Â
This lesson establishes the foundational principles of internal control in banking, exploring its evolution, purpose, and the global frameworks that govern its design and implementation.
1.1 The Purpose and Evolution of Internal Controls
A system of effective internal controls is a critical component of bank management and a foundation for the safe and sound operation of banking organisations. Over time, the importance of the Internal Control System (ICS) has evolved from a simple risk management tool into an essential strategic pillar, representing a mandatory requirement under modern legislation. It is not solely a procedure or policy performed at a certain point; rather, it is a continual process effected by the board of directors, senior management, and all levels of personnel. The ICS contributes not only to certifying processes, ensuring regulatory compliance, and mitigating risks, but also to preserving solvency and reputation, supporting responsible and long-term oriented management.
1.2 The COSO Framework: The Global Standard
The foundational framework for internal control globally is the COSO Internal Control-Integrated Framework. The Committee of Sponsoring Organizations (COSO) formalised this model in 1992, structuring it around five interconnected components:
-
Control Environment:Â The “tone at the top,” including the organisation’s culture, integrity, ethical values, and the competence of its people.
-
Risk Assessment:Â The process of identifying and analysing risks to achieving the organisation’s objectives.
-
Control Activities:Â Policies and procedures that ensure management directives are carried out (e.g., approvals, authorisations, verifications, and segregation of duties).
-
Information and Communication:Â Systems that identify, capture, and communicate relevant information in a form and timeframe that enables people to carry out their responsibilities.
-
Monitoring Activities:Â Ongoing evaluations, separate evaluations, or some combination of the two used to ascertain whether the components of internal control are present and functioning.
1.3 The Basel Committee’s Framework for Banking
The Basel Committee on Banking Supervision (BCBS) adapted the COSO principles for the banking sector, issuing its own Framework for Internal Control Systems in Banking Organisations. This framework sets out key principles covering management oversight, risk recognition and assessment, control activities and segregation of duties, information and communication, and monitoring activities and correcting deficiencies. These principles were developed drawing on lessons learned from problem bank situations and are intended to be of general application for supervisors worldwide.
1.4 Regulatory Integration
In jurisdictions like the EU, the COSO and BCBS frameworks have been integrated into national regulations. The Bank of Italy, for example, has implemented these principles through Circular No. 285/2013, which defines responsibilities and principles for the effectiveness of the ICS in banks. Similarly, the COSO framework is a core reference point for developing internal control systems per regulations like BSP Circular 871 in the Philippines.