Session 4 Flashcards
What are the main objectives of the Internal control process?
- Efficiency and effectiveness of activities (performance objectives).
- Reliability, completeness and timeliness of financial and management information
(information objectives) - Compliance with applicable laws and regulations (compliance objectives)
What are the major elements of the Internal control framework?
- Management oversight and the control culture
a. Board of directors
b. Senior management
c. Control culture - Risk recognition and assessment
- Control activities and segregation of duties
- Information and communication
- Monitoring activities and correcting deficiencies
How do you create an effective risk recognition internal control system?
Continuously assessing & recognizing material risks
Covering all the risks facing the bank
Internal control revisions of these risks
What are some risks a bank could face?
credit risk,
country and transfer risk,
market risk,
interest rate risk,
liquidity risk,
operational risk,
legal risk and reputational risk,
cyber-security risk.
How do you conduct an effective activity control system?
Top level reviews on controls for each department
Checking for exposure
System of approvals and authorizations
system of verification
how do you conduct a good internal control system using information and communication?
Get good data of internal activities, external events to make good decisions.
Reliable info systems on the activities of the bank
Good channels of communication so all staff understand policies and adheres
How do you conduct the monitoring on the internal control system?
Daily monitoring done by the business line themselves.
Periodic monitoring done by internal audit
Independent internal audit, they report to board of directors or audit committee
Timely reporting sent to relevant management
How do supervisory authorities evaluate internal control systems?
Consistent internal controls based on the company & their activities.
A control which is responsive to the environment
What are the three lines of the defence?
1st LOD or the front-line/business
2nd LOD or “independent risk management”
3rd LOD or “internal audit”
What does the first line of the defence do?
verify the quality of their employees’ work whilst assessing the risks associated with their activities
Who is in charge of conducting the first line of defence?
Its a permanent control conducted by the operational line managers
What does the second line of defence do?
They work as a preventive force analysing risks creating frameworks to evaluate if the risk assumed is permissible.
continuous risk monitoring (analyses, following indicators and checking the limits)
Who is in charge of conducting the second line of defence?
The permanent task of the risk management team
Who is in charge of the thrid line of defence?
The internal audit department.
They do these periodic assessments and provide their findings to the audit committee
What does the third line of defence do?
Evaluation of and reporting :
- On the quality of the financial status of each audited unit,
- They concur with levels of risks involved (does the risk level make sense?)
- They assess the valuation devices and of the control of risk.
- Assess the reliability and integrity of the accounting and management information.
- Evaluate compliance