Purpose
Provide independent, risk-based assurance over governance, risk management and internal controls.
Steps
- Build an audit universe from risks, obligations, controls, systems, incidents, changes and prior findings.
- Rank topics by inherent risk, residual risk, control maturity and elapsed time since review. Critical areas (AML/CFT, custody, IT and cybersecurity) receive more frequent testing and assurance per the proportionality principles.
- Prepare an annual plan covering high-risk AML/CFT/CPF framework, custody and reconciliation controls, IT/cybersecurity, business continuity, and governance and reporting areas. For a small VASP, internal audits are conducted annually on high-risk areas and biannually for low-risk domains; external audits are limited to financial statements and regulatory assurance.
- Obtain Board or Audit and Risk Committee approval and record deferrals.
- Define scope, criteria, independence, sampling, evidence and timetable for each engagement. Internal audits may be supplemented by independent third-party reviews when in-house capacity is limited, ensuring independence and objectivity.
- Perform walkthroughs, inspect evidence, test samples and evaluate design and operating effectiveness separately. Use simplified checklists and walkthroughs for key operational and compliance controls as appropriate for a lean operational model.
- Discuss factual accuracy without allowing management to suppress independent conclusions.
- Issue a report with rating, cause, impact, recommendation, management response, owner and due date. Findings are consolidated into a single quarterly report to the Board, supported by corrective action tracking within existing compliance registers.
- Escalate material matters and transfer findings to remediation tracking.
Exceptions and Escalation
Scope limitations, missing evidence or management interference shall be reported explicitly to the Board forum.
Records
- Audit universe and risk assessment
- Approved annual plan
- Engagement scope and workpapers
- Evidence, testing and conclusions
- Audit report and management response
Relationships
- Policy: POL-ICA-001 Internal Controls and Audit Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-ICA-003 Ensure Risk Based Internal Audits Are Independent and Complete
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Frequency: annual plan and engagement-specific
History
- 2026-07-26: Created from section 4.1 of the approved ICA Manual.