This lesson delves into the operational heart of a bank’s compliance and risk management function: the internal control system. It details the international standards, core principles, and structural models that guide how banks manage risk.
7.1 The Framework for Internal Controls
A robust internal control system is a key requirement of banking regulation globally. The primary international standard for designing and implementing internal controls is the COSO Internal Control-Integrated Framework. Its principles are adapted for the banking sector by the Basel Committee on Banking Supervision (BCBS) . This system is designed to provide reasonable assurance regarding the achievement of objectives in three categories: operations, reporting, and compliance .
7.2 Key Principles of an Effective Internal Control System
The BCBS Framework for Internal Control Systems in Banking Organizations outlines five key principles that must be embedded in a bank’s culture and operations :
-
Management Oversight and the Control Culture: The “tone at the top” is paramount. The board of directors and senior management must promote high ethical standards and a culture where internal controls are valued and understood by everyone .
-
Risk Recognition and Assessment: An effective system requires that all material risks faced by the bank (credit, market, operational, liquidity, legal, reputational, etc.) are continuously and comprehensively identified and assessed .
-
Control Activities and Segregation of Duties: Control activities, such as top-level reviews, activity controls, physical controls, and approvals, must be an integral part of the daily business. Crucially, duties must be segregated to ensure no single individual has conflicting responsibilities that could conceal errors or fraud .
-
Information and Communication: Relevant, reliable, and timely information must be identified, captured, and communicated to the right people, enabling them to carry out their responsibilities effectively .
-
Monitoring Activities and Correcting Deficiencies: The entire system of internal controls must be continuously monitored. Deficiencies must be promptly reported and corrected .
7.3 The Three Lines of Defense Model
This is the industry standard model for organizing risk management and internal controls within a bank .
-
First Line of Defense (Operational Management): This is the front-line. Operational managers own and manage risk on a day-to-day basis. They are responsible for implementing effective internal controls and following procedures. Examples include the loan origination team .
-
Second Line of Defense (Risk and Compliance Functions): This line oversees and supports the first line. It includes specialist risk management and compliance functions that set standards, monitor risks (e.g., through Risk and Control Self-Assessment – RCSA), and provide guidance .
-
Third Line of Defense (Internal Audit): This is the independent assurance function. Internal Audit provides objective and independent assurance to the board and senior management on the effectiveness of governance, risk management, and internal control processes .
Â