Purpose
Maintain competent assurance personnel, controlled records, current documentation and proportional audit coverage.
Steps
- Maintain role-based training per the manual’s section 4.6 for Board, Product/Tech, and Ops/Client-facing staff.
- Assign onboarding and annual refreshers and require at least a 90 percent assessment pass rate.
- Remediate failed assessments and monitor culture KPIs: speak-up rates, phishing test results, time-to-close issues, and training completion.
- Retain control tests, audit workpapers, management responses and follow-up verification in the controlled repository for at least five years per section 5.4. All audit and testing activities are supported by evidence-based documentation, including control testing sheets, management responses, and follow-up verification logs in a central digital repository.
- Maintain document management per section 4.7: owner is Head of Risk (with Compliance and MLRO), review cadence is annually or upon material regulatory/product/incident change, and change log captures version, date, summary, approvers, and impacted procedures.
- Apply proportionality per section 5: documented risk-based audit frequency with annual coverage of high-risk areas (AML/CFT, custody, cybersecurity) and biannual coverage of low-risk domains; external audits limited to financial statements and regulatory assurance.
- Apply the five guiding principles of proportionality (section 5.2): risk-based application, startup-appropriate design (combined functions permitted under separation-of-duties safeguards), scalability, efficiency and resource alignment, and continuous alignment.
- Document combined-role safeguards — the Head of Risk and Compliance may serve as Audit Coordinator — and use independent third-party reviews when in-house capacity is limited.
- Review proportionality annually and after growth, new services, jurisdictions, regulatory change or material incidents. The Board or Audit and Risk Committee assesses whether proportionality justifications remain appropriate, ensuring the framework remains fit-for-purpose, efficient, and compliant with CBCS standards.
Exceptions and Escalation
Proportionality shall not reduce assurance below legal or regulatory requirements or excuse inadequate independence, evidence or high-risk coverage.
Records
- Training matrix, results and remediation
- Culture indicators
- Audit and testing repository
- Policy review and version history
- Proportionality and independence assessment
Relationships
- Policy: POL-ICA-001 Internal Controls and Audit Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-ICA-007 Ensure Assurance Competence Evidence and Proportionality
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Frequency: annual and after material change
History
- 2026-07-26: Created from sections 4.6, 4.7 and 5 of the approved ICA Manual.