The Chartered Accountant • Journal of ICAI March 2022 • Vol. 70 • No. 9 • pp. 88–92 (Journal pp. 1128–1132)
BANK AUDIT • RISK MANAGEMENT & ASSURANCE

Risk Management in Bank Branch Audit

CA. Abhijit Sanzgiri

Author is a member of the Institute of Chartered Accountants of India (ICAI). He can be reached at apsanzgiri@hotmail.com and eboard@icai.in.

1. Fundamentals of Risk Management in Banking Operations

The key to risk management is to anticipate, in a formal, structured manner what can go wrong, how and why it can go wrong, and what could be done to ensure that we zeroise or minimize the possibilities of things going wrong. Gross or inherent risk must be kept strictly within the risk appetite, and residual risk within the established risk tolerance.

Mathematical Dimension of Risk

Risk = Function ( Probability / Likelihood of Adverse Event Occurring × Impact / Loss Caused by Actual Occurrence )

Risk needs to be managed effectively by identifying, analysing, evaluating, measuring, monitoring, treating, and communicating risk on an ongoing basis.

Risk cannot operate in a silo and must always be mapped to a corresponding control. Controls have to be proactive, automated, corrective, and collaborative. Properly engineered controls ensure that risk is treated down to an acceptably low level.

Banks function as trustees of public money and are heavily regulated by the Reserve Bank of India (RBI). They accept deposits from the public in savings accounts, current accounts, and term deposits, and lend those funds onward for commercial and industrial purposes at an interest spread. A staggering volume of daily transactions occurs in cash, ATMs, cheques, pay-orders, demand drafts, NEFT, and RTGS.

Multi-Dimensional Risks Confronting Bank Branches:

Bank branches are exposed to diverse operational and financial risk vectors:

Operational Risk Credit Risk Regulatory & Legal Risk Technology Risk Reputational Risk Money Laundering Risk Cyber Security Risk Market & Liquidity Risk Interest Rate Risk Concentration Risk Social Media Risk Fraud Risk

Branches face these risks in varying degrees depending on their business and customer profile. Hence, comprehensive risk profiling of the branch under audit is indispensable to focus on the key risks genuinely impacting the branch.

Banks institute a multitude of controls: maker-checker validation, segregation of duties, job rotation, mandatory leave policies, documented job descriptions, authorizations, ratifications, physical verifications, confirmations, inspections, balancing, reconciliations, and financial delegations.

Fundamental Control Directive: Any manual or detective control must be identified and flagged for upgradation into a preventive, system-based, automated control.

2. Mandatory Standards on Auditing (SAs) & Rigorous Documentation

In a bank branch audit, the statutory auditor certifies whether the financial statements—comprising the Balance Sheet, Profit and Loss Account, Cash Flow Statement, Accounting Policies, and Notes on Accounts—present a true and fair view free from material misstatement. Furthermore, the auditor issues mandatory certificates and the Long Form Audit Report (LFAR).

The Primary Audit Risk: Non-Adherence under Time Constraints

The foremost audit risk is that the auditor may certify financial statements as correct while having omitted critical substantive checks due to the absence of a structured audit methodology, accentuated by acute year-end time pressures. Non-compliance with the Standards on Auditing (SAs) tantamounts to professional misconduct under the Chartered Accountants Act, 1949.

Audit Documentation: The Bedrock under SA 230

While Chartered Accountants are sound in technical accounting, taxation, and law, they must significantly strengthen the robustness of their working paper documentation. SA 230, “Audit Documentation” specifically prescribes the fundamental requirements of maintaining contemporaneous audit trails.

Core Standards on Auditing Governed in Bank Audits:

SA 220: Quality Control for an Audit of Financial Statements
SA 240: The Auditor’s Responsibilities Relating to Fraud
SA 250: Consideration of Laws and Regulations in an Audit
SA 260 (Revised): Communication with Those Charged with Governance
SA 300: Planning an Audit of Financial Statements
SA 315: Identifying & Assessing Risks of Material Misstatement
SA 320: Materiality in Planning and Performing an Audit
SA 330: The Auditor’s Responses to Assessed Risks
SA 450: Evaluation of Misstatements Identified During Audit
SA 530: Audit Sampling
SA 540: Auditing Accounting Estimates & Fair Value Disclosures
SA 550: Related Parties
SA 580: Written Representations
SA 610 (Revised): Using the Work of Internal Auditors
SA 701: Communicating Key Audit Matters
SA 720 (Revised): Auditor’s Responsibilities Relating to Other Information

Working Paper Sign-Off Protocol:

Auditors must review the Standards on Auditing afresh before commencing the audit and formulate structured checklists. Documentation must be executed daily and on an ongoing basis. Crucially, the entire audit working paper file must be thoroughly reviewed and formally signed off by the signing engagement partner prior to signing the final audit report and accounts.

3. Critical Operational Focus Areas & Fraud Governance

Auditors must diligently obtain the branch organization chart to trace operational activities, Key Performance Indicators (KPIs), and Key Risk Areas (KRAs), reviewing them in tandem with the Trial Balance. Non-adherence to the bank’s year-end account closing instructions must be qualified in the audit report.

A. IRAC Compliance & Systemic NPA Identification

Non-Performing Asset (NPA) classification and provisioning represent the highest frequency of divergence in RBI regulatory inspections. NPAs must be identified directly from the core banking system (CBS) without manual intervention. Any interpretive ambiguity regarding RBI IRAC norms must be referred in writing to the Central Statutory Auditors (CSA) to establish an irrefutable audit trail.

Tracking the 45 Early Warning Signals (EWS): The auditor must verify whether the bank actively tracks the 45 Early Warning Signals of Fraud prescribed in the RBI Circular dated 7th May, 2015 on the Framework for Dealing with Loan Frauds.

Revenue Recognition Verification

Verification of system parameters, interest table master updates, and accurate application and modification of interest rates across both advances and customer deposit portfolios.

KYC & AML Diligence

Verification of Cash Transaction Reports (CTR), transaction monitoring alerts, and filing of Suspicious Transaction Reports (STR) under Financial Action Task Force (FATF) standards and Indian Banks’ Association (IBA) red flags.

Fifteen Operational Areas Requiring Targeted Audit Examination:

  1. Adherence to key institutional policies (Credit, Investment, KYC-AML).
  2. Risk classification of customer accounts into High, Medium, and Low risk bands.
  3. Accuracy of Priority Sector Lending (PSL) classifications.
  4. Timely transfer of unclaimed balances to the Depositor Education and Awareness Fund (DEAF).
  5. Verification and reversal of previous year’s Memorandum of Changes (MOC).
  6. Scrutiny of stock audit reports and independent recalculation of Drawing Power (DP).
  7. Review of system-generated Management Information System (MIS) exception and dummy reports.
  8. Reconciliation of Inter-Office, clearing, and transit accounts.
  9. Stringent monitoring of Suspense and Sundry accounts.
  10. Verification of end-use of borrowed funds and tracking diversion of funds.
  11. Classification of Bank Guarantees as financial guarantees or performance guarantees.
  12. Follow-up and resolution of pending audit observations from concurrent, internal, and revenue audits.
  13. Capitalization of fixed assets and accurate computation of depreciation.
  14. Physical cash and ATM operations (balancing, insurance cover, vault retention limits).
  15. Cross-border remittances, SWIFT messaging, and Foreign Currency account operations.

4. Long Form Audit Report (LFAR) & Mandatory Certifications

The Long Form Audit Report (LFAR) is a detailed diagnostic questionnaire requiring the branch auditor to evaluate the branch’s internal controls and operations for the entire financial year, despite the auditor being physically or virtually present only for a brief period at year-end.

Cardinal Rules for LFAR Reporting:

  • Substantiate Methodology: The auditor must clearly state in each LFAR response What was done (area covered), How it was done (audit methodology), and To what extent (sampling size and transactions examined).
  • Concurrent Audit Coordination: Discussions with concurrent auditors are mandatory, and reliance on their reports or management representations must be explicitly stated.
  • Missing Representations: If Management Representation Letters (MRLs) are not furnished, the auditor must explicitly record disclaimers against the concerned LFAR questions.
Golden Rule: The LFAR can only amplify and elaborate upon qualifications in the main Independent Auditor’s Report—it can NEVER serve as a substitute for a qualification in the Statutory Audit Report!

Issuance of Mandatory Statutory Certificates

Auditors must issue various regulatory and bank certificates (e.g. DICGC, agricultural debt waiver, Ghosh and Jilani committee recommendations, asset classification certificates). Certificates must be issued strictly in accordance with the “Guidance Note on Reports or Certificates for Special Purposes (Revised 2016)” issued by ICAI.

Auditors can only express reasonable or limited assurance, and must detail the precise documents verified, actual issues examined, verification methodology, and sampling extent, backed by cross-corroborative audit evidence.

5. Internal Financial Controls Over Financial Reporting (IFC-FR)

The Reserve Bank of India has mandated that branch auditors of Public Sector Banks (PSBs) must issue an independent report on Internal Financial Controls Over Financial Reporting (IFC-FR).

Appendix V Risk Control Matrices (ICAI Technical Guide)

Branch auditors must rigorously consult the “Technical Guide on Audit of Internal Financial Controls in Case of Public Sector Banks” issued by the Auditing and Assurance Standards Board (AASB) of ICAI, specifically referencing Appendix V:

17 Control Points on Advances

Covering appraisal, sanction, documentation, disbursement, security creation, drawing power monitoring, review, and recovery.

7 Control Points on Deposits

Covering account opening diligence, KYC compliance, interest application, dormant accounts, mandate operations, and term deposit renewals.

6. Navigating Year-End Constraints & Escalation Protocols

The central challenge confronting bank branch auditors is navigating intense time compression while managing data delays and securing complete, authentic management responses. Auditor skill lies in framing precise questions and practicing active, attentive listening.

Daily Requisition Tracker

At the commencement of audit, issue a formal, numbered audit requisition memo. Maintain a daily log tracking items submitted and pending. Countersignatures must be obtained from the Branch Head.

Tracking Deployed Man-Hours

Factually state the exact date of audit commencement and the actual audit man-hours deployed on the assignment to substantiate audit adequacy under regulatory scrutiny.

CSA & RBAD Escalation

Maintain active liaison with the Central Statutory Auditors (CSA) and the Regional Bank Audit Department (RBAD), formally communicating constraints or delays hampering audit conduct.

Uncompromising Independence:

Auditors must never succumb to time pressure and sign off without complete verification. If reports must be signed due to non-negotiable regulatory deadlines while material information remains outstanding, the auditor must fearlessly issue a qualified opinion or disclaimer of opinion, keeping the CSA and RBAD in the loop.

7. Conclusion

The statutory bank branch auditor should approach the audit with the full rigor applied to any statutory audit, appreciating the finer aspects of bank functioning and dynamic RBI regulations. Thorough planning, peer consultation, continuous team training, and the right blend of professional skepticism are paramount.

“The auditor has to stand firm ethically and do the right things right. Whenever there is a risk, one needs to derisk. Every risk can be derisked.”