Planning of Bank Branch Audit
The author is a member of the Institute. He can be reached at eboard@icai.in
It is with this purpose that planning for a Bank branch audit assumes greater importance. The auditors need to be aware of the entire gamut of Bank branch audit. SA 300 deals with the Planning an Audit of Financial Statements. Appropriate planning is also essential since in terms of SA 600, using the Work of another Auditor, the Statutory Central Auditor is entitled to rely on the work done by the branch auditor. The auditor should also be abreast with the latest version of the Guidance Note on Audit of Banks issued by the Institute (ICAI). The various stages of the Bank branch audits are explained in the following section.
A. Appointment and Related Formalities
The letter of appointment sent by banks to branch auditors typically contains the following:
- Appointment under the Banking Regulation Act, 1949, and the underlying duties and responsibilities of the auditors.
- Particulars of branches allotted to the firm and of the region/zone to which the branch reports.
- Names and communication details of statutory central auditors.
- Names and communication details of previous auditors.
- Guidelines for conducting audit of Branches, completion of audit, eligible audit fees and reimbursement of expenses, etc.
- Procedural requirements to be complied with in accepting the assignment, e.g., letter of acceptance, declaration of indebtedness, declaration of fidelity and secrecy, other undertaking by the firm/SBA, specimen signatures, etc.
- Requirements of SA 220, SA 210 w.r.t acceptance/ continuance of the client relationship, compliance with ethical requirement, etc.
- Scope of work – Besides the statutory audit under the provisions of the Banking Regulation Act, 1949, the branch auditors are also required to verify certain other areas and issue various report and certificates like the Long Form Audit Report (LFAR), Tax Audit Report, and various certificates.
In present times, the time available for completion of branch audit is extremely limited.
Co-ordination between the auditor and the branch management is essential for an effective audit, timely completion with the highest audit quality. NoC from the previous auditor should be obtained and kept on record. On receipt of NoC and accepting the appointment, the auditor should send a formal communication to the branch management/HO accepting his appointment and other declarations and undertakings so required. An engagement letter should also be sent to the appointing authority of the Bank by the Auditor. For the sake of clarity, the auditor should also specify the books, records, and other information that he would require in the course of his audit. Such a communication would enable the branch management to keep the requisite documents, information, etc., ready in a timely manner. Additionally, a visit to the branches would be helpful prior to actually commencing the audit. It will enable the auditor to get an overall idea about the business, nature and competences of the staff and understanding of the flow of information and authority.
B. Knowledge of the Banking Business, Branch Composition and Expected Deliverables
The functioning of banking industry in India is regulated by the RBI. The auditors need to understand the role of RBI and the nuances of the banking sector. The provisions regarding the financial statements of banks are governed by the Banking Regulation Act, 1949. Further, in case of banking companies, the requirements of the Companies Act, 2013, relating to the balance sheet, profit and loss account and cash flow statement of a company, in so far as they are not inconsistent with the Banking Regulation Act, 1949, also apply to the financial statements, as the case may be, of a banking company. It may be noted that this provision does not apply to Nationalised Banks, State Bank of India, its Subsidiaries and Regional Rural Banks (RRBs).
The provisions regarding audit of Nationalised Banks are governed by the Banking Regulation Act, 1949 and the RBI Guidelines. The provisions regarding audit of Banking Companies are governed by the Banking Regulation Act, 1949, RBI Guidelines and the provisions of the Companies Act, 2013.
The audit plan needs to be based on the business mix of that branch. Sample selection is also dependent on the business mix of the branch. Chartered Accountant must discuss the sample size with branch manager based on business mix and percentage of checking mentioned in the appointment letter, if any.
C. Composition of the Audit Team and Engagement Team Discussions
Since branch audit is essentially a time bound program, the audit team must be chosen appropriately. Preferably, staff having prior knowledge of bank audits should be included in the audit team. Persons having good interpretation and analytical skills, report drafting abilities and intuitive capabilities should be given priority. The team should also comprise of suitable Chartered Accountants for guidance and coordination. It is essential that basic training to the branch prior to actual commencement of the audit is necessary. This includes knowledge of RBI circulars, closing circular of the Bank, proficiency with features of the CBS. Specific emphasis should be provided to the susceptibility of the bank’s financial statements to material misstatement due to fraud, that enables the engagement team to consider an appropriate response to fraud risks, including those related to engagement risk, pervasive risks, and specific risks.
D. Basic Understanding of following Reference Material:
- RBI Circulars: RBI issues various circulars during the year to be complied by the Banks. Auditors of banks are expected to have knowledge of these circulars. Till the year 2015, RBI had a practice of issuing Master Circulars every year on 1st July. Since January 2016, RBI has started issuing Master Directions. Such Master Directions are issued regularly.
- Closing Circular of the Bank: With the appointment letter, the Closing Circular of the bank is also sent to the Auditors. The said circular covers the policies of concerned bank which are framed within the parameters set by RBI Circulars and also SEBI Guidelines etc. Dates of expected compliance from the branches are also included in the Circular. Accounting treatment of various items is also spelt out in the closing circular.
- ICAI Guidance Note: The Guidance Note on Audit of Banks is issued by the Auditing and Assurance Standards Board (AASB) of ICAI every year with the objective to provide detailed and updated guidance to the members on various aspects of bank audits. The Guidance Note is an important resource for the members carrying out audits of banks and bank branches. The Guidance Note is updated every year to incorporate the impact of developments that have taken place in the banking sector which require attention of statutory auditors, such as, master directions/circulars of RBI, other relevant circulars issued by RBI, relevant pronouncements of ICAI having bearing on bank audits, amendments/changes in applicable laws or regulations.
- Accounting and Auditing Standards: Auditors need to be aware of and ensure compliance with relevant and applicable Engagement and Quality Control Standards issued by the ICAI (SAs and SQCs).
- Allied Laws: Auditors should also have basic knowledge of Allied Laws in order to carry out effective audit. For example, Indian Contract Act, 1872, The Bombay Stamp Act, 1958, Negotiable Instruments Act 1881, etc. The impact of provisions under these laws on the documents especially in the area of Loans and Advances need to be considered appropriately, wherever required.
E. Risk Assessment and Internal Control Assessment
Prior to commencing actual verification of files and documents it is essential for the audit team to conduct risk assessment in terms of SA 315, Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity and Its Environment. Banks have certain typical risks viz: handling large volumes of cash on behalf of customers, significant involvement of outsourced services, extensive dependence on IT systems and software, operations spread over vast geographical areas, etc. SA 315 requires the auditor to put specific emphasis on the risks arising out of the fraud, changes in regulatory environment, complex transactions, related party transactions, and abnormal business transactions.
Since the past few years, cybersecurity has gained much importance. The auditor should familiarise himself with the cybersecurity framework in place at the branch. The audit procedures will need to be enhanced/altered if the auditor concludes that the cybersecurity framework is not effective.
F. Audit Planning Document
The engagement partner should summarise audit plan by preparing an audit document also known as the planning memorandum. The planning memorandum should contain the following minimum aspects:
- Results of the risk assessment procedures performed by the auditor and the extent of sample selection as well as decisions of reliance on controls.
- The expected scope and extent of the audit procedures to be performed.
- Any significant changes made during the audit to the overall audit strategy or the audit plan, and the reasons for such changes.
The planning memorandum should also be prepared in a manner that it will act as an aid in the Peer Review process of the Audit Firm.
G. Regular Supervision and Monitoring
Since branch audit is a time sensitive and time bound activity, regular interaction of the engagement partner with the audit team is imperative. The partner should devote adequate time and attention to critical audit areas like NPA verification, fraud reporting, CRAR certification, etc. Suitable checklists may be devised by the firm to track progress of the work. Requirement and work trackers may also be developed which could be updated on a real-time basis on shared network accessible to all the members of the audit team.
Snapshot of Activities to be exercised during Branch Audit
At CA’s Office, Prior to Commencement:
- Refer appointment letter and complete formalities of acceptance, NoC from previous auditor, etc.
- Identification of audit team and preparation of basic audit programme with standardised checklist. Conduct interactive meeting of the team to confirm understanding of audit programme.
- Collect and read all relevant background material as stated above.
- Accounting, Auditing and Assurance Standards, Guidance Notes and other relevant material issued by ICAI be studied.
- Based on the above, prepare a final check list covering all the areas in Bank Branch Audit and have common understanding of contents of checklist. Please remember that checklist is very important to control Bank Branch Audit in limited time and to cover all the areas under audit.
- Decide timelines of completion of each job till signing of final report.
- Draft Management Representation Letter to be obtained from branch manager.
- Before going for audit, carry with you- all stamps, letterheads, pen drive, soft copies of report formats, reference material, etc.
At the Branch, Prior to Commencement:
- If possible, visit the branch before 31st March and discuss broad Audit Programme. Send basic data requirements on e-mail to enable the branch to compile the same. Request for one person to be identified in the Branch as audit coordinator.
- Discuss all Closing Circulars, Accounting Policies and basic working of the branch with branch manager.
- Take judgement of records, work culture, procedures, processes, etc. to have an idea of working of the branch.
- Understand the software used for branch business and CBS system.
- Verify effectiveness of controls and take list of various exception reports generated by CBS software.
- Obtain list of all returns and other submissions to be made by branch to HO, ZO, RBI, etc.
- Obtain copies of all other Audit Reports, i.e., Internal, Revenue, Concurrent, Stock Audit, RBI Inspection, previous year Statutory Auditor’s Report, System Audit Report, Discretionary Financial Powers Circular, etc. Also check new advances sanctioned during the year, restructured accounts, new NPAs declared/NPAs upgraded during the year, previous year Memorandum of Changes (MOCs), list of large borrowers to understand reported irregularities, if any.
- Attend meeting with Central Statutory Auditors, if scheduled, to understand their expectations and management perspective about Bank Branch Audit.
- Prepare a list of items to be checked before 31st March and after 1st April.
- If possible prepare standardised formats of queries to avoid confusion.
- Discuss audit of Loans and Advances with Credit Officer in detail and use judgement to decide sample percentage.
Activities to be exercised During Audit
- Follow timelines and commitments as decided earlier.
- Keep track of daily targets. For pendency, verify reasons and take corrective actions. Document the extent of verification.
- Issues identified by audit staff during the audit may be discussed and cleared on daily basis. However, noting of all observations including those cleared must be preserved as records.
- Comparative analysis of Balance Sheet and Profit & Loss items with previous year’s figures and call for explanations in case of material variances.
- Plan to check and report aspects of LFAR to avoid any area to be missed out.
Activities to be exercised at the End of Audit
- Carefully review the Audit Process and confirm final Query Sheets and Reports. Re-draft the same if necessary. Involve all team members.
- Prepare Draft Audit Report and draft of other documents to be certified by you. Discuss the same with Branch. Quantify and discuss MoCs suggested by you.
- Prepare Final Report.
- Quantify all points raised in report particularly from the point of view of materiality. This will help in deciding whether a particular comment or observation is necessary to be included in the report.
- Generate UDIN, separately for the statutory audit report, certificates and the tax audit report. Refer FAQs on UDIN released by ICAI. These can be accessed at https://udin.icai.org/faqs
- Complete other formalities like stamping, signing and affixing date, etc.
- Handover final sets as required by adhering to the deadline given by bank authorities.
- Take all your working papers and final set without leaving any of your working papers at Branch. Delete working folders created on branch computer systems before leaving the branch.