Sample Internal Audit Task: Review of Funds Transfer Processes (EFT/RTGS/TT)
Objective:
To assess the adequacy and effectiveness of internal controls over funds transfer processes and ensure compliance with regulatory requirements and bank policies.
Scope:
The audit will cover Electronic Funds Transfers (EFT), Real Time Gross Settlement (RTGS), and Telegraphic Transfers (TT) for the period under review. It includes transaction processing, authorization, reconciliation, and reporting.
Key Audit Procedures:
1. Process Understanding
◦ Obtain and review documented procedures for funds transfers.
◦ Conduct walkthroughs with operations staff to understand end-to-end processes.
2. Control Evaluation
◦ Assess segregation of duties between initiation, authorization, and posting of transactions.
◦ Verify whether all transactions are properly authorized in line with approval limits.
◦ Review system access controls to ensure only authorized personnel can initiate or approve transactions.
3. Transaction Testing
◦ Select a sample of EFT, RTGS, and TT transactions.
◦ Verify accuracy of transaction details (amounts, beneficiaries, dates).
◦ Confirm supporting documentation and approvals are in place.
◦ Check compliance with regulatory requirements and internal policies.
4. Reconciliation Review
◦ Review daily and monthly reconciliations for completeness and timeliness.
◦ Investigate any unreconciled items and assess how they are resolved.
5. Fraud Risk Assessment
◦ Identify potential vulnerabilities in the transfer process.
◦ Review exception reports for unusual or suspicious transactions.
◦ Assess controls for detecting and preventing fraudulent activities.
6. Compliance Review
◦ Ensure adherence to central bank guidelines and internal policies.
◦ Confirm proper reporting of large or suspicious transactions where applicable.
Findings (Example):
• Weak segregation of duties observed in transaction authorization.
• Delays in reconciliation leading to unresolved discrepancies.
• Inadequate review of exception reports.
Recommendations:
• Strengthen segregation of duties by enforcing role-based access controls.
• Ensure timely reconciliation and prompt resolution of outstanding items.
• Enhance monitoring of exception reports with documented reviews.
Conclusion:
The funds transfer process is generally functional but requires improvements in control enforcement, reconciliation practices, and monitoring to reduce operational and fraud risks