e. inadequacy or ineffectiveness of the internal audit program and other monitoring activities;

Size: px
Start display at page:

Download "e. inadequacy or ineffectiveness of the internal audit program and other monitoring activities;"

Transcription

1 TABLE OF CONTENTS Page I. BACKGROUND 1 II. SCOPE OF THE BANK INTERNAL CONTROL SYSTEM 2 1. Definition and Objectives 2 2. Stakeholders in the Bank Internal Control System 3 3. Factors to Consider in the Design of the Bank Internal Control System 4 4. Control Environment 4 III. KEY ELEMENTS IN THE BANK INTERNAL CONTROL SYSTEM 5 1. Management Oversight and Control Culture 5 2. Risk Recognition and Assessment 8 3. Control Activities and Segregation of Duties 9 4. Accountancy, Information, and Communications Monitoring Activities and Correcting Deficiencies 16 IV. MISCELLANEOUS PROVISIONS 18 i

2 I. BACKGROUND 1. An effective Internal Control System is a vital component of Bank management and provides the basis for sound and secure Bank operations. Effective Internal Control Systems help Bank managers to safeguard the assets of the Bank, ensure credible financial and managerial reporting, strengthen legal and regulatory compliance, and mitigate risks of losses, irregularities, and violations of prudential banking principles. 2. The operation of a reliable and effective Internal Control System is the responsibility of the managers and officers of the Bank. In addition, Bank managers are also required to improve the effectiveness of the risk culture in the Bank organization and ensure that the culture is in place at every level of the organization. 3. The Internal Control System must be an important Bank focus, given that the causes of the difficulties in Bank operations include various weaknesses in the operation of Bank Internal Control Systems. These weaknesses include: a. lack of a supervision mechanism, lack of clear accountability for Bank managers, and failure to develop an internal control culture at all levels of the organization; b. deficiencies in the work of recognition and assessment of risks in the operations of the Bank; c. absence of or failure in one of the key controls of Bank operations, such as segregation of functions, authorizations, verifications, and review of risk exposures and Bank performance; d. lack of communication and information between the different levels in the Bank organization, in particular information at decision making levels on deterioration in quality of risk exposures and application of corrective actions; e. inadequacy or ineffectiveness of the internal audit program and other monitoring activities; f. poor commitment by Bank management to implement internal control processes and impose firm sanctions on violations of regulatory provisions and the policies and procedures established by the Bank. 1

3 II. SCOPE OF THE BANK INTERNAL CONTROL SYSTEM 1. Definition and Objectives a. Definition Internal control is a mechanism for supervision instituted by the Bank management on an ongoing basis in order to: 1) safeguard and secure the property and assets of the Bank; 2) ensure greater accuracy in reporting; 3) strengthen legal and regulatory compliance; 4) minimize financial impact/losses, irregularities including fraud, and violations of prudential regulations; 5) strengthen the effectiveness of the organization and improve cost efficiency. b. Objectives 1) Legal and regulatory compliance (Compliance Objective) The Compliance Objective is to ensure that all business activities of the Bank are conducted in accordance with applicable laws and regulations, including regulations issued by the government and the Bank supervision authority, and the internal policies, regulations, and procedures established by the Bank. 2) Truthful and complete financial and managerial information shall be made available on a timely basis (Information Objective) The Information Objective is to ensure that truthful, complete, and relevant reports are made available on a timely basis as needed for sound decision making supported by adequate justification. 3) Efficiency and effectiveness of business operations (Operational Objective) The Operational Objective is intended to strengthen effectiveness and efficiency in the use of assets and other resources in order to protect the Bank from risk of losses. 2

4 4) Strengthen the effectiveness of risk culture throughout the organization (Risk Culture Objective) The Risk Culture Objective is intended for early recognition of weaknesses and assessment of deficiencies and ongoing review of the propriety of the policies and procedures in place at the Bank. 2. Stakeholders in the Bank Internal Control System The operation of a reliable and effective Internal Control System shall be the responsibility of all parties involved in the Bank organization, including but not limited to: a. Board of Commissioners The Board of Commissioners of the Bank shall be responsible for oversight of the general operation of internal control, including policies adopted by the Board of Directors that establish the internal control. b. Board of Directors The Board of Directors of the Bank shall be responsible for the creation and maintenance of an effective Internal Control System and ensuring that the system operates securely and properly according to the internal control objectives established by the Bank. The Compliance Director is required to play an active role in prevention of deficiencies in management policymaking in regard to prudential banking principles. c. Internal Audit Unit The Internal Audit Unit must be capable of evaluating and playing an active and ongoing role in building the effectiveness of the Internal Control System in regard to the conduct of Bank operations that may potentially impact the ability of the Bank to achieve the targets established by Bank management. In addition, the Bank must also devote attention to the operation of independent audits through adequate reporting lines and the expertise of internal auditors in the area of risk management practices and their application. 3

5 d. Bank officers and employees Each officer and employee of the Bank is required to understand and put into practice the Internal Control System instituted by the Bank management. Effective internal control will strengthen the responsibility of Bank officers and employees, promote an adequate risk culture, and expedite processes for identification of improper banking practices within the organization by means of an efficient early detection system. e. External parties External stakeholders include the Bank supervision authority, the external auditor, and Bank customers, all of whom have an interest in the operation of a reliable and effective Internal Control System. 3. Factors to Consider in the Design of the Bank Internal Control System The Bank must have an Internal Control System that can be applied on an effective basis, taking into account the following factors: a. total assets; b. products and services offered, including new products and services; c. complexity of operations, including office network; d. risk profile for each business line; e. methods used for data processing and information technology and methodology applied in measurement, monitoring, and establishment of risk limits; and f. legal and regulatory provisions. 4. Control Environment The control environment reflects the entirety of commitments, behavior, concern, and actions of the Board of Commissioners and Board of Directors of the Bank in conducting activities for control of Bank operations. 4

6 The factors that make up the control environment include: a. adequate organizational structure; b. leadership style and management philosophy of the Bank; c. integrity, ethical values, and competence of all employees; d. human resources policy and procedures of the Bank; e. attention and direction pursued by the Bank management and other committees, such as the Risk Management Committee; and f. external factors affecting Bank operations and the application of risk management. III. KEY ELEMENTS IN THE BANK INTERNAL CONTROL SYSTEM The Internal Control of a Bank consists of five key interrelated elements: Management Oversight and Control Culture, Risk Recognition and Assessment, Control Activities and Segregation of Duties, Accountancy, Information, and Communication, and Monitoring Activities and Correcting Deficiencies. Internal Control shall consist of at least these five key elements as follows: 1. Management Oversight and Control Culture a. Board of Commissioners The Board of Commissioners shall have the following responsibilities: 1) approval and regular review of the overall policies and business strategy of the Bank; 2) understanding the main risks faced by the Bank, establishment of risk tolerance, and ensuring that the Board of Directors has taken the necessary measures to identify, assess, monitor, and control these risks; 3) approval of the organizational structure; 4) ensuring that the Board of Directors monitors the effectiveness of the Internal Control System. 5

7 In order to fulfill these responsibilities, the Board of Commissioners must: 1) maintain objectiveness and possess knowledge, capacity, and keen interest in understanding the business lines and risks of the Bank; 2) play an active role in ensuring corrective actions to Bank deficiencies that may undermine the effectiveness of the Internal Control System, such as impediments to flow of information from subordinates to management and weaknesses in the operation of the financial, legal, and internal audit functions; 3) hold regular meetings with the Board of Directors and executive officers of the Bank to discuss the effectiveness of the Internal Control System; 4) review findings from evaluation of the internal control system, prepared by the Board of Directors, Internal Audit Unit, and external auditor; 5) take regular measures to ensure that the Board of Directors appropriately follows up the findings and recommendations presented by the Bank supervision authority, internal auditors, and external auditor; 6) conduct a regular review of the validity of the Bank s strategy. b. Board of Directors The Board of Directors shall have the following responsibilities: 1) implement the policy and strategy approved by the Board of Commissioners; 2) develop procedures to identify, assess, monitor, and control risks faced by the Bank; 3) maintain an organizational structure that reflects clearlydelineated powers, responsibilities, and reporting lines; 4) ensure that delegations of authority operate effectively, supported by accountability applied on a consistent basis; 6

8 5) establish internal control policy, strategy, and procedures; and 6) monitor the adequacy and effectiveness of the internal control system. To carry out these responsibilities, the Board of Directors must pursue various measures including the following: 1) assign managers/officers and staff responsible for specific activities to formulate the policy and procedures for internal control of operations and adequacy of the organization; 2) institute effective control to ensure that these policies and procedures have been developed by the managers/officers and employees and, once adopted, put into practice; 3) document an organizational structure that clearly depicts lines of authority and reporting responsibilities and the operation of an effective communication system at all levels of the Bank organization, and familiarize personnel with this organizational structure; 4) take appropriate measures to ensure that internal control activities are conducted by managers/officers and employees possessing adequate experience and capacity; 5) effectively implement corrective actions or recommendations issued by the internal auditor and/or external auditor, including but not limited to delegation of responsibility to employees for putting these actions and recommendations into effect. c. Control Culture The Board of Commissioners and Board of Directors shall be responsible for upholding a high standard of working ethics and integrity and creating an organizational culture that emphasizes to all Bank employees the importance of the internal control established within the Bank. Specific actions that call for the attention and action of the Bank in creating this control culture include the following: 7

9 1) The Board of Commissioners and Board of Directors must be a role model for all employees, having strong personal commitments to the development of a sound Bank; 2) the Board of Commissioners and Board of Directors must be capable of human resources management that includes processes for employee placement according to skills, knowledge, and conduct; 3) improve the awareness of all Bank employees on the importance of effectiveness in carrying out their individual duties and responsibilities and of employees subsequently communicating any problems that may arise in the course of Bank operations to the appropriate management. To support this control culture, all policies, standards, and operating procedures must be documented in writing and made available to all concerned employees. To strengthen ethical values, the Bank must steer clear of polices and practices that may encourage or provide opportunity for irregularities or violations, such as emphasis on the achievement of short-term targets while neglecting the impact of long-term risks, compensation systems disproportionately based on short-term performance, ineffective segregation of duties, and imposition of overly lenient or excessive sanctions for misconduct. 2. Risk Recognition and Assessment a. Risk assessment constitutes a series of actions by the Board of Directors to identify, analyze, and assess the risks faced by the Bank in the pursuit of its business targets. b. Risks may arise or undergo change in keeping with conditions at the Bank, including but not limited to: 1) changes in the operations of the Bank; 2) changes in organization of personnel; 3) changes in the information system; 4) rapid growth in specific business lines; 5) advancements in technology; 8

10 6) development of new services, products, or activities; 7) merger, consolidation, acquisition, and Bank restructuring; 8) changes in the accounting system; 9) business expansion; 10) changes in laws and regulations; and 11) changes in customer behavior and expectations. c. An effective Internal Control System requires that the Bank continuously recognize and assess risks that may impact the achievement of targets. Assessment of risks must also be conducted by internal auditors, and thus the scope of audit must be broader and more comprehensive. d. This assessment must be capable of identifying the risks faced by the bank and determining risk limits and the techniques for control of the risks. The risk assessment methodology must be used as a yardstick in preparing the risk profile in the form of documented data that can be updated on a periodic basis. Risk assessment must also encompass assessment of quantitative risks and qualitative risks in addition to controllable risks and uncontrollable risks, taking account of costs and benefits. The Bank must then decide whether to take on these risks or avoid risks by cutting back certain business activities. e. The assessment must cover all risks faced by the Bank, whether individual or aggregate risk, encompassing credit risk, market risk, liquidity risk, operational risk, legal risk, reputation risk, strategic risk, and compliance risk. f. Internal control must be appropriately reviewed in the event of discovery of any uncontrolled risks, whether comprising existing or newly emerging risks. The review must be conducted, among others, by means of ongoing evaluation of the influence of each change in environment and conditions and the impact of achievement of targets or effectiveness of internal control on the operations and organization of the Bank. 3. Control Activities and Segregation of Duties Control activities must involve all employees of the Bank, including the Board of Directors. Accordingly, control activities will operate 9

11 effectively if planned and applied for the control of identified risks. Control activities also extend to the establishment of control policies and procedures and an earlier verification process to ensure consistent compliance with these policies and procedures, and represent an integral part of all functions or day-to-day activities of the Bank. a. Control Activities Control activities shall encompass the policies, procedures, and practices that provide assurance to Bank officers and employees that the directions of the Board of Commissioners and Board of Directors of the Bank are effectively implemented. These control activities will assist Board members, including the Board of Commissioners of the Bank, in managing and controlling risks that may affect performance or incur losses for the Bank. Control activities shall be applied at all functional levels according to the organizational structure of the Bank, encompassing at least the following: 1) Top Level Reviews The Board of Directors shall regularly request information and operational performance reports from officers and staff, thus enabling a review of progress against target, for example, the financial statement in comparison with budget. On the basis on this review, the Board of Directors will immediately detect problems such as weaknesses in control, errors in the financial statement, or fraud. 2) Functional Review This review shall be conducted by the Internal Audit Unit on a more frequent basis, and may comprise a daily, weekly, or monthly review. a) review of the risk assessment (risk profile report) produced by the risk management unit; b) analysis of operational data, including data pertaining to risks as well as financial data, by verification of transaction detail and activities against the outputs (reports) generated by the risk management unit; and 10

12 c) review of progress in implementation of the business plan and budget in order to: (1) identify causes of significant variations; (2) determine the requirements for corrective actions. 3) Control of the Information System a) The Bank shall verify the accuracy and completeness of transactions and operate authorization procedures in accordance with internal rules. b) Information control activities may be classified by two criteria: general control and application control. (1) General control includes control of the data center operations, the software procurement and maintenance system, security of access, and development and maintenance of existing applications. General control is applied for mainframes, servers, and user workstations, as well as for internal and external networks. (2) Application control is applied for programs used by the Bank in processing transactions to ensure that all transactions are true, accurate, and duly authorized. In addition, application control must be capable of ensuring that an effective audit process is in place and of checking the integrity of that audit process. 4) Physical Controls a) Control of physical assets shall be carried out to ensure the physical security of Bank assets. b) This activity encompasses the securing of assets, records, and restricted access to computer programs and data files, and compares the value of the Bank s assets and liabilities with the value stated in the controller s records, specifically by means of periodic checks on asset value. 5) Documentation 11

13 a) The Bank shall at least formalize and adequately document its accounting policies, procedures, systems, and standards and the audit process. b) The documents must be updated regularly to depict the actual operations of the bank, and officers and employees must be informed accordingly. c) Documents must always be available on demand for internal auditors, the public accountant, and the Bank Indonesia supervision authority. d) The accuracy and availability of the documents must be assessed by the internal auditor when conducting routine and non-routine audits. b. Segregation of Duties 1) Segregation of duties is intended so that no individual in any position has the opportunity to commit and conceal errors or deficiencies in the course of performing their tasks and duties at all levels of the organization and in all stages of operations. The Bank must comply with this principle of segregation of functions, known as the Four Eyes Principle. 2) If necessary, due to changes in the characteristics of business lines, transactions, and organization of the Bank, the Board of Directors shall be required to establish procedures (powers), including the establishment of a list of officers who may access a high risk transaction or business line. 3) An effective Internal Control System requires segregation of duties and steering clear of assigning powers and responsibilities that could give rise to various forms of conflict of interest. All aspects that may give rise to conflict of interest must be carefully identified, minimized, and monitored by an independent party, such as a Public Accountant. 4) In implementing the segregation of duties, Banks must take measures that include the following: a) designation of certain functions or tasks at the bank that must be segregated or allocated to a number of persons 12

14 in order to reduce risk of manipulation of financial data or misuse of Bank assets; b) this segregation of duties is not restricted to front and back office activities, but is also for control of: (1) approvals for release of funds and realized expenditures; (2) customer accounts and accounts of the Bank owners; (3) transactions in the bookkeeping of the Bank; (4) provision of information to Bank customers; (5) assessment of the adequacy of credit documentation and monitoring of debtors after loan disbursement; (6) other business activities that may give rise to significant conflict of interest; (7) independence of the risk management function at the Bank. 4. Accountancy, Information, and Communications The purpose of adequate accounting, information, and communications systems is to identify problems that may arise and to support exchange of information for performance of tasks in line with individual responsibilities. a. Accountancy 1) Accountancy covers the methods and records for identifying, grouping, analyzing, classification, recording/bookkeeping entry, and reporting of Bank transactions. 2) To ensure that accounting data is accurate and consistent with available data based on the output of system processes, accounting data must be reconciled with the management information system on a regular basis or at least every month. Any variations that arise must be immediately investigated and the problem resolved. The 13

15 reconciliation process must also be documented as part of the requirements for the overall audit trail. b. Information 1) The information system must be capable of generating reports on business operations, financial condition, application of risk management, and legal compliance that support the Board of Commissioners and Board of Directors in the performance of their duties. 2) An effective internal control system shall at the minimum provide adequate and comprehensive internal data/information on financial condition, legal and regulatory compliance of the Bank, market information (external conditions), and any events and conditions necessary for sound decision making supported by proper justification. 3) The Internal Control System shall at the minimum provide credible information on all business lines of the Bank, and in particular significant business lines and business lines with potential for high risk. The information system, including the systems for electronic data storage and use, must be guaranteed security, monitored by an independent party (internal auditor), and supported by an adequate contingency recovery plan. 4) The Bank shall at least organize a contingency recovery plan and a backup system to prevent business failure and the attendant high risks. The procedures, process, and the backup system must be documented and reviewed for effectiveness on a regular basis. To ensure that the entire contingency recovery plan and processes operate effectively, the operation of the process and system must be documented and regularly tested. The Bank must document the regular testing and the Board of Directors of the Bank shall give full attention to weaknesses discovered in the system on the basis of the testing and thereafter take the necessary corrective actions. 5) The Bank at the minimum shall have and maintain an information management system operated in both electronic and non-electronic form. In view of the risks posed by an electronic information system and the use of information technology, the Bank must institute effective 14

16 control of these risks to avoid disruption to business and possible major losses to the Bank. 6) In regard to internal control of the operation of the information system and information technology, the Bank must take account of the following: a) the availability of adequate evidence and documents to support the audit trail. The audit trail process must operate effectively and be documented to ensure the effective and accurate operation of automated processes. The Internal Audit Unit shall be required to assess the effectiveness and accuracy of the audit trail when evaluating the operation of the Bank internal control; b) operation of control for the computer system and its security (general controls) and control of software applications and other manual procedures (application controls); c) anticipation of risk of breakdown or losses caused by factors outside the scope of routine control by the Bank, for which the Bank must have in place a recovery system, contingency plans, and regular checks for the possibility of unforeseeable events (disaster and recovery plan). d) the information system must provide relevant, accurate, and timely data and information that is accessible to stakeholders and presented in a consistent format. e) as part of the recording or bookkeeping process, the information system must be supported by a proper accounting system, including procedures and schedules for retention of transaction records. c. Communications 1) The communications system must be capable of providing information to all internal parties and external parties, such as the Bank supervision authority, external auditor, shareholders, and Bank customers. 2) The Internal Control System of the Bank must ensure that effective communication lines are in place to enable all 15

17 officers/employees to fully understand and comply with the applicable policies and procedures when performing their duties and responsibilities. 3) The Board of Directors must operate effective lines of communication so that needed information is accessible to stakeholders. This requirement shall apply to all information, including established policies and procedures, risk exposures, actual transactions, and the operational performance of the Bank. 4) The organizational structure of the Bank must enable adequate information flows, i.e., bottom-up, top-down, and cross-unit information: a) bottom-up information to ensure that the Board of Commissioners, Board of Directors, and executive officers of the Bank are informed of the risks and performance of Bank operations. These lines of communication must be capable of delivering responses for implementing corrective actions and keeping line management informed accordingly. b) top-down information to ensure that the objectives, strategy, and expectations of the Bank and its policies and procedures are communicated to lower level managers and personnel. c) cross-unit information to ensure that information known to one unit can be conveyed to all other relevant units, in particular for prevention of conflict of interest in decision making and to build adequate coordination. 5. Monitoring Activities and Correcting Deficiencies a. Monitoring Activities 1) The Bank must constantly monitor the overall effectiveness of internal control operations. Priority must be given to monitoring the major risks of the Bank and this monitoring must be incorporated into day-to-day Bank activities, including regular evaluation by both operational units and the Internal Audit Unit. 2) The Bank must constantly monitor and evaluate the adequacy of the Internal Control System in regard to 16

18 changes in internal and external conditions and must improve the capacity of the internal control system in order to raise effectiveness. 3) The measures that must be pursued by the Bank for effective organization of monitoring are at least the following: a) ensure that the monitoring function is clearly established and properly structured within the Bank organization; b) designate a unit/employee assigned to monitor the effectiveness of internal control; c) determine the proper frequency for monitoring activities on the basis of the inherent risks in the Bank and the nature/frequency of changes in operations; d) integrate the Internal Control System into operations and provide regular reports such as the bookkeeping journal, management review, and reports on justification for irregularities for subsequent review; e) review documentation and results of evaluation conducted by units/employees assigned to monitoring duties; f) adopt a suitable format and frequency for information and feedback. b. Functions of the Internal Audit Unit 1) The Bank must conduct an effective and comprehensive internal audit of the internal control system. The internal audit work conducted by the Internal Audit Unit must be supported by an adequate number of independent, competent auditors. 2) As part of the Internal Control System, the Internal Audit Unit must report its findings directly to the Board of Commissioners or Audit Committee (if any), the President Director, and the Compliance Director. 3) The Internal Audit Unit must conduct an independent evaluation of the adequacy of established polices and 17

19 procedures and the Bank s compliance with these policies and procedures. 4) In determining the position, powers, responsibilities, professionalism, organization, and scope of the Internal Audit Unit, the Bank must also follow the guidelines in the applicable Bank Indonesia regulations concerning the Compliance Director and the Standard Practices for the Internal Audit Function (SPFAIB). c. Correction of Weaknesses and Corrective Actions 1) Any weaknesses in internal control, whether identified by a risk taking unit, the Internal Audit Unit, or any other party, must be immediately reported to and receive the attention of the competent officer or member of the Board of Directors. Any material weaknesses in internal control must also be reported to the Board of Commissioners. 2) Improvements that must be made by the Bank to correct weaknesses in internal control include but are not limited to the following: a) each report of weaknesses in internal control or lack of effectiveness in the risk management of the Bank must be immediately followed up by the Board of Commissioners, Board of Directors, and the relevant executive officers; b) the Internal Audit Unit must review or otherwise conduct adequate monitoring of weaknesses that come to light and immediately inform the Board of Commissioners, Audit Committee (if any), and the President Director in the event of any failure to remedy weaknesses or follow up corrective actions; c) to ensure prompt follow up of all weaknesses, the Board of Directors must create a system capable of tracking weaknesses in internal control and taking correcting actions; d) the Board of Commissioners and Board of Directors must receive regular reports in the form of summarized findings of all problems identified in internal control. 18

20 IV. MISCELLANEOUS PROVISIONS In their application of internal control, Banks are required to take into account various aspects of internal control stipulated in other Bank Indonesia regulations, including those set forth in: 1. Decree of the Management of Bank Indonesia Number 27/162/ KEP/DIR and Circular Letter of Bank Indonesia Number 27/7/UPPB, both dated March 31, 1995, concerning the Requirement for Formulation and Implementation of Credit Policy for Commercial Banks; 2. Decree of the Management of Bank Indonesia Number 27/164/ KEP/DIR and Circular Letter of Bank Indonesia Number 27/9/UPPB, both dated March 31, 1995, concerning Use of Information System Technology by Banks; 3. Decree of the Management of Bank Indonesia Number 28/119/ KEP/DIR and Circular Letter of Bank Indonesia Number 28/13/UPPB, both dated December 29, 1995, concerning Derivative Transactions; 4. Decree of the Management of Bank Indonesia Number 31/150/ KEP/DIR and Circular Letter of Bank Indonesia Number 31/12/UPPB, both dated November 12, 1998, concerning Debt Restructuring, as amended by Bank Indonesia Regulation Number 2/15/PBI/2000 dated June 12, 2000; 5. Bank Indonesia Regulation Number 1/6/PBI/1999 dated September 20, 1999, concerning Designation of Compliance Director and Standard Practices for the Bank Internal Audit Function (SPFAIB); 6. Bank Indonesia Regulation Number 3/10/PBI/2001 dated June 18, 2001, concerning Application of Know Your Customer Principles as amended by Bank Indonesia Regulation Number 3/23/PBI/2001 dated December 13, 2001; 7. Circular Letter of Bank Indonesia Number 3/29/DPNP dated December 13, 2001, concerning Standard Guidelines for Application of Know Your Customer Principles; 8. Bank Indonesia Regulation Number 3/22/PBI/2001 dated December 13, 2001, concerning Transparency of Financial Condition of Banks; 19

21 9. Bank Indonesia Regulation Number 5/10/PBI/2001 dated December 13, 2001, concerning Prudential Principles in Equity Participation; 10. Circular Letter of Bank Indonesia Number 5/21/DPNP dated September 29, 2003, concerning Application of Risk Management for Commercial Banks. 20

RREGULATION ON INTERNAL CONTROLS AND INTERNAL AUDIT FUNCTION IN MICROFINANCE INSTITUTIONS. Article 1 Scope and Purpose

RREGULATION ON INTERNAL CONTROLS AND INTERNAL AUDIT FUNCTION IN MICROFINANCE INSTITUTIONS. Article 1 Scope and Purpose Pursuant to Article 35, paragraph 1.1 of the Law No. 03/L-209 on Central Bank of the Republic of Kosovo (Official Gazette of the Republic of Kosovo, No.77 / 16 August 2010) and Articles 98, 103 and 114

More information

BOM/BSD 2/November 1994 BANK OF MAURITIUS. Guideline on Maintenance of Accounting and other Records and Internal Control Systems

BOM/BSD 2/November 1994 BANK OF MAURITIUS. Guideline on Maintenance of Accounting and other Records and Internal Control Systems BOM/BSD 2/November 1994 BANK OF MAURITIUS Guideline on Maintenance of Accounting and other Records and Internal Control Systems November 1994 Revised November 2013 Revised December 2017 TABLE OF CONTENTS

More information

Internal Audit Policy and Procedures Internal Audit Charter

Internal Audit Policy and Procedures Internal Audit Charter Mission Statement Internal Audit Policy and Procedures Internal Audit Charter The mission of the Internal Audit Department is to provide independent and objective reviews and assessments of the business

More information

OPERATIONAL RISK EXAMINATION TECHNIQUES

OPERATIONAL RISK EXAMINATION TECHNIQUES OPERATIONAL RISK EXAMINATION TECHNIQUES 1 OVERVIEW Examination Planning Oversight Policies, Procedures, and Limits Measurement, Monitoring, and MIS Internal Controls and Audit 2 Risk Assessment: Develop

More information

STRAGETIC RISK MANUAL

STRAGETIC RISK MANUAL Strategic Risk Manual 1 Unofficial Translation prepared by The Foreign Banks' Association This translation is for the convenience of those unfamiliar with the Thai language. Please refer to the Thai text

More information

LI & FUNG LIMITED ANNUAL REPORT 2016

LI & FUNG LIMITED ANNUAL REPORT 2016 52 Our approach to risk management We maintain a sound and effective system of risk management and internal controls to support us in achieving high standards of corporate governance. Our approach to risk

More information

GUIDELINES FOR THE INTERNAL CONTROL AND RISK MANAGEMENT SYSTEM OF THE TOD'S S.P.A. GROUP

GUIDELINES FOR THE INTERNAL CONTROL AND RISK MANAGEMENT SYSTEM OF THE TOD'S S.P.A. GROUP GUIDELINES FOR THE INTERNAL CONTROL AND RISK MANAGEMENT SYSTEM OF THE TOD'S S.P.A. GROUP (TRANSLATION OF THE DOCUMENT ISSUED AND APPROVED IN ITALIAN BY THE BOARD OF DIRECTORS OF THE COMPANY IN THE MEETING

More information

Application: All licensed institutions and supervisory personnel

Application: All licensed institutions and supervisory personnel Title: SR-1 Strategic Risk Management Date: FINAL Purpose: To set out the approach which the NBRM will adopt in the supervision of licensed institutions strategic risk, and to provide guidance to licensed

More information

Guidance Note: Corporate Governance - Board of Directors. January Ce document est aussi disponible en français.

Guidance Note: Corporate Governance - Board of Directors. January Ce document est aussi disponible en français. Guidance Note: Corporate Governance - Board of Directors January 2018 Ce document est aussi disponible en français. Applicability The Guidance Note: Corporate Governance - Board of Directors (the Guidance

More information

Internal Control Systems

Internal Control Systems Internal Control Systems What are Internal Controls? Internal Controls are a set of rules, policies, and procedures a municipality can implement to provide reasonable assurances that: its financial reports

More information

An Overview of the 2013 COSO Framework. August 2013

An Overview of the 2013 COSO Framework. August 2013 An Overview of the 2013 COSO Framework August 2013 Introduction Dean Geesler, KPMG Senior Manager Course Objectives Summarize the key changes from the 1992 Framework to the 2013 Framework including the

More information

Corporate Governance. Basic Approach to Corporate Governance. 1. Outline of corporate governance structure

Corporate Governance. Basic Approach to Corporate Governance. 1. Outline of corporate governance structure Corporate Governance Basic Approach to Corporate Governance The Bank s management policy is to improve management efficiency and transparency to receive high evaluation from and build unshakable bonds

More information

In the first year of The 13th Medium-term Management Plan. Earnings capability. Net income

In the first year of The 13th Medium-term Management Plan. Earnings capability. Net income Management Strategy In the first year of The 13th Medium-term Management Plan FY2014 will mark the first year of The 13th Medium-Term Management Plan ~ All For Your Smile: Providing Wholehearted Services,

More information

Internal Audit Charter

Internal Audit Charter Internal Audit Charter 1/9 1.0 INTRODUCTION 1.1. Legal Standing a. Bank Indonesia Regulation No.1/6/PBI/1999 dated 20 September 1999 concerning Designation of Compliance Director and Application of the

More information

GUIDANCE NOTE FOR DEPOSIT TAKERS (Class 1(1) and Class 1(2))

GUIDANCE NOTE FOR DEPOSIT TAKERS (Class 1(1) and Class 1(2)) GUIDANCE NOTE FOR DEPOSIT TAKERS (Class 1(1) and Class 1(2)) Operational Risk Management MARCH 2017 STATUS OF GUIDANCE The Isle of Man Financial Services Authority ( the Authority ) issues guidance for

More information

Internal Control in Higher Education

Internal Control in Higher Education Internal Control in Higher Education Daniel Adams Office of Audit Services Audit Services Mission To provide assurance and advisory services that are independent, objective and risk-based in order to protect

More information

Our Approach to Risk Management

Our Approach to Risk Management 62 Li & Fung Limited Annual Report 2017 Our Approach to Risk Management Our Approach to Risk Management We maintain a solid, effective system of risk management and internal controls to support us in achieving

More information

COPY OF FINANCIAL SERVICES AUTHORITY REGULATION NUMBER 4 /POJK.03/2016 CONCERNING ASSESSMENT OF COMMERCIAL BANK SOUNDNESS LEVEL

COPY OF FINANCIAL SERVICES AUTHORITY REGULATION NUMBER 4 /POJK.03/2016 CONCERNING ASSESSMENT OF COMMERCIAL BANK SOUNDNESS LEVEL COPY OF FINANCIAL SERVICES AUTHORITY REGULATION NUMBER 4 /POJK.03/2016 CONCERNING ASSESSMENT OF COMMERCIAL BANK SOUNDNESS LEVEL WITH THE BLESSINGS OF GOD ALMIGHTY, BOARD OF COMMISSIONERS OF FINANCIAL SERVICES

More information

GENERALI GROUP GROUP INTERNAL CONTROL AND RISK MANAGEMENT SYSTEM VERSION 2.0

GENERALI GROUP GROUP INTERNAL CONTROL AND RISK MANAGEMENT SYSTEM VERSION 2.0 GENERALI GROUP GROUP INTERNAL CONTROL AND RISK MANAGEMENT SYSTEM VERSION 2.0 TABLE OF CONTENTS 1. INTRODUCTION...3 2. THE INTEGRATED APPROACH TO RISKS AND CONTROLS...4 3. INTERNAL CONTROL AND RISK MANAGEMENT

More information

The COSO Risk Framework: A reference for internal control? Transition from COSO I to COSO II

The COSO Risk Framework: A reference for internal control? Transition from COSO I to COSO II The COSO Risk Framework: A reference for internal control? Transition from COSO I to COSO II S P E A K E R : D O T T. FA B I O A C C A R D I C O U R S E O F B U S I N E S S A U D I T I N G U N I V E R

More information

PART 6 - INTERNAL CONTROL

PART 6 - INTERNAL CONTROL PART 6 - INTERNAL CONTROL INTRODUCTION The A-102 Common Rule and OMB Circular A-110 (2 CFR part 215) require that non-federal entities receiving Federal awards (i.e., auditee management) establish and

More information

DECISION 10/2014/GB OF THE GOVERNING BOARD OF THE EUROPEAN POLICE COLLEGE ADOPTING THE EUROPEAN POLICE COLLEGE S INTERNAL CONTROL STANDARDS AND

DECISION 10/2014/GB OF THE GOVERNING BOARD OF THE EUROPEAN POLICE COLLEGE ADOPTING THE EUROPEAN POLICE COLLEGE S INTERNAL CONTROL STANDARDS AND DECISION 10/2014/GB OF THE GOVERNING BOARD OF THE EUROPEAN POLICE COLLEGE ADOPTING THE EUROPEAN POLICE COLLEGE S INTERNAL CONTROL STANDARDS AND AMENDING THE DECISION 08/2011/GB Adopted by the Governing

More information

CORPORATE GOVERNANCE GUIDELINES

CORPORATE GOVERNANCE GUIDELINES CORPORATE GOVERNANCE GUIDELINES [Translation] Chapter 1 General Provisions Article 1 Purpose These Guidelines set forth the Company s basic views and systems regarding corporate governance in order to

More information

AmMetLife Insurance Berhad BOARD CHARTER

AmMetLife Insurance Berhad BOARD CHARTER BOARD CHARTER 1. Introduction 1.1 The Board of Directors (the Board ) regard sound Corporate Governance as vital to the success of the Company s business and are unreservedly committed to applying the

More information

Internal Controls: Need Them, Have Them, Love Them

Internal Controls: Need Them, Have Them, Love Them Internal Controls: Need Them, Have Them, Love Them Tiffany R. Winters, Esquire twinters@bruman.com Brustein & Manasevit Fall Forum 2010 Why Do We Have Internal Controls? The Federal Managers Financial

More information

LeiningerCPA, Ltd. RISK MANAGEMENT POLICY STATEMENT

LeiningerCPA, Ltd. RISK MANAGEMENT POLICY STATEMENT LeiningerCPA, Ltd. RISK MANAGEMENT POLICY STATEMENT This policy provides an overview of the bank s risk management process and defines the broad responsibilities for overseeing corporate governance and

More information

Guide to Internal Controls

Guide to Internal Controls Guide to Internal Controls Table of Contents Introduction to Internal Controls...3 Roles...4 Components....5 Control Environment...5 Risk assessment...6 Control Activities...7 Information & Communication...9

More information

REBOSIS PROPERTY FUND LIMITED AUDIT AND RISK COMMITTEE TERMS OF REFERENCE

REBOSIS PROPERTY FUND LIMITED AUDIT AND RISK COMMITTEE TERMS OF REFERENCE CONSTITUTION REBOSIS PROPERTY FUND LIMITED AUDIT AND RISK COMMITTEE TERMS OF REFERENCE The company has established an Audit and Risk Committee ( Committee ) to assist the board of directors in discharging

More information

Auditing Standards and Practices Council

Auditing Standards and Practices Council Auditing Standards and Practices Council PHILIPPINE STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT PHILIPPINE STANDARD ON AUDITING

More information

INTERNATIONAL STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT CONTENTS

INTERNATIONAL STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT CONTENTS INTERNATIONAL STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT (Effective for audits of financial statements for periods beginning

More information

INTERNAL CONTROLS FOR NONPROFITS

INTERNAL CONTROLS FOR NONPROFITS INTERNAL S FOR NONPROFITS Best Practice Principles, Policies, and Procedures 1 INTERNAL S FOR NONPROFITS GUIDE BACK NEXT PAGE S WITH INTERNAL S FOR NONPROFITS: Best Practice Principles, Policies, and Procedures

More information

An Audit of Internal Control Over Financial Reporting Performed in Conjunction with An Audit of Financial Statements

An Audit of Internal Control Over Financial Reporting Performed in Conjunction with An Audit of Financial Statements Page A 1 Standard Appendix Auditing Standard No. 2 AUDITING AND RELATED PROFESSIONAL PRACTICE STANDARDS Auditing Standard No. 2 An Audit of Internal Control Over Financial Reporting Performed in Conjunction

More information

An Audit of Internal Control Over Financial Reporting Performed in Conjunction with An Audit of Financial Statements

An Audit of Internal Control Over Financial Reporting Performed in Conjunction with An Audit of Financial Statements AUDITING STANDARD No. 2 An Audit of Internal Control Over Financial Reporting Performed in Conjunction with An Audit of Financial Statements March 9, 2004 AUDITING AND RELATED PROFESSIONAL PRACTICE STANDARDS

More information

ADMINISTRATIVE INTERNAL AUDIT Board of Trustees Approval: 03/10/2004 CHAPTER 1 Date of Last Cabinet Review: 04/07/2017 POLICY 3.

ADMINISTRATIVE INTERNAL AUDIT Board of Trustees Approval: 03/10/2004 CHAPTER 1 Date of Last Cabinet Review: 04/07/2017 POLICY 3. INTERNAL AUDIT Board of Trustees Approval: 03/10/2004 POLICY 3.01 Page 1 of 14 I. POLICY The Internal Audit Department assists Salt Lake Community College in accomplishing its objectives by providing an

More information

Guidance Note: Corporate Governance - Audit Committee. January Ce document est aussi disponible en français.

Guidance Note: Corporate Governance - Audit Committee. January Ce document est aussi disponible en français. Guidance Note: Corporate Governance - Audit Committee January 2018 Ce document est aussi disponible en français. Applicability The Guidance Note: Corporate Governance Audit Committee (the Guidance Note

More information

DIRECTOR TRAINING AND QUALIFICATIONS: SAMPLE SELF-ASSESSMENT TOOL February 2015

DIRECTOR TRAINING AND QUALIFICATIONS: SAMPLE SELF-ASSESSMENT TOOL February 2015 DIRECTOR TRAINING AND QUALIFICATIONS: SAMPLE SELF-ASSESSMENT TOOL February 2015 DIRECTOR TRAINING AND QUALIFICATIONS SAMPLE SELF-ASSESSMENT TOOL INTRODUCTION The purpose of this tool is to help determine

More information

The definition of a deficiency is also set forth in the attached Appendix I.

The definition of a deficiency is also set forth in the attached Appendix I. Deloitte & Touche LLP 361 South Marine Corps Drive Tamuning, GU 96913-3973 USA Tel: (671)646-3884 Fax: (671)649-4932 www.deloitte.com May 26, 2014 Mr. David Paul General Manager Marshalls Energy Company,

More information

Corporate Governance. Information Request List Family- or Founder-Owned Unlisted Companies. Commitment to Corporate Governance

Corporate Governance. Information Request List Family- or Founder-Owned Unlisted Companies. Commitment to Corporate Governance Commitment to Corporate Governance 1. Policies relating to corporate governance. What written policies, codes or manuals have been elaborated that set out the company s approach to governance, the respective

More information

Comparison of the PCAOB s Auditing Standards No. 5 and No. 2 (Certain key differences are highlighted by underlining)

Comparison of the PCAOB s Auditing Standards No. 5 and No. 2 (Certain key differences are highlighted by underlining) Comparison of the PCAOB s Auditing Standards No. 5 and No. 2 (Certain key differences are highlighted by underlining) Topic AS No. 5 AS No. 2 Objective of ICFR Audit Planning the ICFR Audit Integration

More information

CITIBANK N.A JORDAN. Governance and Management of Information and Related Technologies Guide

CITIBANK N.A JORDAN. Governance and Management of Information and Related Technologies Guide CITIBANK N.A JORDAN Governance and Management of Information and Related Technologies Guide 2018 Table of Contents 1. OVERVIEW... 2 2. Governance of Enterprise IT... 3 3. Principles of Governance of Enterprise

More information

English Translation (For Information Purposes Only) CODE OF BEST CORPORATE PRACTICES. Introduction

English Translation (For Information Purposes Only) CODE OF BEST CORPORATE PRACTICES. Introduction English Translation (For Information Purposes Only) SCHEDULE A CODE OF BEST CORPORATE PRACTICES Introduction Upon the initiative of the Business Coordinating Council, the Corporate Governance Committee

More information

MIDAS HOLDINGS LIMITED. TERMS OF REFERENCE OF THE BOARD (Adopted pursuant to the Board resolution passed on 28 March 2012)

MIDAS HOLDINGS LIMITED. TERMS OF REFERENCE OF THE BOARD (Adopted pursuant to the Board resolution passed on 28 March 2012) MIDAS HOLDINGS LIMITED TERMS OF REFERENCE OF THE BOARD (Adopted pursuant to the Board resolution passed on 28 March 2012) 1. Establishment 1.1 The board of directors ( the Board ) is established by Midas

More information

Understanding Internal Controls Office of Internal Audit

Understanding Internal Controls Office of Internal Audit Understanding Internal Controls Office of Internal Audit July 2015 Objectives for this manual Provide guidance to help management understand their responsibility to ensure that internal controls are established,

More information

Final May Corporate Governance Guideline

Final May Corporate Governance Guideline Final May 2006 Corporate Governance Guideline Table of Contents 1. INTRODUCTION 1 2. PURPOSES OF GUIDELINE 1 3. APPLICATION AND SCOPE 2 4. DEFINITIONS OF KEY TERMS 2 5. FRAMEWORK USED BY CENTRAL BANK TO

More information

INTERNAL CONTROLS FOR NONPROFITS

INTERNAL CONTROLS FOR NONPROFITS INTERNAL S FOR NONPROFITS Best Practice Principles, Policies, and Procedures 1 INTERNAL S FOR NONPROFITS GUIDE BACK NEXT PAGE S WITH INTERNAL S FOR NONPROFITS: Best Practice Principles, Policies, and Procedures

More information

DECISION. mb a5 EFSA Internal Control Framework. Internal Control Framework of the European Food Safety Authority. Decision No.

DECISION. mb a5 EFSA Internal Control Framework. Internal Control Framework of the European Food Safety Authority. Decision No. mb171212-a5 EFSA Internal Control Framework LEGAL & ASSURANCE SERVICES DECISION EFSA European Food Safety Authority Internal Control Framework of the European Food Safety Authority Effective Date: 1 January

More information

An Examination of an Entity s Internal Control Over Financial Reporting That Is Integrated With an Audit of Its Financial Statements

An Examination of an Entity s Internal Control Over Financial Reporting That Is Integrated With an Audit of Its Financial Statements ASB Meeting July 30 August 1, 2013 Agenda Item 3B AT Section 501 An Examination of an Entity s Internal Control Over Financial Reporting That Is Integrated With an Audit of Its Financial Statements Source:

More information

Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement

Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement Issued December 2007 International Standard on Auditing Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement The Malaysian Institute of Certified Public Accountants

More information

CGMA Competency Framework

CGMA Competency Framework CGMA Competency Framework Technical skills CGMA Competency Framework 1 Technical skills : This requires a basic understanding of the business structures, operations and financial performance, and includes

More information

EXECUTIVE SUMMARY INTERNAL AUDIT REPORT. IOM Berlin DE NOVEMBER 2017

EXECUTIVE SUMMARY INTERNAL AUDIT REPORT. IOM Berlin DE NOVEMBER 2017 EXECUTIVE SUMMARY INTERNAL AUDIT REPORT IOM Berlin DE201701 15-23 NOVEMBER 2017 Issued by the Office of the Inspector General Page 1 of 8 Report on the Audit of IOM Berlin Executive Summary Audit File

More information

Guidance Note: Corporate Governance - Audit Committee. March Ce document est aussi disponible en français.

Guidance Note: Corporate Governance - Audit Committee. March Ce document est aussi disponible en français. Guidance Note: Corporate Governance - Audit Committee March 2015 Ce document est aussi disponible en français. Applicability The Guidance Note: Corporate Governance Audit Committee (the Guidance Note )

More information

Internal Audit Report

Internal Audit Report Internal Audit Report Key Financial Controls Accounts Payable and Accounts Receivable December 2017 To: Deputy Chief Executive Director of Finance Head of Finance Finance Manager Copied to: Operations

More information

LeiningerCPA, Ltd. INTERNAL AUDIT AND CONTROL POLICY STATEMENT. Summary of Overall Responsibilities and Objectives

LeiningerCPA, Ltd. INTERNAL AUDIT AND CONTROL POLICY STATEMENT. Summary of Overall Responsibilities and Objectives LeiningerCPA, Ltd. INTERNAL AUDIT AND CONTROL POLICY STATEMENT This policy statement provides an overview of the internal audit and control process and defines the broad responsibilities for overseeing

More information

Evaluating Internal Controls

Evaluating Internal Controls A SSURANCE AND A DVISORY BUSINESS S ERVICES Fourth in the Series!@# Evaluating Internal Controls Evaluating Overall Effectiveness, Identifying Matters for Improvement, and Ongoing Assessment of Controls

More information

Community Bankers Conference

Community Bankers Conference 3rd Annual Regional and Community Bankers Conference The Federal Reserve Bank of Boston Disclaimer NEVER WRONG DON T COMPLETELY RELY UPON Recent Developments in Audit Practice SOX, FDICIA 112, Other Robert

More information

The Development of Public Internal Financial Control in Albania And His Role in Strengthening the Managerial Accountability

The Development of Public Internal Financial Control in Albania And His Role in Strengthening the Managerial Accountability The Development of Public Internal Financial Control in Albania And His Role in Strengthening the Managerial Accountability Doi:10.5901/ajis.2014.v3n4p301 Abstract Dr. Hysen Muceku hysen_muceku@hotmail.com

More information

The most commonly applied model for designing and auditing internal

The most commonly applied model for designing and auditing internal Fair Value Accounting Fraud: New Global Risks and Detection Techniques By Gerard M. Zack Copyright 2009 by Gerard M. Zack Appendix C Internal Controls over Fair Value Accounting Applications The most commonly

More information

PT Mandom Indonesia Tbk GCG

PT Mandom Indonesia Tbk GCG REGULATION OF THE INTERNAL AUDIT DEPARTMENT Chapter I GENERAL PROVISIONS Article 1 Purpose The purpose of this regulation is to serve the function of internal control for the company s activities with

More information

Corporate Governance Statement

Corporate Governance Statement - 2017 OVERVIEW The Board is responsible for the overall corporate governance of the Company, including establishing and monitoring key performance goals. It is committed to attaining standards of corporate

More information

INTERNAL FINANCIAL CONTROL POLICY

INTERNAL FINANCIAL CONTROL POLICY INTERNAL FINANCIAL CONTROL POLICY Legal Framework This policy has been formulated pursuant to Section 135 of the Companies Act, 2013, for ensuring the orderly and efficient conduct of the business of the

More information

GUIDELINE FOR IMPLEMENTATION OF ANTI-FRAUD STRATEGY FOR COMMERCIAL BANKS

GUIDELINE FOR IMPLEMENTATION OF ANTI-FRAUD STRATEGY FOR COMMERCIAL BANKS Attachment 1 BANK INDONESIA CIRCULAR LETTER NUMBER 13/28/DPNP DATED 9 DECEMBER 2011 CONCERNING IMPLEMENTATIONOF ANTI-FRAUD STRATEGY FOR COMMERCIAL BANKS GUIDELINE FOR IMPLEMENTATION OF ANTI-FRAUD STRATEGY

More information

UNITY TRUST BANK PLC ( the Bank ) AUDIT AND RISK COMMITTEE

UNITY TRUST BANK PLC ( the Bank ) AUDIT AND RISK COMMITTEE UNITY TRUST BANK PLC ( the Bank ) AUDIT AND RISK COMMITTEE Terms of Reference 1. Constitution The Audit and Risk Committee (the Committee) was established by a resolution of the Board on. 2. Membership

More information

4. Organic documents. Please provide an English translation of the company s charter, by-laws and other organic documents.

4. Organic documents. Please provide an English translation of the company s charter, by-laws and other organic documents. Commitment to Good Corporate Governance 1. Ownership structure. Please provide a chart setting out the important shareholdings, holding companies, affiliates and subsidiaries of the company. If the company

More information

CGMA Competency Framework

CGMA Competency Framework CGMA Competency Framework Technical Skills CGMA Competency Framework 8 Technical Skills : This requires a basic understanding of the business structures, operations and financial performance, and includes

More information

The definition of a deficiency is also set forth in the attached Appendix I.

The definition of a deficiency is also set forth in the attached Appendix I. Deloitte & Touche LLP 361 South Marine Corps Drive Tamuning, GU 96913-3911 USA September 22, 2015 Tel: (671)646-3884 Fax: (671)649-4932 www.deloitte.com Mr. David Paul General Manager Marshalls Energy

More information

In Control: Getting Familiar with the New COSO Guidelines. CSMFO Monterey, California February 18, 2015

In Control: Getting Familiar with the New COSO Guidelines. CSMFO Monterey, California February 18, 2015 In Control: Getting Familiar with the New COSO Guidelines CSMFO Monterey, California February 18, 2015 1 Background on COSO Part 1 2 Development of a comprehensive framework of internal control Internal

More information

9. Internal control Internal control, as defined in accounting and auditing, is a process for assuring achievement of an organization's objectives in

9. Internal control Internal control, as defined in accounting and auditing, is a process for assuring achievement of an organization's objectives in 9. Internal control Internal control, as defined in accounting and auditing, is a process for assuring achievement of an organization's objectives in operational effectiveness and efficiency, reliable

More information

UNITY TRUST BANK PLC ( the Bank ) AUDIT AND RISK COMMITTEE. Terms of Reference

UNITY TRUST BANK PLC ( the Bank ) AUDIT AND RISK COMMITTEE. Terms of Reference UNITY TRUST BANK PLC ( the Bank ) AUDIT AND RISK COMMITTEE Terms of Reference 1. Constitution The Audit and Risk Committee (the Committee) was established by a resolution of the Board on 24 September 2015.

More information

INTERNATIONAL STANDARD ON AUDITING 260 COMMUNICATION WITH THOSE CHARGED WITH GOVERNANCE CONTENTS

INTERNATIONAL STANDARD ON AUDITING 260 COMMUNICATION WITH THOSE CHARGED WITH GOVERNANCE CONTENTS Introduction INTERNATIONAL STANDARD ON AUDITING 260 COMMUNICATION WITH THOSE CHARGED WITH GOVERNANCE (Effective for audits of financial statements for periods beginning on or after December 15, 2009) +

More information

International Standards for the Professional Practice of Internal Auditing (Standards)

International Standards for the Professional Practice of Internal Auditing (Standards) INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS) Attribute Standards 1000 Purpose, Authority, and Responsibility The purpose, authority, and responsibility of the

More information

TORONTO COMMUNITY HOUSING CORPORATION CHARTER OF THE BOARD OF DIRECTORS

TORONTO COMMUNITY HOUSING CORPORATION CHARTER OF THE BOARD OF DIRECTORS TORONTO COMMUNITY HOUSING CORPORATION CHARTER OF THE BOARD OF DIRECTORS PURPOSE: Toronto Community Housing Corporation ( TCHC ) is the largest social housing provider in Canada and the second largest in

More information

PRIVY COUNCIL OFFICE. Audit of PCO s Accounts Payable Function. Final Report

PRIVY COUNCIL OFFICE. Audit of PCO s Accounts Payable Function. Final Report [*] An asterisk appears where sensitive information has been removed in accordance with the Access to Information Act and Privacy Act. PRIVY COUNCIL OFFICE Audit and Evaluation Division Final Report January

More information

Policy and Procedures Date: November 5, 2017

Policy and Procedures Date: November 5, 2017 Virginia Polytechnic Institute and State University No. 3350 Rev.: 8 Policy and Procedures Date: November 5, 2017 Subject: Charter for the Office of Audit, Risk, and Compliance 1. Purpose... 1 2. Policy...

More information

STARWOOD HOTELS & RESORTS WORLDWIDE, INC. CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS

STARWOOD HOTELS & RESORTS WORLDWIDE, INC. CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS STARWOOD HOTELS & RESORTS WORLDWIDE, INC. CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS Starwood Hotels & Resorts Worldwide, Inc. (the Company ) has determined that it is of the utmost importance

More information

(the Company) The Committee also monitors the processes which are undertaken by management and auditors.

(the Company) The Committee also monitors the processes which are undertaken by management and auditors. (the Company) 2 AUDIT and RISK MANAGEMENT COMMITTEE This policy governs the operations of the Audit and Risk Management Committee. The Committee shall review and reassess the policy at least annually and

More information

Mapping of Original ISA 315 to New ISA 315 s Standards and Application Material (AM) Agenda Item 2-C

Mapping of Original ISA 315 to New ISA 315 s Standards and Application Material (AM) Agenda Item 2-C Mapping of to 315 s and Application Material (AM) Agenda Item 2-C AM 1. The purpose of this International Standard on Auditing (ISA) is to establish standards and to provide guidance on obtaining an understanding

More information

POLICY. Number: Title: Internal Control Responsible Office: USF System Audit I. PURPOSE AND INTENT

POLICY. Number: Title: Internal Control Responsible Office: USF System Audit I. PURPOSE AND INTENT 1 2 3 USF System USF USFSP USFSM POLICY 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 Number: 0-023 Title: Internal Control Responsible Office:

More information

Corporate Governance Principles 2015

Corporate Governance Principles 2015 Corporate s 2015 corporate principles 1 corporate principles 1. Ethical leadership and corporate citizenship Responsible leadership 1.1 The board should provide effective leadership based on an ethical

More information

STATEMENT ON RISK MANAGEMENT AND INTERNAL CONTROL

STATEMENT ON RISK MANAGEMENT AND INTERNAL CONTROL STATEMENT ON RISK MANAGEMENT AND INTERNAL CONTROL FINANCIAL YEAR ENDED 31 DECEMBER 2017 INTRODUCTION The Board of Directors is pleased to provide the Statement on Risk Management and Internal Control pursuant

More information

INTERNAL CONTROLS FOR NONPROFITS

INTERNAL CONTROLS FOR NONPROFITS INTERNAL S FOR NONPROFITS Best Practice Principles, Policies, and Procedures INTRO 1 INTERNAL S FOR NONPROFITS GUIDE BACK NEXT PAGE INTERNAL S FOR NONPROFITS: Best Practice Principles, Policies, and Procedures

More information

Corporate Governance Guidelines

Corporate Governance Guidelines Corporate Governance Guidelines Chapter 1. General Provisions Article 1. Purpose These guidelines set out the basic policy, framework and operating policy of the corporate governance of Fuji Heavy Industries

More information

IAASB Main Agenda (September 2004) Page Agenda Item PROPOSED REVISED INTERNATIONAL STANDARD ON AUDITING 540

IAASB Main Agenda (September 2004) Page Agenda Item PROPOSED REVISED INTERNATIONAL STANDARD ON AUDITING 540 IAASB Main Agenda (September 2004) Page 2004 1651 Agenda Item 4-A PROPOSED REVISED INTERNATIONAL STANDARD ON AUDITING 540 AUDITING ACCOUNTING ESTIMATES AND RELATED DISCLOSURES (EXCLUDING THOSE INVOLVING

More information

FREQUENTLY ASKED QUESTIONS ABOUT INTERNAL CONTROL OVER FINANCIAL REPORTING

FREQUENTLY ASKED QUESTIONS ABOUT INTERNAL CONTROL OVER FINANCIAL REPORTING FREQUENTLY ASKED QUESTIONS ABOUT INTERNAL CONTROL OVER FINANCIAL REPORTING Nature and Timing of the Reporting Requirement When must registrants begin to report on internal control over financial reporting?

More information

IAASB CAG Public Session (March 2018) CONFORMING AND CONSEQUENTIAL AMENDMENTS ARISING FROM DRAFT PROPOSED ISA 540 (REVISED) 1

IAASB CAG Public Session (March 2018) CONFORMING AND CONSEQUENTIAL AMENDMENTS ARISING FROM DRAFT PROPOSED ISA 540 (REVISED) 1 Agenda Item B.4 CONFORMING AND CONSEQUENTIAL AMENDMENTS ARISING FROM DRAFT PROPOSED ISA 540 (REVISED) 1 ISA 200, Overall Objectives of the Independent Auditor and the Conduct of an Audit in Accordance

More information

Corporate Governance Framework

Corporate Governance Framework Corporate Governance Framework Seera is committed to effective corporate governance, as this is a key aspect of the Bank's strategic direction and encompasses the Bank's overall operating mission. More

More information

Dutchess County Department of Planning and Community Development Division of Mass Transit January 2007 December 2008

Dutchess County Department of Planning and Community Development Division of Mass Transit January 2007 December 2008 Dutchess County Department of Planning and Community Development Division of Mass Transit January 2007 December 2008 COMPTROLLER S SUMMARY... 2 Organization and Background... 2 Audit Scope, Objective and

More information

CLIENT ALERT: INTERNAL CONTROL OVER FINANCIAL REPORTING

CLIENT ALERT: INTERNAL CONTROL OVER FINANCIAL REPORTING CLIENT ALERT: INTERNAL CONTROL OVER FINANCIAL REPORTING All public companies either have begun or will soon begin a process, required under Section 404 of the Sarbanes-Oxley Act of 2002 ( SOX ), of reviewing

More information

GOODWILL INDUSTRIES OF COLORADO SPRINGS

GOODWILL INDUSTRIES OF COLORADO SPRINGS GOODWILL INDUSTRIES OF COLORADO SPRINGS CORPORATE COMPLIANCE PROGRAM ADOPTED : By the Board of Directors Date: October 25, 2005 Attachment 2 Memorandum 10-41 TABLE OF CONTENTS Corporate Compliance Program

More information

Internal Control Program

Internal Control Program DFA Conversations Office of the University Controller Internal Control Program November 20, 2017 Introduction Bill Sibert, University Controller Erica Jessup, Senior Financial Analyst Phil Turke, Payroll

More information

CORPORATE GOVERNANCE REPORT. 1. Implementation and Reporting on Corporate Governance

CORPORATE GOVERNANCE REPORT. 1. Implementation and Reporting on Corporate Governance CORPORATE GOVERNANCE REPORT 1. Implementation and Reporting on Corporate Governance The Board of Directors of Fjordkraft Holding ASA ( Fjordkraft or the Company ) has prepared this report that presents

More information

CORPORATE GOVERNANCE GUIDANCE NOTES FOR THE SUPERVISORY BOARD OF SUPERVISED FINANCIAL INSTITUTIONS

CORPORATE GOVERNANCE GUIDANCE NOTES FOR THE SUPERVISORY BOARD OF SUPERVISED FINANCIAL INSTITUTIONS CORPORATE GOVERNANCE OF SUPERVISED FINANCIAL INSTITUTIONS Willemstad, October 2001 CORPORATE GOVERNANCE OF SUPERVISED FINANCIAL INSTITUTIONS I NDEX Page I Introduction. 2 II The regulation and supervision

More information

Ocean Glass Public Company Limited CORPORATE GOVERNANCE GUIDELINES

Ocean Glass Public Company Limited CORPORATE GOVERNANCE GUIDELINES Ocean Glass Public Company Limited CORPORATE GOVERNANCE GUIDELINES Table of Contents CORPORATE GOVERNANCE POLICY...1 RESPONSIBILITIES OF THE BOARD...2 Duties and Responsibilities...2 Business Ethics...4

More information

THE AUDIT COMMITTEE CHARTER

THE AUDIT COMMITTEE CHARTER THE AUDIT COMMITTEE CHARTER Administrative Detail Policy Policy Owner Corporate Secretary Function Policy Custodian - Corporate Secretary Function - Enterprise Risk & Policy Management Division Version

More information

On the Revision of the Standards and Practice Standards for. Management Assessment and Audit concerning Internal Control

On the Revision of the Standards and Practice Standards for. Management Assessment and Audit concerning Internal Control (Provisional translation) On the Revision of the Standards and Practice Standards for Management Assessment and Audit concerning Internal Control Over Financial Reporting (Council Opinions) Released on

More information

CAPITAL ASSET MANAGEMENT LTD (THE COMPANY )

CAPITAL ASSET MANAGEMENT LTD (THE COMPANY ) CAPITAL ASSET MANAGEMENT LTD (THE COMPANY ) AUDIT AND RISK COMMITTEE CHARTER 1. Purpose 1.1 The Audit and Risk Committee (hereinafter referred to as the Committee )assists the Board of Directors in fulfilling

More information

Minneapolis Public Schools Special School District No. 1 Minneapolis, Minnesota. Communications Letter of the Student Activity Accounts.

Minneapolis Public Schools Special School District No. 1 Minneapolis, Minnesota. Communications Letter of the Student Activity Accounts. Minneapolis, Minnesota Communications Letter of the Student Activity Accounts June 30, 2018 Table of Contents Report on Matters Identified as a Result of the Audit of the Financial Statements 1 Material

More information

B. The Committee assists the Board in its oversight of: D. The Committee is entitled to place reasonable reliance on:

B. The Committee assists the Board in its oversight of: D. The Committee is entitled to place reasonable reliance on: I. Purpose and Objectives This Charter sets forth the authority and responsibilities of the Audit Committee of the Board of the Directors. A. The Committee assists the Board in fulfilling its oversight

More information