Overview of Internal Financial Control over
Description: Overview of Internal Financial Control over Financial Reporting and IRAC Norms by A Gopalakrishnan, B.Sc., FCA, CISA, DISA One Day CPE Seminar Friday, 19th March, 2021 9.00 AM to 04.30 PM Organized by Ernakulam Branch of SIRC of ICAI
Related Topics
Download Presentation
"Overview of Internal Financial Control over" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
slide1. Overview of Internal Financial Control over Financial Reporting and IRAC Norms
by
A Gopalakrishnan, B.Sc., FCA, CISA, DISA
One Day CPE Seminar
Friday, 19th March, 2021
9.00 AM to 04.30 PM
Organized by
Ernakulam Branch of SIRC of ICAI<br>
slide2. Framework
Introduction
Contents
Overview of IRAC Norms
Overview of Internal Financial Controls over Financial Reporting
Conclusion<br>
slide3. OVERVIEW OF IRAC NORMS<br>
slide4. Introduction - Regulatory (RBI) Outlook
Emerging views and approach of Regulator : Comments of RBI Governor after the monetary policy announcement
RBI undertaking deep dive assessment of the true state of NPAs in each of the banks and have a sense of the overall situation
RBI collecting data from various banks with regard to the size of individual stress and the kind of NPAs in all banks
RBI has deepened its supervision and is making an assessment of the true state of non-performing assets (NPA) in all banks<br>
slide5. Contd…
The Economic Survey 2021:
Called for an Asset Quality Review (AQR) for banks after the COVID-19-related forbearance is removed
Forbearance represents emergency medicine that should be discontinued at the first opportunity when the economy exhibits recovery, not a staple diet that gets continued for years.
Financial Stability Report (FSR) released by the RBI in January 2021:
Under the baseline stress scenario, gross non-performing assets (GNPAs) of all banks may rise to a 22 years high of 13.5 per cent by September 2021, from 7.5 per cent in September 2020<br>
slide6. Contd…
RBI is collecting data from various banks with regard to the size of individual stress and the kind of NPAs in all banks
RBI harping on banks to make provisions proactively and many banks have done made them anticipating higher NPAs
A positive development in the sense that there is a wide realisation in the banking sector that they need to provide adequately for the build-up of stress
RBI constantly monitoring the impact of the standstill which is there on asset classification and the COVID-19 related resolution framework
All these data flowing into RBI on a daily basis will have a clearer picture as economy move ahead<br>
slide7. Critical Issues
Announcement in the Monetary Policy of RBI released in Dec 2020 - Asset (advance) quality review by the RBI. Emphasis of RBI to delve deep into the asset portfolio of the banks –
Reminder to the profession
Focus of the audit is to ensure compliance with IRAC Norms
COVID -19 Impact – Developments
Several RBI circulars to extend benefits to the borrowers
Interim Order of the Hon. Supreme Court of India on asset classification of COVID affected companies – Effect of COVID provisions created by certain banks and the steps of banks to avoid hit in the coming quarters
Final order awaited to have more clarity on asset classification of COVID affected companies and the possible impact on the profits in the current year or subsequent periods
India’s top 10 banks hold more than Rs. 50,000 Crores of COVID related contingency provisions as on 31.12.2020<br>
slide8. Major Developments in the last year having impact on Financial Statements and Reporting
Impact of the interim order of the Hon’ble Supreme Court of India dated 03-09-2020 on the asset classification, income recognition and Capital Adequacy
RBI Circulars and guidelines granting major reliefs due to the spread of COVID-19 pandemic
Implementation of IFC over Financial Reporting<br>
slide9. Advances
Important aspects to be considered in the audit
Efficient review and verification to be specific with regard to each type of facilities:
Cash Credit
Agricultural Cash Credit
Overdraft
Demand Loan
Term Loan
Agricultural Term Loan
Bills of Exchange
Bank Guarantees
Letter of Credits<br>
slide10. Contd…
Cash Credit Account – Key Factors:
Computation of Drawing Power with reference to Current Assets and Current Liabilities, Treatment of Sundry Creditors, advance from customers, advance against purchase of raw materials, statutory liabilities
Advances to MSME sector - Proper Classification of MSME Advance and Restructuring as per revised RBI guidelines
Stock and receivable audit as per norms
Reconciliation of GST Returns with monthly stock statements
Concessions as per the recent RBI Circulars and Impact of Interim Order of the Hon’ble Supreme Court of India
Impact due to the spread of COVID-19 in decline in economic activity - Major challenges for the Bank , stress on working capital management and declining profits and earnings of the industry - Effect on the cash flows or profitability of the Bank branches<br>
slide11. Contd…
Erosion in the value of security during COVID period
Provision in respect of advance accounts declared as fraud to be created over four quarters
Recent circulars of RBI related to Advances, restructured accounts, additional finance, etc.
Compliance with the RBI guidelines dated 06-08-2020 for MSME Sector - Restructuring of Loans
COVID 19 RBI Circular -dated 27.03.2020 to mitigate the burden of debt servicing. Benefits includes:
Rescheduling of repayments of Term Loans
Rescheduling of Working capital Facilities,
Easing of Working Capital Financing
Classification as Special Mention Account (SMA) and Non-performing Asset (NPA)
COVID Emergency Credit facility (CCCEL) upto 10% of existing CC limits to specified customers @ MCLR – Monitoring of End use of such facility by branches and auditors to review the records as on 31-03-2021<br>
slide12. Contd…
Interim Order of the Hon’ble Supreme Court of India dated September 03, 2020 - “the accounts not declared as NPA till August 31, 2020 shall not be declared as NPA till further Orders” – Quantification of the impact based on computation of Provision as per IRAC norms and unrecovered Interest
Agricultural advances - Proper Classification of Agri. Advances as per RBI guidelines
Provisions - Necessary provisions for NPAs, Standard Assets, Standard Derivative Exposures, Restructured Assets
Pending applications received for restructuring under consideration
Estimated liability for Unhedged Foreign Currency<br>
slide13. NPAs – Key Considerations
Correct Asset Classification
Order of appropriation of recoveries in NPA accounts i.e., interest and principal – compliance with the bank’s policy
Income Recognition and Asset Classification (IRAC) norms – Impact on NPAs after August 31, 2020 as at 31.03.2021
Proper classification of NPAs borrower-wise, all accounts of a borrower to be treated as NPA
Correctness and completeness of the data in respect of NPAs such as date of NPA, nature of security, security value<br>
slide14. Contd…
Compliance with the Interim order of Supreme Court dated 3rd September 2020. Accounting treatment of Provisions without impacting gross and net Advances
Disclosure of Gross and Net NPA classification of Loan accounts as per IRAC norms (on Memorandum basis) without considering the Interim order of Supreme Court
Method of Reversal of Interest on NPA
Review of the entries relating to DCCO (Date of commencement of Commercial Operations)
Provisions to be made on account of Delay in implementation of resolution plan & Reporting of Restructured accounts at Branch Level.<br>
slide15. Income recognition
Income recognition in accordance with the RBI Prudential Norms
Adherence to the Significant Accounting Policies
Reversal of Interest on NPA
Manual collection of commitment and loan processing charges and other charges from customers
Interest on the accounts impacted by the interim order of the Hon’ble Supreme Court of India dated 03-09-2020<br>
slide16. Common causes for Divergences in Asset Classification identified by RBI
Failed multiple restructuring and corresponding Date of NPA
Up-gradation made even in the absence of satisfactory performance during the specific period
Accounts were not downgraded when conditions for eligibility of restructuring benefits were not met
Accounts were upgraded despite partial recovery of over dues
Latest position of drawing power as intimated by the lead Bank was not updated in the system resulting in non recognition of the down gradation.<br>
slide17. Contd…
Ever greening of accounts by sanction of additional loans
Divergence in classification of NPAs
Latest valuation of security was not obtained or erosion in the value of security not recognized
Allowing concessions in an account with financial difficulties and not treating it as restructuring
Extension of DCCO beyond stipulated period
Delayed implementation of restructuring plan<br>
slide18. List of recent RBI Circulars<br>
slide19. Gist of recent RBI Circulars<br>
slide20. Contd…<br>
slide21. OVERVIEW OF INTERNAL FINANCIAL CONTROL OVER FINANCIAL REPORTING<br>
slide22. Introduction on Reporting of Internal Financial Control
IFCoFR relates to testing controls relevant to financial closing process
RBI directed Statutory Central Auditors(SCAs) to report on Internal Financial Controls (IFC) in the Financial Statements on:
adequacy of Internal Financial Controls (IFC) system
operating effectiveness of IFC
Reporting on IFC - to consider Bank’s internal controls including control culture, structure and complexity of IT systems to determine audit strategy
Principles and guidance stated in the Guidance Note on IFC to companies by ICAI equally applicable to PSBs<br>
slide23. Applicability to SBAs
Financial statements of the Bank include financial information relating to the branches
reporting on IFCoFR applicable in respect of branches
SCAs to determine the branches required to be covered for reporting on IFCoFR and the scope
Controls operating at the branches will be common controls designed centrally at the Bank and operated at the branches
All branches of the Bank may not be covered<br>
slide24. Scope – SCAs
To determine the scope in the branches for testing and reporting
Send appropriate referral instructions to the SBAs
At branches, the design of control would not be required to be tested by SBAs
Required to test only the operating effectiveness of IFCoFR at the branches
Tests at each branch to be based on sample sizes determined by the SCAs<br>
slide25. Categories of Controls
Common Control
The SCA can determine the components or locations to be covered for testing
Inform the SBAs of the components or locations about the need for testing controls
The SBA determines the sample size and selects the sample<br>
slide26. Group audit instructions
SCAs to give detailed instructions on testing of the controls to the SBAs of the Branch
The instructions should either state:
the samples to be tested at the branch for operating effectiveness of controls (in case of common controls with homogenous population)
full testing of the operating effectiveness of the IFCoFR (where the SBA independently determines the sample to be tested in case of heterogeneous population at the branches)).
inform the SBA that the design of the controls has been tested centrally and the results of such testing.
share with the respective SBAs, the relevant portions of the Risk Controls Matrix (“RCM”) of the PSBs
request the SBA to test the operating effectiveness of the controls based on the risks and controls described in the RCM.<br>
slide27. Typical business cycles covered as part of audit of IFCoFR of a branch
Entity Level Controls<br>
slide28. Scoping (of branches) for testing IFCoFR
Branches classified as low/medium risk in previous year, but high in current year
Branches assigned needs improvement/unsatisfactory rating in current year
High Volume of CASA, term deposits, advances and cash at branches
Branches where association of branch head is more than 5 years (or appropriate term)
New branches opened during the year
Branches having material decentralized operations<br>
slide29. Broad Audit Framework<br>
slide30. General Audit Approach
Who is involved in the process (e.g., departments, roles, and people)?
Are there segregations of duties that are relevant to the process?
What is the general objective of the processes and what are the related sub processes?
When does the process occur?
Does the process involve, or impact, multiple locations?
What are the tasks within the process and in what sequence do they occur?
What are the points in the process at which a misstatement, including a misstatement due to fraud, could arise?
What control activities address the risks?
What IPE is involved?
How are application systems involved within the process?<br>
slide31. Audit of General Information Technology Control ( GITC)and Scoping of testing GITC
Increased focus on effective operation of internal controls around IT assets and services adopted for enabling greater efficiency in operations
Provide the foundation for reliance on data, reports, automated controls, and other system functionality underlying business processes
The security, integrity, and reliability of financial information relies on proper access controls, change management, and operational controls
General IT controls are policies and procedures that relate to many applications and support the effective functioning of application controls<br>
slide32. Contd…
General IT controls that maintain the integrity of information and security of data commonly include controls over the following:
Data center and network operations
Program change
Access security
The Auditor must perform an understanding of the relevant flow of transaction or processes
Generation of reports and other electronic information
Controls surrounding journal entries<br>
slide33. Information Used in Controls (“IUCs”)
IUCs are used to record:
account activity or
support judgments, such as estimates
operation of relevant controls
Following IUCs used to prepare financial statements are tested:
data
reports
Spreadsheets
Steps for testing IUC:
What the IUC is? - detailed understanding of the IUC
How the IUC is used? - process from initiation of data to generation of reports
Three elements of IUC:
source data
report logic
parameters<br>
slide34. Auditors’ Objectives on IUC control procedures
Ensure IUCs produced are accurate and complete
Evaluation strategy of IUCs:
based on different forms and methods adopted in generation of IUC
based on nature of the IUC (standard pre-coded report Vs. custom ad-hoc report)
How IUCs are created? (the degree of automation)<br>
slide35. Element of IUC - Source Data
Information from which IUC is created
Source data can be:
data maintained in IT system within an application system or database
external to the system (e.g., data maintained in an Excel spreadsheet or manually)
Source Data may or may not be subject to general IT controls.<br>
slide36. Element of IUC - Report Logic
Automated report logic, eg: computer code, algorithms, formulas for transforming, extracting, or loading the relevant source data for generating report
Includes standardized report programs, user operated tools (e.g., query tools, report writers), excel spreadsheets<br>
slide37. Element of IUC - Report Parameters
Includes:
defining report structure
specifying/filtering data used in report
connecting related reports (data or output)
Classification of Report Parameters depending on report structure:
created manually by user (user-entered parameters)
pre-set parameters (parameters configured depending on application system)<br>
slide38. Auditors’ Considerations in checking control procedures on IUCs
Key considerations in the use of IUCs:
understanding how the IUC is generated (i.e., from initiation of data to the generation of the report)
overall understanding of process flows for the relevant process
Obtain appropriate understanding of both IT aspects and non-IT aspects of generating information.
Information used in a relevant control is generally derived from:
Process flow
Transactional data captured by the bank’s IT systems<br>
slide39. Contd…
Types of reports:
System-generated –subject to the entity’s General IT Controls (GITCs)
Non-system-generated –with manual intervention
Collection of Data from other sources:
Information from processes or systems not initially considered to be relevant to internal control
Information generated from applications hosted by a service organization
Information obtained from external sources
teaming with the auditor’s IT Specialists for appropriate understanding of IT and non-IT aspects<br>
slide40. Types of Controls on IUC
Transaction-level controls:
over initiation and processing of data included in the report (including relevant automated or interface controls)
Automation of report logic, which is subject to GITCs
prevention of unauthorized access to source data
make certain that changes the applications related to source data or report logic are tested prior to being placed into production
Controls implemented by management to ensure that the report produced was as intended<br>
slide41. Timeline for testing controls
Depends on materiality and account balances scoped in
SCA to issue necessary instructions to Branch auditors for process and controls
Certain controls need to be tested before year-end to form an opinion on design and operating effectiveness of the controls
Other controls may be tested after year-end
IT and automated controls need to be tested before year-end for expressing an opinion on IFCoFR. Those controls may change after year-end without leaving a trail of the operation during the year.<br>
slide42. Evaluation of misstatements – aggregation of control deficiencies
Evaluate the control deficiencies - deficiencies exists when related GITCs may not be designed or operating effectively
Categories of Deficiencies based on severity:
Material weakness (MW):
reasonable possibility that a material misstatement of bank’s annual financial statements will not be prevented or detected on a timely basis
Significant deficiency (SD)
Less severe than material weakness,
merit attention by those responsible for oversight of the entity’s financial reporting
Deficiency
Design/ operation of a control does not allow management/employees, in the normal course of performing their assigned functions, to prevent/ detect misstatements on a timely basis
Less severe than MW or SD<br>
slide43. Financial Closing and Reporting Process (FCRP)
Controls are to be exercised at HO level and branch level
HO to issue instructions to the central team of the PSB on the requirements for preparation of the financial statements of PSB
SCA should particularly examine whether instructions are in consonance with accounting policies of PSB
Obtaining evidence on compliance with accounting policies of PSB
SBAs will be able to perform audit to enable appropriate preparation of financial information at HO<br>
slide44. Memorandum of Changes (“MoC”)
To record / propose accounting entries to be posted centrally in relation to the branch
Categories of MOC:
Entries identified as part of FCRP but could not be posted due to closure of books at branch
Entries identified at branch by branch management to rectify errors/omissions in books of account
Audit adjustments included based on audit observations accepted by branch management
SBA to categorise entries proposed in MoC into each of the above categories to enable SCA to opine on IFCoFR for the PSB at HO level<br>
slide45. Audit Report on IFCoFR
Illustrative formats of Audit Reports by SBAs may be given by ICAI in the Guidance Note.
Requirements to report on internal controls covered by LFAR is an independent requirement.
Testing on IFCoFR to be leveraged to report on control aspects covered as part of LFAR
Audit of IFCoFR to be leveraged to test information relating to other certificates issued by SBAs based on or included in audited financial statements.<br>
slide46. Automation Vs. Manual
Systems
Impact on IFCoFR
Matching the System logic with the applicable Business Logic
Details of areas automated and areas still covered manually, such as:
commitment charges,
processing charges,
legal charges,
unrecovered charges
Contingent liabilities<br>
slide47. Conclusion
Views and Approach of the Government ( Owner)
Economic Survey 2021
Fresh Asset Quality Review Of Banks after the Covid-19-related regulatory forbearances are removed
Regulatory forbearance must be removed as the economy recovers
Reserve Bank of India to do a complete clean-up exercise of bank balance sheets after granting every regulatory forbearance
2016 AQR impaired the problems in the banking sector
Problem of asymmetric information between the regulator and the banks. Gets accentuated during the forbearance regime<br>
slide48. Contd…
Banking regulator should strengthen its early warning signal systems to figure out cracks in bank balance sheets early on
The asset quality review must account for all the creative ways in which banks can ever- green their loans
Advance warning signals needs to be more equipped in the early detection of fault lines and must expand the toolkit of ex-ante remedial measures
The RBI had discontinued all forms of forbearance given to banks in the latter half of 2015 and launched an asset quality review to know the exact amount of bad loans present in the banking system
NPAs increased from 4.3% in 2014-15 to 7.5% in 2015-16 and peaked at 11.2% in 2017-18<br>
slide49. Contd…
All regulatory forbearance to be withdrawn after the intended objective is achieved
Forbearance represents emergency medicine to be discontinued at the first opportunity when the economy exhibits recovery, not a staple diet that gets continued for years
Prolonged forbearance is likely to sow the seeds of a much deeper crisis<br>
slide50. AUDITORS’ DHARMA
Help the Government (owner) and Regulator
to achieve the
Grand VISION
“to ensure a healthy Borrowing Culture in the country”
and contribute to Nation Building<br>
slide51. THANK YOU FOR THE PATIENT HEARING
-A Gopalakrishnan, B.Sc., FCA, CISA, DISA<br>
by
A Gopalakrishnan, B.Sc., FCA, CISA, DISA
One Day CPE Seminar
Friday, 19th March, 2021
9.00 AM to 04.30 PM
Organized by
Ernakulam Branch of SIRC of ICAI<br>
slide2. Framework
Introduction
Contents
Overview of IRAC Norms
Overview of Internal Financial Controls over Financial Reporting
Conclusion<br>
slide3. OVERVIEW OF IRAC NORMS<br>
slide4. Introduction - Regulatory (RBI) Outlook
Emerging views and approach of Regulator : Comments of RBI Governor after the monetary policy announcement
RBI undertaking deep dive assessment of the true state of NPAs in each of the banks and have a sense of the overall situation
RBI collecting data from various banks with regard to the size of individual stress and the kind of NPAs in all banks
RBI has deepened its supervision and is making an assessment of the true state of non-performing assets (NPA) in all banks<br>
slide5. Contd…
The Economic Survey 2021:
Called for an Asset Quality Review (AQR) for banks after the COVID-19-related forbearance is removed
Forbearance represents emergency medicine that should be discontinued at the first opportunity when the economy exhibits recovery, not a staple diet that gets continued for years.
Financial Stability Report (FSR) released by the RBI in January 2021:
Under the baseline stress scenario, gross non-performing assets (GNPAs) of all banks may rise to a 22 years high of 13.5 per cent by September 2021, from 7.5 per cent in September 2020<br>
slide6. Contd…
RBI is collecting data from various banks with regard to the size of individual stress and the kind of NPAs in all banks
RBI harping on banks to make provisions proactively and many banks have done made them anticipating higher NPAs
A positive development in the sense that there is a wide realisation in the banking sector that they need to provide adequately for the build-up of stress
RBI constantly monitoring the impact of the standstill which is there on asset classification and the COVID-19 related resolution framework
All these data flowing into RBI on a daily basis will have a clearer picture as economy move ahead<br>
slide7. Critical Issues
Announcement in the Monetary Policy of RBI released in Dec 2020 - Asset (advance) quality review by the RBI. Emphasis of RBI to delve deep into the asset portfolio of the banks –
Reminder to the profession
Focus of the audit is to ensure compliance with IRAC Norms
COVID -19 Impact – Developments
Several RBI circulars to extend benefits to the borrowers
Interim Order of the Hon. Supreme Court of India on asset classification of COVID affected companies – Effect of COVID provisions created by certain banks and the steps of banks to avoid hit in the coming quarters
Final order awaited to have more clarity on asset classification of COVID affected companies and the possible impact on the profits in the current year or subsequent periods
India’s top 10 banks hold more than Rs. 50,000 Crores of COVID related contingency provisions as on 31.12.2020<br>
slide8. Major Developments in the last year having impact on Financial Statements and Reporting
Impact of the interim order of the Hon’ble Supreme Court of India dated 03-09-2020 on the asset classification, income recognition and Capital Adequacy
RBI Circulars and guidelines granting major reliefs due to the spread of COVID-19 pandemic
Implementation of IFC over Financial Reporting<br>
slide9. Advances
Important aspects to be considered in the audit
Efficient review and verification to be specific with regard to each type of facilities:
Cash Credit
Agricultural Cash Credit
Overdraft
Demand Loan
Term Loan
Agricultural Term Loan
Bills of Exchange
Bank Guarantees
Letter of Credits<br>
slide10. Contd…
Cash Credit Account – Key Factors:
Computation of Drawing Power with reference to Current Assets and Current Liabilities, Treatment of Sundry Creditors, advance from customers, advance against purchase of raw materials, statutory liabilities
Advances to MSME sector - Proper Classification of MSME Advance and Restructuring as per revised RBI guidelines
Stock and receivable audit as per norms
Reconciliation of GST Returns with monthly stock statements
Concessions as per the recent RBI Circulars and Impact of Interim Order of the Hon’ble Supreme Court of India
Impact due to the spread of COVID-19 in decline in economic activity - Major challenges for the Bank , stress on working capital management and declining profits and earnings of the industry - Effect on the cash flows or profitability of the Bank branches<br>
slide11. Contd…
Erosion in the value of security during COVID period
Provision in respect of advance accounts declared as fraud to be created over four quarters
Recent circulars of RBI related to Advances, restructured accounts, additional finance, etc.
Compliance with the RBI guidelines dated 06-08-2020 for MSME Sector - Restructuring of Loans
COVID 19 RBI Circular -dated 27.03.2020 to mitigate the burden of debt servicing. Benefits includes:
Rescheduling of repayments of Term Loans
Rescheduling of Working capital Facilities,
Easing of Working Capital Financing
Classification as Special Mention Account (SMA) and Non-performing Asset (NPA)
COVID Emergency Credit facility (CCCEL) upto 10% of existing CC limits to specified customers @ MCLR – Monitoring of End use of such facility by branches and auditors to review the records as on 31-03-2021<br>
slide12. Contd…
Interim Order of the Hon’ble Supreme Court of India dated September 03, 2020 - “the accounts not declared as NPA till August 31, 2020 shall not be declared as NPA till further Orders” – Quantification of the impact based on computation of Provision as per IRAC norms and unrecovered Interest
Agricultural advances - Proper Classification of Agri. Advances as per RBI guidelines
Provisions - Necessary provisions for NPAs, Standard Assets, Standard Derivative Exposures, Restructured Assets
Pending applications received for restructuring under consideration
Estimated liability for Unhedged Foreign Currency<br>
slide13. NPAs – Key Considerations
Correct Asset Classification
Order of appropriation of recoveries in NPA accounts i.e., interest and principal – compliance with the bank’s policy
Income Recognition and Asset Classification (IRAC) norms – Impact on NPAs after August 31, 2020 as at 31.03.2021
Proper classification of NPAs borrower-wise, all accounts of a borrower to be treated as NPA
Correctness and completeness of the data in respect of NPAs such as date of NPA, nature of security, security value<br>
slide14. Contd…
Compliance with the Interim order of Supreme Court dated 3rd September 2020. Accounting treatment of Provisions without impacting gross and net Advances
Disclosure of Gross and Net NPA classification of Loan accounts as per IRAC norms (on Memorandum basis) without considering the Interim order of Supreme Court
Method of Reversal of Interest on NPA
Review of the entries relating to DCCO (Date of commencement of Commercial Operations)
Provisions to be made on account of Delay in implementation of resolution plan & Reporting of Restructured accounts at Branch Level.<br>
slide15. Income recognition
Income recognition in accordance with the RBI Prudential Norms
Adherence to the Significant Accounting Policies
Reversal of Interest on NPA
Manual collection of commitment and loan processing charges and other charges from customers
Interest on the accounts impacted by the interim order of the Hon’ble Supreme Court of India dated 03-09-2020<br>
slide16. Common causes for Divergences in Asset Classification identified by RBI
Failed multiple restructuring and corresponding Date of NPA
Up-gradation made even in the absence of satisfactory performance during the specific period
Accounts were not downgraded when conditions for eligibility of restructuring benefits were not met
Accounts were upgraded despite partial recovery of over dues
Latest position of drawing power as intimated by the lead Bank was not updated in the system resulting in non recognition of the down gradation.<br>
slide17. Contd…
Ever greening of accounts by sanction of additional loans
Divergence in classification of NPAs
Latest valuation of security was not obtained or erosion in the value of security not recognized
Allowing concessions in an account with financial difficulties and not treating it as restructuring
Extension of DCCO beyond stipulated period
Delayed implementation of restructuring plan<br>
slide18. List of recent RBI Circulars<br>
slide19. Gist of recent RBI Circulars<br>
slide20. Contd…<br>
slide21. OVERVIEW OF INTERNAL FINANCIAL CONTROL OVER FINANCIAL REPORTING<br>
slide22. Introduction on Reporting of Internal Financial Control
IFCoFR relates to testing controls relevant to financial closing process
RBI directed Statutory Central Auditors(SCAs) to report on Internal Financial Controls (IFC) in the Financial Statements on:
adequacy of Internal Financial Controls (IFC) system
operating effectiveness of IFC
Reporting on IFC - to consider Bank’s internal controls including control culture, structure and complexity of IT systems to determine audit strategy
Principles and guidance stated in the Guidance Note on IFC to companies by ICAI equally applicable to PSBs<br>
slide23. Applicability to SBAs
Financial statements of the Bank include financial information relating to the branches
reporting on IFCoFR applicable in respect of branches
SCAs to determine the branches required to be covered for reporting on IFCoFR and the scope
Controls operating at the branches will be common controls designed centrally at the Bank and operated at the branches
All branches of the Bank may not be covered<br>
slide24. Scope – SCAs
To determine the scope in the branches for testing and reporting
Send appropriate referral instructions to the SBAs
At branches, the design of control would not be required to be tested by SBAs
Required to test only the operating effectiveness of IFCoFR at the branches
Tests at each branch to be based on sample sizes determined by the SCAs<br>
slide25. Categories of Controls
Common Control
The SCA can determine the components or locations to be covered for testing
Inform the SBAs of the components or locations about the need for testing controls
The SBA determines the sample size and selects the sample<br>
slide26. Group audit instructions
SCAs to give detailed instructions on testing of the controls to the SBAs of the Branch
The instructions should either state:
the samples to be tested at the branch for operating effectiveness of controls (in case of common controls with homogenous population)
full testing of the operating effectiveness of the IFCoFR (where the SBA independently determines the sample to be tested in case of heterogeneous population at the branches)).
inform the SBA that the design of the controls has been tested centrally and the results of such testing.
share with the respective SBAs, the relevant portions of the Risk Controls Matrix (“RCM”) of the PSBs
request the SBA to test the operating effectiveness of the controls based on the risks and controls described in the RCM.<br>
slide27. Typical business cycles covered as part of audit of IFCoFR of a branch
Entity Level Controls<br>
slide28. Scoping (of branches) for testing IFCoFR
Branches classified as low/medium risk in previous year, but high in current year
Branches assigned needs improvement/unsatisfactory rating in current year
High Volume of CASA, term deposits, advances and cash at branches
Branches where association of branch head is more than 5 years (or appropriate term)
New branches opened during the year
Branches having material decentralized operations<br>
slide29. Broad Audit Framework<br>
slide30. General Audit Approach
Who is involved in the process (e.g., departments, roles, and people)?
Are there segregations of duties that are relevant to the process?
What is the general objective of the processes and what are the related sub processes?
When does the process occur?
Does the process involve, or impact, multiple locations?
What are the tasks within the process and in what sequence do they occur?
What are the points in the process at which a misstatement, including a misstatement due to fraud, could arise?
What control activities address the risks?
What IPE is involved?
How are application systems involved within the process?<br>
slide31. Audit of General Information Technology Control ( GITC)and Scoping of testing GITC
Increased focus on effective operation of internal controls around IT assets and services adopted for enabling greater efficiency in operations
Provide the foundation for reliance on data, reports, automated controls, and other system functionality underlying business processes
The security, integrity, and reliability of financial information relies on proper access controls, change management, and operational controls
General IT controls are policies and procedures that relate to many applications and support the effective functioning of application controls<br>
slide32. Contd…
General IT controls that maintain the integrity of information and security of data commonly include controls over the following:
Data center and network operations
Program change
Access security
The Auditor must perform an understanding of the relevant flow of transaction or processes
Generation of reports and other electronic information
Controls surrounding journal entries<br>
slide33. Information Used in Controls (“IUCs”)
IUCs are used to record:
account activity or
support judgments, such as estimates
operation of relevant controls
Following IUCs used to prepare financial statements are tested:
data
reports
Spreadsheets
Steps for testing IUC:
What the IUC is? - detailed understanding of the IUC
How the IUC is used? - process from initiation of data to generation of reports
Three elements of IUC:
source data
report logic
parameters<br>
slide34. Auditors’ Objectives on IUC control procedures
Ensure IUCs produced are accurate and complete
Evaluation strategy of IUCs:
based on different forms and methods adopted in generation of IUC
based on nature of the IUC (standard pre-coded report Vs. custom ad-hoc report)
How IUCs are created? (the degree of automation)<br>
slide35. Element of IUC - Source Data
Information from which IUC is created
Source data can be:
data maintained in IT system within an application system or database
external to the system (e.g., data maintained in an Excel spreadsheet or manually)
Source Data may or may not be subject to general IT controls.<br>
slide36. Element of IUC - Report Logic
Automated report logic, eg: computer code, algorithms, formulas for transforming, extracting, or loading the relevant source data for generating report
Includes standardized report programs, user operated tools (e.g., query tools, report writers), excel spreadsheets<br>
slide37. Element of IUC - Report Parameters
Includes:
defining report structure
specifying/filtering data used in report
connecting related reports (data or output)
Classification of Report Parameters depending on report structure:
created manually by user (user-entered parameters)
pre-set parameters (parameters configured depending on application system)<br>
slide38. Auditors’ Considerations in checking control procedures on IUCs
Key considerations in the use of IUCs:
understanding how the IUC is generated (i.e., from initiation of data to the generation of the report)
overall understanding of process flows for the relevant process
Obtain appropriate understanding of both IT aspects and non-IT aspects of generating information.
Information used in a relevant control is generally derived from:
Process flow
Transactional data captured by the bank’s IT systems<br>
slide39. Contd…
Types of reports:
System-generated –subject to the entity’s General IT Controls (GITCs)
Non-system-generated –with manual intervention
Collection of Data from other sources:
Information from processes or systems not initially considered to be relevant to internal control
Information generated from applications hosted by a service organization
Information obtained from external sources
teaming with the auditor’s IT Specialists for appropriate understanding of IT and non-IT aspects<br>
slide40. Types of Controls on IUC
Transaction-level controls:
over initiation and processing of data included in the report (including relevant automated or interface controls)
Automation of report logic, which is subject to GITCs
prevention of unauthorized access to source data
make certain that changes the applications related to source data or report logic are tested prior to being placed into production
Controls implemented by management to ensure that the report produced was as intended<br>
slide41. Timeline for testing controls
Depends on materiality and account balances scoped in
SCA to issue necessary instructions to Branch auditors for process and controls
Certain controls need to be tested before year-end to form an opinion on design and operating effectiveness of the controls
Other controls may be tested after year-end
IT and automated controls need to be tested before year-end for expressing an opinion on IFCoFR. Those controls may change after year-end without leaving a trail of the operation during the year.<br>
slide42. Evaluation of misstatements – aggregation of control deficiencies
Evaluate the control deficiencies - deficiencies exists when related GITCs may not be designed or operating effectively
Categories of Deficiencies based on severity:
Material weakness (MW):
reasonable possibility that a material misstatement of bank’s annual financial statements will not be prevented or detected on a timely basis
Significant deficiency (SD)
Less severe than material weakness,
merit attention by those responsible for oversight of the entity’s financial reporting
Deficiency
Design/ operation of a control does not allow management/employees, in the normal course of performing their assigned functions, to prevent/ detect misstatements on a timely basis
Less severe than MW or SD<br>
slide43. Financial Closing and Reporting Process (FCRP)
Controls are to be exercised at HO level and branch level
HO to issue instructions to the central team of the PSB on the requirements for preparation of the financial statements of PSB
SCA should particularly examine whether instructions are in consonance with accounting policies of PSB
Obtaining evidence on compliance with accounting policies of PSB
SBAs will be able to perform audit to enable appropriate preparation of financial information at HO<br>
slide44. Memorandum of Changes (“MoC”)
To record / propose accounting entries to be posted centrally in relation to the branch
Categories of MOC:
Entries identified as part of FCRP but could not be posted due to closure of books at branch
Entries identified at branch by branch management to rectify errors/omissions in books of account
Audit adjustments included based on audit observations accepted by branch management
SBA to categorise entries proposed in MoC into each of the above categories to enable SCA to opine on IFCoFR for the PSB at HO level<br>
slide45. Audit Report on IFCoFR
Illustrative formats of Audit Reports by SBAs may be given by ICAI in the Guidance Note.
Requirements to report on internal controls covered by LFAR is an independent requirement.
Testing on IFCoFR to be leveraged to report on control aspects covered as part of LFAR
Audit of IFCoFR to be leveraged to test information relating to other certificates issued by SBAs based on or included in audited financial statements.<br>
slide46. Automation Vs. Manual
Systems
Impact on IFCoFR
Matching the System logic with the applicable Business Logic
Details of areas automated and areas still covered manually, such as:
commitment charges,
processing charges,
legal charges,
unrecovered charges
Contingent liabilities<br>
slide47. Conclusion
Views and Approach of the Government ( Owner)
Economic Survey 2021
Fresh Asset Quality Review Of Banks after the Covid-19-related regulatory forbearances are removed
Regulatory forbearance must be removed as the economy recovers
Reserve Bank of India to do a complete clean-up exercise of bank balance sheets after granting every regulatory forbearance
2016 AQR impaired the problems in the banking sector
Problem of asymmetric information between the regulator and the banks. Gets accentuated during the forbearance regime<br>
slide48. Contd…
Banking regulator should strengthen its early warning signal systems to figure out cracks in bank balance sheets early on
The asset quality review must account for all the creative ways in which banks can ever- green their loans
Advance warning signals needs to be more equipped in the early detection of fault lines and must expand the toolkit of ex-ante remedial measures
The RBI had discontinued all forms of forbearance given to banks in the latter half of 2015 and launched an asset quality review to know the exact amount of bad loans present in the banking system
NPAs increased from 4.3% in 2014-15 to 7.5% in 2015-16 and peaked at 11.2% in 2017-18<br>
slide49. Contd…
All regulatory forbearance to be withdrawn after the intended objective is achieved
Forbearance represents emergency medicine to be discontinued at the first opportunity when the economy exhibits recovery, not a staple diet that gets continued for years
Prolonged forbearance is likely to sow the seeds of a much deeper crisis<br>
slide50. AUDITORS’ DHARMA
Help the Government (owner) and Regulator
to achieve the
Grand VISION
“to ensure a healthy Borrowing Culture in the country”
and contribute to Nation Building<br>
slide51. THANK YOU FOR THE PATIENT HEARING
-A Gopalakrishnan, B.Sc., FCA, CISA, DISA<br>