessment
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

shall identify, evaluate and continually assess all material risks that could affect the achievement of the bank’s performance, information and compliance objectives.

A

Internal Control (Risk Recognition and Assessment)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

the potential for fraud shall be considered in assessing the risks to the achievement of said objectives

A

Internal Control (Risk Recognition and Assessment)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

risk assessment shall cover all risks facing the bank

A

Internal Control (Risk Recognition and Assessment)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

identifies and considers both internal and external factors that could affect the internal control framework

A

Risk Assessment (Risk Recognition and Assessment)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

shall be conducted at the level of individual business units and across all bank activities/groups/units and subsidiaries

A

Risk Assessment (Risk Recognition and Assessment)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Internal controls shall be revised to address any new or previously uncontrolled or unidentified risks.

A

Risk Assessment (Risk Recognition and Assessment)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Control Activities involves:

A
  1. System that provides for top and functional level reviews
  2. Checking compliance with exposure limits and follow-up on non-compliance
  3. System of approvals and authorizations, which shall include the approval process for new products and services
  4. System of verification and reconciliation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Internal Control under Control Activities involves:

A
  1. Clear arrangements for delegating authority
  2. Adequate accounting policies, records and processes
  3. Robust physical and environmental controls to tangible assets and access controls to information assets
  4. Segregation of conflicting functions.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Information and communication:

A
  • Reliable management information system
  • Effective channels of communication
  • All personnel are cognizant of their duty to promptly report any deficiency to appropriate levels of management or to the board of directors,
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Monitoring Activities and Correcting Deficiencies (Monitoring)

A
  • Adequately defined by Management
  • Integrated in the operating environment
  • Should produce regular reports for review
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Monitoring Activities and Correcting Deficiencies (Evaluation)

A
  • Done by personnel from the same operational area or from other areas
  • Adequately documented
  • Internal control deficiencies and weaknesses identified shall be reported on a timely basis
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Committee of Sponsoring Organizations (COSO) Internal Control-Integrated Framework

A

I. Internal control components
1. control environment
2. risk assessment
3. control activities
4. information & communication
5. monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

internal control components which is responsible for

• Demonstrates commitment to integrity and ethical values • Exercises oversight and responsibility
• Establishes structure, authority, and responsibility
• Demonstrates commitment to competence
• Enforces accountability

A

control environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

internal control components responsible for:

• Specifies suitable objectives
• Identifies and analyzes risks
• Assesses fraud risk
• Identifies and analyzes significant change

A

risk assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

internal control components responsible for:

• Selects & develops control activities
• Selects & develops general controls over technology
• Deploys through policies and procedures

A

control activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

internal control components responsible for:

• Uses relevant information
• Communicates internally
• Communicates externally

A

information & communication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

internal control components responsible for:

• Conducts ongoing and/or separate evaluations
• Evaluates and Communicates deficiencies

A

monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Which part of the MORB is the BSP – Internal Control Framework referenced to?

A

MORB section 162

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

The principles under The Institute of Internal Auditors (IIA) Three Lines Model includes:

A
  1. governance
  2. governing body roles
  3. management and 1st and 2nd line roles
  4. 3rd line roles
  5. 3rd line independence
  6. creating and protecting value
38
Q

accountability to stakeholders for organizational oversight

A

governing body

39
Q

governing body roles

A
  • integrity
  • leadership
  • transparency
40
Q

actions (including managing risk) to achieve organizational objectives

A

management

41
Q

what are the 2 line roles of management as stated in the Institute of Internal Auditors (IIA) Three Lines Model?

A
  1. first line roles
  2. second line roles
42
Q

provision of products/services to clients; managing risk

A

first line roles (management)

43
Q

expertise, support, monitoring, and challenge on risk-related matters

A

second line roles (management)

44
Q

independent assurance

A

internal audit

45
Q

independent and objective assurance and advice on all matters related to the achivement of objectives.

A

third line roles (internal audit)

46
Q

key stated in the Institute of Internal Auditors (IIA) Three Lines Model

A
  • ⬆️ accounting, reporting
  • ⬇️ delegation, direction, resources, oversight
  • ↔️ alignment, communication, coordination, collaboration
47
Q

External assurance providers under the Institute of Internal Auditors (IIA) Three Lines Model are:

A
  1. governing body
  2. management
  3. internal audit
48
Q

Management control techniques’ means of control involves:

A
  • Organization
  • Policies
  • Procedures
  • Personnel
  • Accounting
  • Budgeting
49
Q

An approved intentional structuring of roles assigned to people within the entity so that it can achieve its objectives efficiently and economically.

A

organization

50
Q

responsibilities of organization

A
  1. division of responsibility
  2. management authority
  3. individual responsibility
  4. effective system of follow-up
  5. exercise authority without close supervision
51
Q

Any stated principle that requires, guides, or restricts action.

A

policies

52
Q

policies’ qualifications

A
  1. clearly stated in writing
  2. systematically communicated
  3. conform with applicable laws and regulations
  4. provide satisfactory degree of assurance that resources are safeguarded
  5. periodically reviewed
53
Q

Methods employed to carry out activities in conformity with prescribed policies

A

procedures

54
Q

requirements in writing procedures

A
  1. Coordinated (one’s work is automatically checked by another)
  2. Not so detailed as tostifle the use of judgement
  3. simple and inexpensive
  4. not overlapping, conflicting, or duplicative
  5. periodically reviewed and improved
55
Q

People hired or assigned should have the qualifications to do the jobs.

A

personnel

56
Q

under the personnel, it involves:

A
  1. New employees should be investigated as to honesty and reliability
  2. Employees should be given necessary training
  3. Employees should be given information on the duties and responsibilities of other segments of the organization
  4. Employee performance should be periodically reviewed
57
Q

Indispensable means of financial control over activities and resources; financial scorekeeper of the organization

A

accounting

58
Q

under accounting, it involves:

A
  1. Fit the needs of managers for rational decision- making
  2. Based on lines of responsibility
  3. Permits controllable costs to be identified
59
Q

A __________ is a statement of expected results expressed in numerical terms.

A

budget

60
Q

A budget is a statement of expected results expressed in numerical terms. It sets a standard for input of resources and what should be achieved as output.

A

budgeting

61
Q

under budgeting, it involves:

A
  1. Persons responsible for meeting a budget should participate in its preparation and should be provided with adequate information that compares budgets with actual events
  2. Subsidiary budgets should tie into the overall budget
  3. Budgets should set measurable objectives
  4. Should help sharpen the organizational structure
62
Q

Reports received by Management are the basis of its decision.

A

reporting

63
Q

reports should:

A
  1. be in accordance with assigned responsibilities
  2. be a simple as possible and consistent with the nature of the subject matter
  3. be timely
  4. be polled periodically (report recipients)
  5. Individuals/Units should be required to report only on those matters for which they are responsible
  6. Cost of accumulating data and preparing reports should be weighed against the benefits to be obtained
64
Q

___________________ refers to the disclosure or filing of a complaint by an employee, group of employees, or other stakeholders who in good faith, believes that the Bank or any of his/their colleagues is engaging/has engaged in acts of fraud, malpractice, conflict of interest or violation of internal/regulatory policies, procedures and controls.

A

Whistle blowing

65
Q

who are covered in metrobank’s whistle blowing program?

A

all employees

66
Q

true or false. principles of Metrobank MOPP L2 - whistleblowing apply in instances when an employee or stakeholder deems it more prudent to report violations or offenses to another authorized unit/person within the Bank for proper handling, investigation and resolution

A

true

67
Q

true or false. principles of Metrobank MOPP L2 - whistleblowing states that When the matter which is brought to the attention of the immediate superior or Bank personnel is not acted upon in accordance with the standard reporting procedures, or is concealed, or the immediate superior or Bank personnel is himself involved in the infraction, or the reporting employee or stakeholder fears reprisal.

A

true

68
Q

responsible persons/units of metrobank whistleblowing program

A
  1. IAG Head
  2. IAG and HRMG
69
Q

the designated recipient of complaints from Reporting Employees and other stakeholders

A

IAG Head

70
Q

These units ensures that investigations are undertaken in case of whistleblowing

A

IAG and HRMG

71
Q

These units identifies the appropriate unit(s) in the Bank responsible to conduct the investigation

A

IAG and HRMG

72
Q

These units disseminates and communicates the whistle blowing policy to all employees

A

IAG and HRMG

73
Q

Identity of the Reporting Employee or stakeholder (if provided) shall be treated as ________

A

Confidential

74
Q

Identity of the Reporting Employee or stakeholder (if provided) shall be treated as Confidential

A

protection of reporting person

75
Q

exceptions from the protection of the reporting person:

A
  1. person agrees to be identified
  2. Identification is necessary to allow the Bank to investigate or respond effectively
  3. Required by Law
76
Q

_________________ may be filed through the Bank’s website or sent via email

A

Complaints/concerns

77
Q

True or false. It is required for the Reporting Employee/ complainant to disclose his identity and details on the complaint/concern should be submitted

A

false. There is no requirement for the Reporting Employee/ complainant to disclose his identity but details on the complaint/concern should be submitted

78
Q

when filing for complaints/concerns, these details should be submitted:

A

• Full name, position and unit of the person subject of the complaint
• Brief statement on relevant and material facts
• Evidence of the act committed, if any

79
Q

___________ refers to an act of reprisal, discrimination, harassment, intimidation or adverse personnel action by the Bank’s directors, officers, executives, supervisors or employees whether directly or indirectly, against a Reporting Employee or a witness.

A

Retaliation

80
Q

true or false. Retaliation is allowed against any Reporting Employee or stakeholder.

A

false. Retaliation shall not be allowed against any Reporting Employee or stakeholder.

81
Q

_______________ shall be considered as misconduct and erring officers/staff involved shall be dealt with following existing policies on Omissions, Errors, and Offenses

A

Retaliatory actions

82
Q

Details on the complaint/concern

A

• Name and position of the director, officer, employee alleged to have retaliated
• Brief description and date of the complaint to which the alleged retaliation relates
• Brief description and details of the alleged retaliation
• Relevant evidence

83
Q

true or false. Complaints in writing may not be filed directly with the Chairman of the Board

A

false. Complaints in writing may be filed directly with the Chairman of the Board

84
Q

The __________________ may deputize IAG/HRMG to assist in the investigation.

A

Chairman of the Board

85
Q

If a Reporting Employee or Stakeholder or Witness believes he has been retaliated upon for filing a complaint or for participating or cooperating in an investigation, a written complaint may be filed with the IAG Head within ______________ from the occurrence of the alleged act or retaliation incident

A

one month

86
Q

all of the following are under organization except (management control techniques):

a. division of responsibilities
b. effective system of follow-up
c. individual responsibility
d. none of the above

A

d. none of the above

87
Q

which is not under policies (management control techniques):

a. simple and inexpensive
b. not overlapping, conflicting, or duplicative
c. based on lines of responsibility
d. all of the above

A

d. all of the above

88
Q

all of the following are under procedures (management control techniques) except?

a. should help sharpen the organizational structure
b. coordinated (automatically checked by another employee)
c. not so detailed as to stifle the use of judgement
d. periodically reviewed and improved

A

a. should help sharpen the organizational structure

89
Q

Management control technique’s personnel states that New employees should be investigated as to _______ and ________.

A

honesty, reliability

90
Q

true or false. Management control technique’s personnel states that Employees should be given necessary training

A

true

91
Q

true or false. Management control technique’s personnel states that Employees should not be given information on the duties and responsibilities of other segments of the organization

A

false. Employees should be given information on the duties and responsibilities of other segments of the organization