Purpose

Provide independent, risk-based assurance over governance, risk management and internal controls.

Steps

  1. Build an audit universe from risks, obligations, controls, systems, incidents, changes and prior findings.
  2. Rank topics by inherent risk, residual risk, control maturity and elapsed time since review. Critical areas (AML/CFT, custody, IT and cybersecurity) receive more frequent testing and assurance per the proportionality principles.
  3. Prepare an annual plan covering high-risk AML/CFT/CPF framework, custody and reconciliation controls, IT/cybersecurity, business continuity, and governance and reporting areas. For a small VASP, internal audits are conducted annually on high-risk areas and biannually for low-risk domains; external audits are limited to financial statements and regulatory assurance.
  4. Obtain Board or Audit and Risk Committee approval and record deferrals.
  5. Define scope, criteria, independence, sampling, evidence and timetable for each engagement. Internal audits may be supplemented by independent third-party reviews when in-house capacity is limited, ensuring independence and objectivity.
  6. Perform walkthroughs, inspect evidence, test samples and evaluate design and operating effectiveness separately. Use simplified checklists and walkthroughs for key operational and compliance controls as appropriate for a lean operational model.
  7. Discuss factual accuracy without allowing management to suppress independent conclusions.
  8. Issue a report with rating, cause, impact, recommendation, management response, owner and due date. Findings are consolidated into a single quarterly report to the Board, supported by corrective action tracking within existing compliance registers.
  9. Escalate material matters and transfer findings to remediation tracking.

Exceptions and Escalation

Scope limitations, missing evidence or management interference shall be reported explicitly to the Board forum.

Records

  • Audit universe and risk assessment
  • Approved annual plan
  • Engagement scope and workpapers
  • Evidence, testing and conclusions
  • Audit report and management response

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Frequency: annual plan and engagement-specific

History

  • 2026-07-26: Created from section 4.1 of the approved ICA Manual.