Basel Core Principles for Effective Banking Supervision (2024)
Principles 26 to 29: internal control and audit, financial reporting, disclosure and abuse of financial services – Basel Core Principles for Effective Banking Supervision (2024)

Basel Core Principles for Effective Banking Supervision (2024) P26: Principle 26: internal control and audit

The bank has an internal control framework, the responsibility of the board and senior management, that keeps an effectively controlled and tested operating environment for its risk profile with a forward-looking view (including climate-related and emerging risks), covering organisational structure (defined duties, clear delegation such as loan approval limits, decision processes, separation of origination, payments, reconciliation, risk management, accounting, audit and compliance), accounting policies (reconciliations, control lists, management information), checks and balances (segregation of duties, cross-checking, dual control, double signatures) and safeguarding of assets (physical and computer access control), with measures to prevent and detect fraud, embezzlement, unauthorised trading and computer intrusion. Back office and control functions have skills, resources, expertise and authority (and board access where appropriate) to check the business units. A permanent, independent, adequately staffed compliance function helps senior management manage compliance risk, under board oversight. A permanent, independent and effective internal audit function (in-house, outsourced or co-sourced) assesses whether policies, processes and controls, including risk management, compliance and governance, remain effective and are complied with; it is resourced with trained staff, accountable to the board or audit committee with standing that makes management act on its findings, informed of material risk changes, free to contact any staff and access all records of the bank and affiliates, uses a risk-identifying methodology and a regularly reviewed risk-based audit plan, and can assess outsourced functions. Control staff remuneration is set independently of the lines they oversee.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 3 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • P10 Principle 10: Selects and develops control activities
  • P16 Principle 16: Conducts ongoing and/or separate evaluations
  • P3 Principle 3: Establishes structure, authority and responsibility

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Principles 26 to 29: internal control and audit, financial reporting, disclosure and abuse of financial services – Basel Core Principles for Effective Banking Supervision (2024)

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.