Operate Internal Audit per 12 CFR Part 30 Appendix D Section II.C.3. Internal Audit must (a) be a function independent of the front line units and Independent Risk Management with authority and independence to provide assurance to the Board on the design and operating effectiveness of the Risk Governance Framework + processes + controls, (b) report to a Chief Audit Executive (CAE) who reports directly to the Audit Committee of the Board + with unfettered access to the Board, (c) maintain a charter approved by the Audit Committee defining scope + authority + reporting + escalation + budget + staffing + methodology, (d) operate per professional standards (typically IIA International Professional Practices Framework + with augmentation for banking-specific guidance), (e) develop a risk-based audit plan covering all material risk categories + business lines + significant processes + with sufficient frequency to provide meaningful assurance, (f) execute audits with sufficient methodology + workpapers + evidence + supervisory review + quality assurance, (g) report findings + ratings + management responses + remediation status to the Audit Committee at appropriate frequency, (h) maintain follow-up tracking of audit issues through closure. CAE must (a) be appointed with documented qualifications, (b) be retained with appropriate compensation structure independent of front line unit results.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.