The Chartered Accountant • Journal of ICAI March 2021 • Vol. 69 • No. 9 • pp. 86–90 (Journal pp. 1110–1114)
BANK AUDIT

Reporting on Internal Financial Controls (over Financial Reporting) in Public Sector Banks

CA. V. Balaji The author is member of the Institute. He can be reached at ars6566@gmail.com and eboard@icai.in.

“RBI has asked the Statutory Central Auditors (SCAs) of public sector banks (PSBs) to mandatorily report on the adequacy and operating effectiveness of internal financial controls with reference to financial statements with effect from the year ended March 31, 2021. The requirement is similar to the auditor’s reporting on internal financial controls over financial reporting prescribed under section 143(3)(i) of the Companies Act, 2013. The ICAI has issued a Guidance Note on Audit of Internal Financial Controls over Financial Reporting in September 2015 which is industry agnostic and can apply to such reporting under any legislation and therefore will apply even for such reporting in PSBs. Read on...”

The ICAI is in the process of bringing out a “Technical Guide on Audit of Internal Financial Controls in Case of Public Sector Banks”. The Technical Guide will provide additional guidance in relation to certain specific matters that may arise in an audit of internal financial controls with reference to financial statements of PSBs. The Technical Guide should be used in conjunction with the aforesaid Guidance Note.

Reporting on internal financial controls (IFC) for the year ended March 31, 2021 may pose challenges to the SCAs based on the state of readiness of IFC preparation by the PSBs.

The RBI vide its letter no. DOS. ARG No.6270 /08.91.001/2019-20 dated 17th March 2020 has directed the Public Sector Banks (“PSB”) to advise their Statutory Central Auditor’s (“SCAs”) to report in their independent auditor’s report, inter alia, whether the Bank has adequate internal financial controls system in place and the operating effectiveness of such controls. Subsequently, on May 19, 2020, the RBI clarified that the reporting on internal financial controls system is with reference to financial statements. Auditor’s reporting on internal financial controls in a PSB will be mandatory from the year ending March 31, 2021.

Reporting on internal controls is not new to the auditors. This was introduced in the Manufacturing and Other Companies (Auditor’s Report) Order, 1988 (MAOCARO 1988), wherein the auditors were required to report on the adequacy of internal control on certain aspects of purchases and sales in specified class of companies. The requirement was continued in CARO 2003. The Companies Act, 2013 introduced section 143(3)(i) which requires the auditors of companies (other than exempted class of companies) to report in their independent auditor’s report, whether the company has adequate internal financial controls with reference to financial statements and the operating effectiveness of such controls. The ICAI issued a Guidance Note on Audit of Internal Financial Controls over Financial Reporting (“the Guidance Note”) in September 2015 to assist auditors in meeting their reporting obligations under the Companies Act, 2013.

“The ICAI issued a Guidance Note on Audit of Internal Financial Controls over Financial Reporting (“the Guidance Note”) in September 2015 to assist auditors in meeting their reporting obligations under the Companies Act, 2013.”

The Guidance Note is industry agnostic and can be applied to an audit of internal financial controls over financial reporting irrespective of the industry or the legislation under which such reporting is required as the Guidance Note clearly lays down the principles of an audit of internal financial controls.

In a PSB, the SCAs and the Statutory Branch Auditors (“SBAs”) have been traditionally testing and relying on internal controls at the PSB when performing their audits. Such testing and reliance is essential as it is impracticable for SCAs and SBAs to test the account balances only through substantive procedures, considering the volume of transactions in PSBs. As such the requirement specified by the RBI for the SCAs to report on internal financial controls formalizes what the SCAs were traditionally doing in respect of testing the account balances with an expansion in the scope of testing internal controls from just account balances to include to cover the overall control environment at the PSB such as entity level controls and the financial closing and reporting process.

The SCAs have been asked to report on the internal financial controls with reference to financial statements of the PSB. As such, the reporting is for the PSB as a whole and therefore would cover even the branches that are audited by other auditors appointed as the SBAs, whose report is relied upon by the SCAs when forming their audit opinion on the financial statements of the PSB. Accordingly, it becomes important for the SCAs to identify the transactions at the branches that are required to be tested for internal controls. To identify the transactions to be tested the SCA will need to consider the prevalence of common controls as described below.

When auditing internal financial controls over financial reporting in a PSB, SCAs will need to consider the following important features of PSB:

  1. Prevalence of common controls and scoping of branches
  2. Presence of entity level controls to operate the common controls
  3. Prevalence of centralized controls
  4. Extensive use of information technology
  5. The importance of information used in operating the control
  6. The importance of regulatory compliance in the financial reporting process

Let us understand each of the above.

“In a PSB, typically many controls are designed centrally, and the same control is operated across the branches of a PSB. The SCA should identify those controls in a PSB that are common controls to determine the extent of testing such controls.”

a. Common controls and scoping of branches

As the name suggests, a common control is a control that is designed centrally but operated / implemented on the same basis across various locations of the entity. In a PSB, typically many controls are designed centrally, and the same control is operated across the branches of a PSB. The SCA should identify those controls in a PSB that are common controls to determine the extent of testing such controls.

In a PSB it is most likely that all controls are designed centrally and therefore the design (adequacy) of the controls is tested centrally by the SCAs. The SBAs will be required to test only the operating effectiveness of the controls relying on the testing of design of the control by the SCAs.

If the population covered by such common control is considered homogenous, then the whole population covered by such control is viewed as a single population, irrespective of the branch where a transaction in such population has occurred. The number of samples should be selected at a minimum based on the sample sizes stated in the Guidance Note. In such situations, it is likely that not all branches may be selected for testing a control as the sample size required to be tested will be lesser than the number of branches. Such scoping would not impact the coverage and consequently the opinion on internal financial controls since the SCAs have assed the control to be a common control.

If it is not possible to determine whether the population is homogenous due to variants in the nature of transactions at the branches, the SCA should determine the branches to be covered for testing internal controls based on the guidance given in the Guidance Note and inform the SBAs of the branches so determined for coverage about the need for testing controls. It may be noted that under this alternative only the branch is selected by the SCA and the SBA determines the sample size as per the Guidance Note and selects the sample. In this alternative, the overall sample size tested for controls will be significantly higher than the sample size stated in the Guidance Note but such higher sample size will be distributed across components or locations and will be tested by different SBAs.

The SCAs may select the branches for testing internal financial controls based on various factors such as:

  • Branches classified as high risk in current year.
  • Branches assigned need improvement/unsatisfactory rating in current year.
  • High volume of account balances
  • Branches where association of branch head is more than a certain period of time.
  • New branches opened during the year (with significant account balances).
  • Branches which have material decentralized operations.

b. Entity level controls to operate the common controls

It is common in PSBs to have promotions, transfers, including role changes for key employees. SCAs should understand and test the controls that are designed, implemented and operated by the PSB to familiarise such employees regarding the way in which the controls should be operated by such employees in their new roles such that the controls operate on the same basis as intended.

c. Centralized controls

Centralized controls are controls that are designed and operated centrally irrespective of the branch to which the transaction belongs. In a centralized control, the population covered by each such control is viewed as a single population and samples are selected across such single population. However, when controls in a centralized environment are designed to operate differently for certain branches or nature of transactions, the auditor tests the controls for each branch or type of transaction as a separate population to address the difference in design of the control for such branch or type of transaction.

d. Information technology

Today, Banks use sophisticated accounting and core banking software for processing transactions and the Bank’s IT environment is ever evolving. Information generated by IT systems are also used for decision making. Considering the significance of IT environment in the overall accounting and financial reporting process in a PSB, it will be an understatement to state that SCAs should test the design and operation of controls over the IT environment.

IT controls that maintain the integrity of information and security of data commonly include controls over the following:

  • Data center and network operations.
  • System change.
  • Access security.

From an auditor’s standpoint, it is important to identify applications and related IT elements that are relevant to financial reporting and then evaluate the IT controls for such applications before placing reliance on the automated controls or system generated reports. The auditor should perform an understanding of the relevant flow of transaction or processes that identifies the relevant IT environment related to those flows or processes. This also helps in understanding the effect of IT and the information technology risks on the processes.

“The auditor should inquire and obtain a register of all IT applications including the related infrastructure used in the bank, both at central/ corporate level and at a branch level. The auditor shall perform an assessment to identify the relevance of each such IT system for the purposes of internal financial controls over financial reporting.”

The auditor should inquire and obtain a register of all IT applications including the related infrastructure used in the bank, both at central/ corporate level and at a branch level. The auditor shall perform an assessment to identify the relevance of each such IT system for the purposes of internal financial controls over financial reporting. The auditor shall also understand, whether the maintenance of any application or infrastructure is outsourced to a third party.

Scoping is a continuous exercise and the auditor needs to factor any significant changes to the application landscape during the audit period until completion of the audit.

Evaluation of IT controls will also involve cyber security to the extent such cyber applications impact financial reporting.

e. Information used in the control

Many of the internal controls in a PSB will operate based on the information analyzed by the PSB’s IT system or based on data extracted from such IT system. To test the design of a control that operates based on such information, the auditor should:

  1. assess the source data to ensure the completeness of the source from which such information is obtained;
  2. the logic used in generating the report of such information to ensure the completeness and accuracy of such information report; and
  3. the parameters used in generating such information report to ensure the completeness of such information.

f. Ensuring regulatory compliance in the financial reporting process

PSBs financial reporting process is directly impacted by the directions and guidance given by the RBI. It is essential for the SCA to understand the PSBs design of controls to ensure regulatory compliances. This involves understanding and testing the PSBs process for:

  1. identifying all relevant regulatory requirements applicable during the financial year;
  2. the management understanding and disseminating information about such regulatory requirements;
  3. laying down action plans by the management to meet the regulatory requirements;
  4. monitoring and validating the actual compliance with the regulatory requirements.

“Some of the controls operate throughout the year, some only at period ends (like quarterly interest calculation) and some after the year end (like controls in the financial closing and reporting process since the activity of financial closing itself happens only after the year / period end).”

Another important aspect is the timing of auditor performing the test of controls. The reporting on internal financial controls is for the year with an emphasis on controls at the year end operating for a reasonable period of time before the year end to determine operating effectiveness of such controls as at the balance sheet date. Some of the controls operate throughout the year, some only at period ends (like quarterly interest calculation) and some after the year end (like controls in the financial closing and reporting process since the activity of financial closing itself happens only after the year / period end). Considering the above, the auditor will need to appropriately plan the timing of testing controls. It may be important for the auditor to test IT controls and automated controls before the year end since those controls may be subject to change after the year-end and may not leave any trail of the operation during the year. Manual controls may be tested after the year end since the evidence of exercise of the control will be available even after the year end.

Needless to state, the auditor’s work on testing internal financial controls should comply with the requirements of the standards on auditing.

— CA. V. Balaji