Вы находитесь на странице: 1из 4

 

Bhutan National Bank Limited 
 
Program on Risk Based Internal Audit in Banks 
Proposed Duration : 2 weeks 
Delivery Mode: Classroom training – interactive learning 
 
Introduction and objectives:
 
Risk Based Internal Audit and Auditing Risk Management in Banks
Risk management and risk control techniques have assumed paramount importance in banking
business. The bank internal audit is going to assume more significant role and responsibilities in that
it is expected to serve as an independent evaluation authority of integrity and efficacy of a banks’ risk
management and risk control systems and procedures.

Under Risk Based Supervision (RBS) approach, the supervisor would leverage upon the risk based
internal audit reports of banks. The auditor of banks would also have to re-orient the auditing scope
and methodology from transactions testing to assessment of risk management and risk control
systems at all levels of the organization. Supervisors in countries (including USA and UK) have
introduced RBS approach.

The auditing profession is expected to play a major role under Risk Based Supervision approach.
Today’s challenges to auditors in banks is to understand the relevant risks, product and financial
implications of entering into each transaction as well as the basic objectives of traders and users, in
order to determine and establish effective controls.

In this context, the acquisition of knowledge and relevant skills of New Basel II Capital Accord, RBS
Approach, risk management in banks and risk based internal audit skills by the bank internal
inspection and audit staff and by professional auditors, chartered accountants has assumed enormous
significance.

Various clauses of the new Basel II Capital Accord place substantial responsibility on
internal/external auditors in respect of review and audit of risk management frameworks of banks.
Before you can effectively audit the operational risk management processes and measurement
systems, you need to understand the fundamental issues.

Program also includes case studies. Participants are also expected to make presentations. 
 
 
Benefits of attending
• Understand Risk Management in simple and practical way
• Understand the crucial role of Auditors in controlling and mitigating various risks faced by Banks.
• Understand the issues in implementation of risk based internal audit in banks and how to overcome the
issues
• Develop the skills to effectively audit Risk Management and Anti-Money Laundering Frameworks
• Learn how to focus on important issues rather than get bogged with trivia 

MVL Consulting Private Limited/Bhutan National Bank Ltd./RBIA/2009 
 
 
 
Proposed Program Contents:
 
• Introduction
• What is internal audit ?
• Scope and objectives of internal audit
• Risk based internal audit
o What is risk based internal audit (RBIA) ?
o Comparison of RBIA with traditional internal audit
o Need for RBIA
o Advantages of RBIA
• Changing role of internal auditor
• Types of audits which can be conducted by internal audit
o Financial audit
o Process audit
ƒ Exercise: Documentation of processes
o Compliance audit
• Information systems audit
• International standards for internal audit
o Attribute standards
o Performance standards
• Risk based supervision (RBS)
• What is risk based supervision approach ?
• Concept and methodology
• Bank risk profiling template
• Use of audit as supervisory resource
• Relationship between supervisors and internal auditors - BCBS expectations
• Understanding risk management in banks
• What is risk ?
• Understanding risk
o Credit risk
o Market risk
o Operational risk
• Understanding risk mitigation mechanisms
o External measures
ƒ Derivatives
• Credit risk derivatives
• Market risk derivatives
• Other derivatives
ƒ Securitisation
• Traditional securitization
• Synthetic securitization
o Pass through/CDO/CMO/CBO/CLO

MVL Consulting Private Limited/Bhutan National Bank Ltd./RBIA/2009 
 
 
o Internal measures
ƒ Limits
ƒ Internal controls
• Importance of internal controls in RBIA
• COSO framework on internal controls
• Basel guidance on internal controls
• Testing effectiveness of internal controls
• Understanding business risks and control risks
• Integrated/enterprise-wide approach to risk management (ERM)
• Exercise: Classification of banking risks
• Case study: fall of Barings Bank
• Introduction to Basel II Capital Accord
• Structure and objectives of the new capital accord
• Comparison of old and new capital accords
• Introduction to Pillars I, II and III
• Concept of regulatory capital and economic capital
• Disclosures under new accord
• Basel II expectations from auditors
• Essentials of risk based internal audit
• Design scope and methodology
• Audit charter/RBIA policy/Sampling policy
• Designing audit framework
• Planning for audit
• Risk profiling of branches
• Formats of audit reports
• Risk severity and risk frequency
• Business risk/control risk matrix
• Direction of risk
• Process of risk based internal audit
• Auditing risk management in banks
o Auditing credit risk frameworks, PD, LGD, EAD
o Auditing market risk framework
o Auditing operational risk framework
• Auditing integrated treasury operations
o Domestic Treasury
o Forex treasury
• Auditing advances portfolio
• Auditing deposit portfolio
• Auditing anti-money laundering/KYC frameworks
o Financial Action Task Force guidance
• Auditing Payment and Settlement Systems
• Auditing derivative transactions
• Preparation of audit reports

MVL Consulting Private Limited/Bhutan National Bank Ltd./RBIA/2009 
 
 
• Exercise : Developing audit report formats
• Exercise : Developing audit report formats
• Exercise: Conducting RBIA at treasury
• Exercise: Conducting RBIA at branches
• Exercise: Auditing AML framework
• Information systems audit
• Importance of information systems audit in banks
• Implications of RBIA and Basel II on information systems audit
• Methods of information systems audits
• Understanding COBiT framework
• Understanding ISO 27001
• Computer and cyber-crimes related to banks
• Auditing ATM operations
• Conducting information systems audit at branches
• Conducting network security audits
o Hands on training on some network audit tools
• Exercise : Using CAATs for internal audit
o Hands on training using CAATS for
ƒ Financial audit
ƒ Information systems audit

MVL Consulting Private Limited


#17, Laxman Villa Condominium, Near Jog Hospital,
Paud Road, Pune 411 038, India.
Telefax: +91-20-25466154, +91-20-25422874, +91-20-65007531, +91-20-65007645
Email: info@mvlcco.com Website: www.mvlco.com

MVL Consulting Private Limited/Bhutan National Bank Ltd./RBIA/2009 

Вам также может понравиться