| Guidelines This chapter describes supervisory expectations for the internal audit function. The contents of this chapter are based on:
|
| Related standards |
| Related guidelines |
A strong internal control system, including an independent and effective internal audit function, is part of sound corporate governance1. Banking supervisors must be satisfied as to the effectiveness of a bank's internal audit function, that policies and practices are followed and that management takes appropriate and timely corrective action in response to internal control weaknesses identified by internal auditors.
An internal audit function provides vital assurance to a bank’s board of directors and senior management (and bank supervisors) as to the quality of the bank’s internal control system. In doing so, the function helps reduce the risk of loss and reputational damage to the bank.
The following terms are used throughout this chapter and have the meaning given below:
This chapter seeks to promote a strong internal audit function within banks. It sets out principles for supervisory expectations for the internal audit functions, the relationship of the supervisory authority with the internal audit function and the supervisory assessment of that function.
The principles also encourage banks’ internal auditors to comply with and to contribute to the development of national and international professional standards, such as those issued by The Institute of Internal Auditors. It also promotes due consideration of prudential issues in the development of internal audit standards and practices.
The principles should be applied in accordance with the national legislation and corporate governance structures applicable in each country.
For large banks and internationally active banks, an audit committee (or its equivalent) is typically responsible for providing oversight of the bank’s internal auditors.2 Such a committee is established within the board of directors.
| 2 | Annex 2 of The internal audit function in banks (June 2012) includes a detailed description of the responsibilities of a bank's audit committee. |
Principle 1 – An effective internal audit function provides independent assurance to the board of directors and senior management on the quality and effectiveness of a bank’s internal control, risk management and governance systems and processes, thereby helping the board and senior management protect their organisation and its reputation.3
| 3 | Supervisory authorities share a keen interest in these areas, but it is important to note that internal auditors and supervisors, while both using risk-based approaches, have distinct mandates and make independent judgements and assessments. |
The internal audit function should develop an independent and informed view of the risks faced by the bank based on their access to all bank records and data, their enquiries, and their professional competence. The internal audit function should be able to discuss their views, findings and conclusions directly with the audit committee and the board of directors, thereby helping the board to oversee senior management.
Principle 2 – The bank's internal audit function must be independent of the audited activities, which requires the internal audit function to have sufficient standing and authority within the bank, thereby enabling internal auditors to carry out their assignments with objectivity.
Based on the audit plan established by the head of the internal audit function and approved by the board of directors, the internal audit function must be able to perform its assignments on its own initiative in all areas and functions of the bank. It must be free to report its findings and assessments internally through clear reporting lines. The head of internal audit should demonstrate appropriate leadership and have the necessary skills to fulfil their responsibility for maintaining the function’s independence and objectivity.
The internal audit function should not be involved in designing, selecting, implementing or operating specific internal control measures. However, the independence of the internal audit function should not prevent senior management from requesting input from internal audit on matters related to risk and internal controls. Ultimately, the development and implementation of internal controls should remain the responsibility of management.
Continuously performing similar tasks or routine jobs may negatively affect an individual internal auditor’s capacity for critical judgement because of possible loss of objectivity. It is therefore a sound practice, whenever practicable and without jeopardising competence and expertise, to periodically rotate internal audit staff within the internal audit function. In addition, a bank may rotate staff from other functional areas of the bank to the internal audit function or from the internal audit function to other functional areas of the bank. Staff rotations within the internal audit function and staff rotations to and from the internal audit function should be governed by and conducted in accordance with a sound written policy. The policy should be designed to avoid conflicts of interest, including the observance of an appropriate “cooling-off” period following an individual's return to the internal audit staff before that individual audits activities in the functional area of the bank where their rotation had been served..
The remuneration of internal audit staff (including the head of internal audit) should be determined in accordance with the remuneration policies and practices of the bank. Remuneration of internal audit staff should be determined independently of the business lines and second line functions for which they exercise internal audit responsibilities, and structured to avoid creating conflicts of interest and compromising independence and objectivity.
Principle 3 – Professional competence, including the knowledge and experience of each internal auditor and of internal auditors collectively, is essential to the effectiveness of the bank’s internal audit function.
Professional competence depends on the auditor’s capacity to collect and understand information, to examine and evaluate audit evidence and to communicate with the stakeholders of the internal audit function. This should be combined with suitable methodologies and tools and sufficient knowledge of auditing techniques.
The head of internal audit should be responsible for ensuring the team has the qualifications and skills needed to fulfil its mandate effectively. They should continually assess and monitor the skills necessary to do so. The skills required for senior internal auditors should include the abilities to judge outcomes and influence decisions at the highest level of the organisation.
The head of internal audit should ensure that internal audit staff acquires appropriate ongoing training to meet the growing technical complexity of banks’ activities, new products and processes, and other developments in the financial sector.
Internal auditors collectively should be competent to examine all areas in which the bank operates. Alternatively, when outsourcing arrangements are in place, it is the responsibility of the head of internal audit to maintain adequate oversight and to ensure adequate transfer of knowledge from external experts to the bank’s internal audit staff. The head of internal audit should ensure that the use of those experts does not compromise the independence and objectivity of the internal audit function.4
| 4 | If internal experts from within the bank (so-called guest auditors) are used in lieu of, or in addition to external experts, the head of internal audit has the same responsibilities for oversight, knowledge transfer, independence and objectivity. |
Internal auditors must apply the care and skills expected of a reasonably prudent and competent professional. While due professional care does not imply infallibility, internal auditors with limited competence and experience in a particular area should be supervised by more experienced internal auditors.
Principle 4 – Internal auditors must act with integrity.
Integrity establishes trust as it requires the internal auditor to be straightforward, honest and truthful. This provides the basis for reliance on the internal auditor's professional judgement.
Internal auditors should respect the confidentiality of information acquired in the course of their duties. They should not use that information for personal gain or malicious action and should be diligent in the protection of information acquired.
The head of the internal audit function and all internal auditors should avoid conflicts of interest. Internally recruited internal auditors should not engage in auditing activities for which they have had previous responsibility before a sufficiently long “cooling off” period has elapsed. Moreover, compensation arrangements should not provide incentives for internal auditors to act contrary to the attributes and objectives of the internal audit function.
Internal auditors should apply the bank’s code of ethics (when there is one) or should adhere to an established international code of ethics for internal auditors, such as that of The Institute of Internal Auditors.5 A code of ethics should at a minimum address the principles of objectivity, competence, confidentiality and integrity.
| 5 | The Institute of Internal Auditors (The IIA) and the International Ethics Standards Board for Accountants (IESBA) have each issued a code of ethics. Both codes emphasise the importance of the principle of integrity. |
Principle 5 – Each bank should have an internal audit charter that articulates the purpose, standing and authority of the internal audit function within the bank in a manner that promotes an effective internal audit function as described in Principle 1.
The charter should be drawn up and reviewed periodically by the head of internal audit and approved by the board of directors. It should be available to all internal stakeholders of the organisation and, in certain circumstances, such as listed entities, to external stakeholders.
At a minimum, an internal audit charter should establish:
The charter should empower the internal audit function, whenever relevant to the performance of its assignments, to directly communicate with any member of staff, to examine any activity or entity of the bank, and to have full and unconditional access to any records, files, data and physical properties of the bank. This includes access to management information systems and records, and the minutes of all consultative and decision-making bodies.
Principle 6 – Every activity (including outsourced activities) and every entity of the bank should fall within the overall scope of the internal audit function.
The scope of internal audit activities should include the examination and evaluation of the effectiveness of the internal control, risk management and governance systems and processes of the entire bank, including the organisation’s outsourced activities and its subsidiaries and branches.
The internal audit function should independently evaluate the:
The head of internal audit is responsible for establishing an annual internal audit plan that can be part of a multi-year plan. The plan should be based on a robust risk assessment (including input from senior management and the board) and should be updated at least annually (or more frequently to enable an ongoing real-time assessment of where significant risks lie). The board’s approval of the audit plan implies that an appropriate budget will be available to support the internal audit function’s activities. The budget should be sufficiently flexible to adapt to variations in the internal audit plan in response to changes in the bank’s risk profile.
Principle 7 – The scope of the internal audit function’s activities should ensure adequate coverage of matters of regulatory interest within the audit plan.
Internal audit should have the appropriate capability regarding matters of regulatory interest and undertake regular reviews of such areas based on the results of its robust risk assessment. These include policies, processes and governance measures established in response to various regulatory principles, rules and guidance established by the relevant authorities. In particular, the internal audit function of a bank should have the capacity to review key risk management functions, regulatory capital adequacy and liquidity control functions, regulatory and internal reporting functions, the regulatory compliance function and the finance function.
A bank’s risk management processes support and reflect its adherence to regulatory provisions and safe and sound banking practices. The following aspects of risk management should be within scope of internal audit reviews:
When the risk management function has not informed the board of directors about significantly diverging views between senior management and the risk management function regarding the level of risk faced by the bank, the head of internal audit should inform the board about this divergence.
The scope of internal audit should include all provisions of the regulatory framework for capital and liquidity. In particular:
Internal auditors should regularly evaluate the effectiveness of the process by which the risk and reporting functions interact to produce timely, accurate, reliable and relevant reports for both internal management and the supervisor. This includes standardised reports which record the bank’s calculation of its capital resources, requirements and ratios. It may also include public disclosures intended to facilitate transparency and market discipline such as the Pillar 3 disclosures and the reporting of regulatory matters in the bank’s public reports.
Financial controls should be subject to periodic internal audit review. Internal audit should devote sufficient resources to evaluate the valuation control environment, availability and reliability of information or evidence used in the valuation process and the reliability of estimated fair values. This is achieved through reviewing the independent price verification processes and testing valuations of significant transactions. The scope of internal audit reviews should include, but are not limited to:
Principle 8 – Each bank should have a permanent internal audit function, which should be structured consistent with Principle 14 when the bank is within a banking group or holding company.
In fulfilling its duties and responsibilities, senior management and the board should take all necessary measures to ensure that the bank has a permanent internal audit function commensurate with its size, the nature of its operations and the complexity of its organisation.
Principle 9 – The bank’s board of directors has the ultimate responsibility for ensuring that senior management establishes and maintains an adequate, effective and efficient internal control system. The board should support the internal audit function in discharging its duties effectively.
At least once a year, the board should review the effectiveness and efficiency of the internal control system based, in part, on information provided by the internal audit function. As part of their oversight responsibilities, the board should review the performance of the internal audit function. From time to time, the board should consider commissioning an independent external quality assurance review of the internal audit function.
Senior management is responsible for developing an internal control framework that identifies, measures, monitors and controls all risks faced by the bank. The control framework should maintain an organisational structure that clearly assigns responsibility, authority and reporting relationships and ensures that delegated responsibilities are effectively carried out. Senior management should report to the board of directors on the scope and performance of the internal control framework.
Senior management should inform the internal audit function of new developments, initiatives, projects, products and operational changes and ensure that all associated risks, known and anticipated, are identified and communicated at an early stage.
Senior management should be accountable for ensuring that timely and appropriate actions are taken on all internal audit findings and recommendations.
Senior management should ensure that the head of internal audit has the necessary resources, financial and otherwise, available to carry out their duties commensurate with the annual internal audit plan, scope and budget approved by the audit committee.
Principle 10 – The audit committee, or its equivalent, should oversee the bank’s internal audit function.
This principle applies when the board of directors has established an audit committee. In cases where no audit committee exists, the responsibilities described below should be assumed by the board itself. As set out in CGO10, an audit committee should be required for systemically important banks and is strongly recommended for other banks based on an organisation’s size, risk profile or complexity.
The oversight function of the audit committee includes ensuring that the internal audit function can discharge its responsibilities in an independent manner, congruent with principle 2. It also includes reviewing and approving the audit plan, its scope, and the budget of the internal audit function. The audit committee reviews key audit reports and ensures that senior management is taking necessary and timely corrective actions to address control weaknesses, compliance issues with policies, laws and regulations and other concerns identified and reported by the internal audit function.
Principle 11 – The head of the internal audit department should be responsible for ensuring that the department complies with sound internal auditing standards and with a relevant code of ethics.
The head of the internal audit department should ensure compliance with sound internal auditing standards, such as The Institute of Internal Auditors’ International Standards for the Professional Practice of Internal Auditing. In addition, auditors should adhere to a relevant code of ethics (see principle 4).
The audit committee should ensure that the head of the internal audit function is a person of integrity. This means that they will be able to perform their work with honesty, diligence and responsibility. It also implies that they observe the law and have not been a party to any illegal activity. The head of internal audit should also ensure that the members of internal audit staff are persons of integrity.
Principle 12 – The internal audit function should be accountable to the board, or its audit committee, on all matters related to the performance of its mandate as described in the internal audit charter.
Senior management is responsible for implementing and maintaining an adequate and effective internal control system and processes. The internal audit function should promptly inform senior management of all significant findings so that timely corrective actions can be taken. The internal audit function should follow up with senior management on the outcome of these corrective measures. The head of the internal audit function should report to the board, or its audit committee, the status of findings that have not been rectified by senior management.
Principle 13 – The internal audit function should independently assess the effectiveness and efficiency of the internal control, risk management and governance systems and processes created by the business units and support functions and provide assurance on these systems and processes.
According to the three lines of defence model (see CGO10), the internal audit function is the third line of defence. It independently assesses the effectiveness of the processes created in the first and second lines of defence and provides assurance on these processes.
Principle 14 – To facilitate a consistent approach to internal audit across all banks within a group or holding company, the board of each bank should ensure that either:
The board of directors of each bank in a group or holding company structure remains responsible for ensuring that the bank’s senior management establishes and maintains an adequate, effective and efficient internal control system and processes. The board also should ensure that internal audit activities are conducted effectively at the bank. The internal auditors of the bank should report to the bank’s audit committee, or its equivalent, and to the group or holding company’s head of internal audit.
The board of directors and senior management of the parent entity have overall responsibility for ensuring that an adequate and effective internal audit function is established across the banking organisation, and for ensuring that internal audit policies and mechanisms are appropriate for the structure, business activities and risks of all components of the group or holding company.
The head of internal audit at the parent entity should define the group or holding company’s internal audit strategy, determine the organisation of the internal audit function both at the parent and subsidiary bank levels (in consultation with the respective boards and in accordance with local laws) and formulate the internal audit principles, which include the audit methodology and quality assurance measures.
The group or holding company’s internal audit function should determine the audit scope for the banking organisation. In doing so, it should comply with local legal and regulatory provisions and incorporate local knowledge and experience.
Principle 15 – Regardless of whether internal audit activities are outsourced, the board of directors remains ultimately responsible for the internal audit function.
It is recommended that large banks and internationally active banks perform internal audit activities using their own staff. However, outsourcing of internal audit activities, but not the function, on a limited and targeted basis can bring benefits to banks such as access to specialised expertise and knowledge for an internal audit engagement where the expertise is not available within the bank. Outsourcing could also alleviate temporary resourcing constraints which might otherwise jeopardise the execution of the audit plan. Banks should be able to explain the reasons for outsourcing specific internal audit activities.
The head of internal audit should ensure that external experts comply with the principles of the bank’s internal audit charter. To preserve independence, it is important to ensure that external experts have not been previously engaged in a consulting engagement in the same area within the bank unless a reasonably long “cooling-off” period has elapsed. Those external experts who participate in an internal audit engagement should not provide subsequent consulting services to a function of the bank they recently audited. Additionally, as a sound practice, banks should not outsource internal audit activities to their own external audit firm.7
| 7 | Any departure from this best practice should be limited to small banks and should remain within the bounds of the applicable ethical standards for the statutory or external auditor. |
The head of internal audit should ensure that, whenever practical, the relevant knowledge input from an expert is assimilated into the bank. This may be possible by having one or more members of the bank’s internal audit staff participate in the external expert’s work.
The supervisor will benefit from effective communication about topics of mutual interest with the internal audit function of a bank. When establishing a relationship with the internal audit function, the supervisor should obtain an understanding of the organisation and operation of the internal audit function, including its position and remit within the bank.
Supervisors and internal auditors should each ensure that enhanced communication does not undermine their respective perceived and actual independence and status, or roles and responsibilities. Regardless of the supervisor’s assessment of the internal audit function, the supervisor should be able to challenge the work of the internal auditors through their continuous supervision process, including through on-site supervision.
The relationship between the supervisor and the internal audit function should be established in a structured and transparent way. In principle, the supervisor will initiate this relationship.
Principle 16 – Supervisors should have regular communication with the bank’s internal auditors to: (i) discuss the risk areas identified by both parties; (ii) understand the risk mitigation measures taken by the bank; and (iii) monitor the bank’s response to identified weaknesses.
Supervisors have an interest in engaging in a constructive and formal dialogue with the internal audit function, because it provides an independent assessment of the bank’s internal controls and procedures. This dialogue may be a valuable source of information on the quality of the internal control system.
Supervisors should meet periodically with the bank’s internal auditors to discuss their risk analysis, findings, recommendations and the audit plan. Supervisors should decide on a case by case basis whether senior management should be present at these meetings. These meetings may allow supervisors to understand how - and to what extent - the recommendations made by supervisors (including those made during on-site reviews) and internal auditors have been implemented. The meetings should be sufficiently frequent to enable the supervisor to ensure the effectiveness of the actions taken by the bank to address these recommendations. The frequency of these meetings and other communication between supervisors and internal auditors should be commensurate with the bank's size, the nature and risks of its operations and the complexity of its organisation. Supervisors may also request internal audit reports from time to time. The analysis of these internal audit reports and information may contribute to the supervisor’s assessment of the internal control system of the bank.
Supervisors may consider sharing relevant information with the internal audit function of a bank when this could increase the effectiveness of its internal audit work. Supervisors should make specific recommendations for strengthening the internal audit function and the control environment.
Although all matters covered by the internal audit function are potentially of value to supervisors, some topics are closely related to supervisory requirements and are therefore of particular interest to banking supervisors.
A bank’s capital and liquidity positions and its processes and methods for determining, monitoring, controlling and reporting on material risks are directly relevant and important to supervisors. Supervisors and internal auditors should discuss the areas described in Principle 7.
Internal audit is well placed to provide the supervisor with insight on the bank’s business model including risks in business activities, processes and functions, and the adequacy of the control and oversight of these risks such as:
To the extent that accounting data drives certain regulatory measures or is included in regulatory reporting, supervisors should seek to understand and benefit from internal audit’s work relating to:
Supervisors may also have an interest in business or market conduct issues as identified through the audit of the compliance function, for example:
The board of directors and senior management are responsible for establishing the bank’s strategy and business models. However, changes may have consequences for the bank’s internal control, risk management and governance systems and processes. Although internal audit does not set the bank’s policies and should not interfere in its business decisions, it can influence them by challenging management. Both the internal audit function and supervisor have an interest in the:
Supervisors should assess the internal audit function. This will influence their overall assessment of the bank and enable them to determine the extent to which they will use the work of the internal audit function.
Principle 17 – Bank supervisors should regularly assess whether the internal audit function has sufficient standing and authority within the bank and operates according to sound principles.
The supervisor should consider the extent to which the board of directors, its audit committee and senior management promote a strong internal control environment supported and assessed by a sound internal audit function.
The assessment of the internal audit function should be based on the supervisory expectations set out in principles 1-15, including:
To promote consistency and comparability over time and across banks and to identify industry best practices, the supervisor may benefit from using a grading system to perform its assessment of the internal audit function.
Weaknesses identified in the internal audit function may affect the supervisor’s assessment of the bank’s risk profile.
Although the supervisor should independently assess the quality of the internal audit function, the audit committee or its equivalent and the internal audit function should develop and maintain their own tools to assess the quality of the internal audit function.
The supervisor should be promptly informed by the audit committee (or its equivalent) or senior management of the appointment of a new head of the internal audit function, including relevant qualifications and previous experience. Similarly, whenever the head of the internal audit function ceases to act in this capacity, the supervisor should be informed of this fact and its circumstances. The supervisor should consider meeting with the former head of internal audit to discuss the reasons for their departure.
Principle 18 - Supervisors should formally report all weaknesses they identify in the internal audit function to the board of directors and require remedial actions.
When the supervisor concludes that a bank's internal audit function is inadequate or ineffective, it should require the board to develop an appropriate written remediation plan that addresses the identified weaknesses on a timely basis. The written plan should be submitted to the supervisor for review. If the supervisor is not satisfied, it should require changes or additional measures to be included in the plan. The supervisor should monitor the implementation of the plan.
The supervisor may also recommend enhancements to the governance of the bank including the functioning of the audit committee.
The audit committee and board should not conclude that the internal audit function is functioning well solely because the supervisor has not identified any weaknesses. The supervisory review process is not a substitute for the audit committee's assessment, or an external assessment of the internal audit function.
Principle 19 – The supervisor should consider the impact of its assessment of the internal audit function on its evaluation of the bank's risk profile and on its own supervisory work.
The assessment of the internal audit function may have consequences for the supervisor's evaluation of the bank's risk profile, the allocation of supervisory resources and the activities envisaged by the authority.
Where remedial actions cannot be agreed upon or where the bank faces ongoing delays in remediating the identified weaknesses, the supervisor should consider the impact of this on the bank’s risk profile.
In cases where a bank belongs to an international group, the supervisor should consider sharing its concerns with the other relevant authorities, for example within the supervisory college.
Principle 20 – The supervisor should be prepared to take informal or formal supervisory actions requiring the board and senior management to remedy any identified deficiencies related to the internal audit function within a specified timeframe and to provide the supervisor with periodic written progress reports.
While supervisors expect banks to have a strong and robust internal audit function, there may be certain circumstances in which deficiencies exist and warrant specific supervisory actions aimed at remedying the deficiencies. Supervisory action may be of a public or non-public nature.
This module describes expectations to combat money laundering and terrorist financing.
This module describes expectations and practices relating to capital adequacy.
This module describes expectations for corporate governance.
This module describes expectations for credit risk and counterparty credit risk management.
This module describes expectations for external audit and sets out references related to public disclosure.
This module describes expectations for banks’ internal audit and compliance functions.
This module describes expectations for liquidity risk management.
This module sets out references related to market risk and interest rate risk.
This module describes expectations for the management of operational risk and operational resilience.
This module describes expectations for the management of problem assets and expected credit losses.
This module describes the application of proportionality in prudential regulation and supervision.
This module describes expectations for risk management.
This module describes the nature and application of prudential supervision.