NewFintech
Risk Based Internal Audit (Directive No. 196/2021)
National Bank Of Ethiopia196/2021
Summary
This directive establishes a risk-based internal audit methodology for banks operating in Ethiopia, aiming to enhance the soundness of the banking system, improve the effectiveness of internal control, and strengthen corporate governance.
Who's affected
All banks operating in Ethiopia.
Action required
Banks must adopt and understand the importance of the risk-based internal audit methodology throughout their organization.
Key points
10- Adoption of risk-based internal audit methodology is mandatory for all banks.
- Internal audit function must be independent and directly report to the board.
- An audit charter is required to define the purpose, authority, and responsibility of the internal audit function.
- Internal audit staff require specific competencies and ongoing training.
- Management is responsible for providing resources, preparing risk registers, and acting on audit findings.
- The Board of Directors is responsible for oversight, establishing committees, and approving audit plans.
- All audit procedures and working papers must be documented and retained for at least 10 years.
- Quarterly internal audit reports must be submitted to the National Bank.
- The directive details the responsibilities of the Internal Audit Function, Bank Management, and the Board of Directors.
- Annexes provide detailed charters for the Internal Audit Function and the Board Audit Committee.
Show 7 more
Requirements
16- Banks shall adopt risk-based internal audit methodology and ensure its importance is understood.
- Banks shall establish an internal audit function directly responsible to the board with sufficient independence and authority.
- Banks shall develop an internal audit charter.
- Internal audit function staff must possess required competencies and undergo ongoing training.
- Management shall provide necessary resources for internal audit, risk management, and compliance functions.
- Management shall prepare and submit risk registers.
- Management shall ensure internal audit, risk management, and compliance functions are informed of new developments and associated risks.
- Management shall provide full access to required information.
- Management shall prepare action plans for internal audit findings and recommendations.
- Board of Directors shall ensure risk registers are prepared, reviewed, and approved.
- Board of Directors shall establish and ensure effective functioning of audit, risk management, and compliance committees.
- Board of Directors shall approve and ensure periodic review of internal audit charters, policies, procedures, and audit plans.
- Board of Directors shall review the performance of internal audit, risk management, and compliance functions quarterly.
- All audit procedures shall be documented in working papers.
- Audit working papers shall be kept for at least 10 years.
- Banks shall submit internal audit reports quarterly and disclose regulatory significant matters promptly.
Show 13 more
Rights and permissions
15- Internal audit function has explicit authority to investigate any unit of a bank.
- Internal audit function has full access to and co-operation from management.
- Internal audit function has full discretion to directly communicate with any staff, director, or executive officer.
- Internal audit function has reasonable resources to discharge its functions properly.
- Internal audit function has full and unrestricted access to information.
- Internal audit function can obtain independent professional advice from external auditors and National Bank desk officers.
- Internal audit function can initiate direct communication with any member of staff.
- Internal audit function can examine any activity or unit of the bank.
- Internal audit function has full and unconditional access to any records, files, data, including management information systems and minutes of consultative and decision-making bodies.
- Board Audit Committee has explicit authority to investigate any matter within its terms of reference.
- Board Audit Committee has full access to and co-operation from management.
- Board Audit Committee has full discretion to invite any director or executive officer to attend its meetings.
- Board Audit Committee has reasonable resources to discharge its functions properly.
- Board Audit Committee has full and unrestricted access to information.
- Board Audit Committee can obtain independent professional advice.
Show 12 more
Restrictions
3- Internal audit function shall not subordinate its judgment on audit matters.
- Management shall not withhold information from auditors.
- Non-audit services provided by external auditors should not interfere with the exercise of independent judgment.
Objectives
6- Enhance the soundness of the banking system
- Improve the effectiveness of the internal control system
- Strengthen corporate governance of banks
- Ensure independent verification of accuracy, reliability, timeliness, and completeness of transactions and financial/operational information
- Ensure compliance with accounting principles, directives, policies, procedures, and relevant laws
- Ensure efficiency and effectiveness of resources used
Show 3 more
Organizations
2- National Bank of Ethiopia
- Banks operating in Ethiopia
Legal references
3- Article 59 (2) of the Banking Business Proclamation No. 592/2008
- Banking (Amended) Proclamation No.1159/2019
- National Bank directives
Original sourcehttps://justice.gov.et/en/directives/risk-based-internal-audit-directive-no-196-2021/
View source