Master Circular on Inspection & Audit Systems in Primary (Urban)Co-op. Banks - RBI - Reserve Bank of India
Master Circular on Inspection & Audit Systems in Primary (Urban)Co-op. Banks
RBI/2010-11/96 July 1, 2010 Chief Executive Officers of Dear Sir Master Circular on Please refer to our Master Circular UBD.BPD.(PCB).MC.No.9 /12.05.001/2009-10 dated July 1, 2009 on the captioned subject ( available at RBI website www.rbi.org.in).The enclosed Master Circular consolidates and updates all the instructions / guidelines on the subject up to June 30, 2010. Yours faithfully Master Circular on Contents
Master Circular on 1.1 It has been observed that quite often the internal inspection machinery in banks has failed to highlight and pinpoint the existence of gross and serious irregularities such as improper credit appraisal, disbursement without observing the terms of sanction, failure to exercise proper post-disbursement supervision, even suppression of information relating to unauthorised excess drawals allowed, kite flying in bills and cheques, etc. 1.2 The internal inspection reports rarely make any adverse comments on the failure of officials of Controlling/Head Offices. It is observed that very few cases of frauds and malpractices come to light through internal inspection/audit reports indicating that there is room for improvement in the quality of inspection. The failure of the internal inspection machinery is mainly attributable to the incompetence of the internal inspection personnel and the casual manner in which the work is carried out. The follow up of the inspection is not carried out seriously. Personnel who cannot otherwise be deployed in other sensitive/critical areas more often staff the inspection/audit department. 2. GHOSH COMMITTEE RECOMMENDATIONS ON INTERNAL INSPECTION AND AUDIT The Reserve Bank of India had constituted a High Level Committee, under the chairmanship of Shri A. Ghosh, the then Deputy Governor of RBI, to enquire into the various aspects relating to frauds and malpractices in banks. The Committee made a number of recommendations and suggested precautions to be taken to avoid incidence of frauds and malpractices in the banks. Reserve Bank of India had examined these recommendations and some of the recommendations relevant to the primary (urban) co-op. banks commended for adoption by them are indicated below: 2.1 Internal Audit Machinery The banks should introduce a sound system of internal audit. With a view to strengthening the credibility of the inspection system in detecting cases of frauds/malpractices, steps need to be taken to gear up the inspection/audit machinery and to improve the quality of officers of the inspection department. The head of the inspection department at the Head Office should be a sufficiently senior person and should report directly to the Chairman. If the bank has Regional Offices, there should be an audit machinery under an official of sufficient seniority as the Regional Office Chief to conduct the periodical audit of branches under its jurisdiction. The officers posted to this department should have sufficient experience and exposure and the department should be headed by an official of sufficient seniority and 2.2 Periodicity of Internal Audit The periodicity of the internal audit of the branches should be at least once in every 12 months, which should be really of surprise character. 2.3 Coverage of Internal Audit 2.3.1 The coverage of such inspections should also be made more comprehensive, inter alia, to include a thorough examination of the internal control system obtaining at the branches including the various periodical control returns submitted to the controlling offices. The internal inspection report should specifically comment, on the position of irregularities pointed out in the inspection report of Reserve Bank of India. The inspection/audit officials should also critically analyse and make in-depth study of the corruption/fraud prone areas such as appraisal of credit proposals, balancing of books, reconciliation of inter-branch accounts, settlement of clearing transactions, suspense accounts, premises and stationery accounts during the course of inspections leaving no scope for any malpractices/irregularities remaining undetected. 2.3.2 The internal inspector should scrutinise the suspense account during inspection / visit and give specific instructions for early reversal of entries. 2.3.3 The banks should ensure that the system evolved for recording the details of off-balance sheet transactions are properly followed by all branches. These records should be periodically balanced and internal inspectors should verify the same and offer critical comments. 2.3.4 Proper inventory of dead stock articles, stationary should be maintained and subjected to surprise check at periodical intervals by the officials of the branch as also internal inspectors. 2.4 Supplementary Short Inspections The annual internal inspection should be supplemented by surprise short inspections at irregular intervals, particularly of large branches, to be carried out by officials at appropriate higher levels not only to look into the general working of the branches but also to ensure that no malafide practices are being indulged in to by the branch officials. In addition wherever so warranted, spot/special inspections or scrutiny should also be carried out on receiving signals to that effect. 2.5 Revenue Audit 3.1.3.2 The deals have been undertaken in the best interest of the bank. 3.2 compliance with Prudential Norms Internal auditors should bring out non-compliance with the prudential norms relating to income recognition, asset classification and provisioning for taking suitable action in the matter. 3.3 Cheque Purchase Transactions The internal inspectors should verify all the cheque purchased/discounted beyond the sanctioned limit. They should be asked to conduct a sample checking of transactions. 4 CONCURRENT AUDIT SYSTEM 4.1 Ghosh Committee had recommended introduction of concurrent audit at large and exceptionally large branches of banks to serve as administrative support to branches, help in adherence to prescribed systems and procedures and prevention and timely detection of lapses/irregularities. Accordingly, all scheduled and other primary (urban) co-op. banks with deposits over Rs.50 crore were required to introduce the system of concurrent audit. Subsequently, based on the recommendations of the Joint Parliamentary Committee (JPC), which enquired into stock market scam and matters relating thereto, all primary (urban) co-operative banks are required to introduce the system of concurrent audit. 4.2 The concurrent audit system is to be regarded as part of a bank's early-warning system to ensure timely detection of irregularities and lapses, which helps in preventing fraudulent transactions at branches. It is, therefore, necessary for the bank's management to bestow serious attention to the implementation of various aspects of the system such as selection of branches, coverage of business operations, appointment of auditors, appropriate reporting procedures, follow-up/rectification processes and utilisation of the feed-back from the system for appropriate and quick management decisions. 4.3 The Board should review the effectiveness of the system and take necessary measures to correct the lacunae in the system, once in a year. 4.4 It is basically for the individual banks' managements to decide the details of the concurrent audit system. However, a note indicating the broad features of concurrent audit system is given in the Annexure 1 for the guidance of the banks. The note broadly defines the concept and scope of concurrent audit, such as converge of business/branches, types of activities to be covered during the audit reporting system. The note also details the broad suggestions in respect of various aspects of concurrent audit. 4.5 It is expected that the suggestions in the note would ensure some uniformity in the systems to be introduced by different banks. While framing a concurrent audit system, the banks may clearly spell out the linkages between different forms of internal inspections and audits already in existence and the proposed concurrent audit. 4.6 The concurrent auditors shall certify that the investments held by the bank as on the last reporting Friday of each quarter as reported to the Reserve Bank of India are actually owned / held by it as evidenced by physical securities or the custodians statement. The certificate should be submitted to the Regional Office of the Reserve Bank of India, having jurisdiction over the bank, within thirty days from the end of the relative quarter. 4.9 Chartered Accountants / audit firms associated with the bank for internal / concurrent audit assignments should not undertake statutory audit assignment during the same period. The firms associated with internal / concurrent audit should relinquish the internal / concurrent audit before accepting the statutory audit assignment during the year. 5 AUDIT FOR ELECTRONIC DATA PROCESSING SYSTEM: 5.1 Primary (urban) co-operative banks which have partially / fully computerised their operations should introduce EDP audit system on perpetual basis. In case such banks have an independent Inspection & Audit Department, an EDP audit cell should be constituted as part of their Inspection and Audit Department to carry out EDP audit in branches/offices having computerised operations. However, those primary (urban) co-operative banks, which do not have an independent Inspection & Audit Department, should create a dedicated group of persons, who, when required, can perform functions of an EDP Auditor. The overall control and supervision of these EDP Audit Cells should be vested in the Audit Committees. In this regard, all primary (urban) co-operative banks having fully/ partially computerised operations should ensure to comply with the norms stipulated in the succeeding paragraphs. 5.2 A team of competent and motivated EDP personnel may be developed. It is beneficial to have a collective development system consisting of many persons instead of a few, in order to take care of a possible exodus of key personnel. EDP auditors' technical knowledge should be augmented on a continuing basis through deputation to seminars/conferences, supply of technical periodicals and books etc. 5.3 Duties of system programmer/designer should not be assigned to persons operating the system and there should be separate persons dedicated to system programming/design. System person would only make modifications /improvements to programs and the operating persons would only use such programs without having the right to make any modifications. 5.4 Major factors which lead to security violations in computers include inadequate or incomplete system design, programming errors, weak or inadequate logical access controls, absent or poorly designed procedural controls, ineffective employee supervision and management controls. These loopholes may be plugged by: 5.6 Contingency plans/procedures in case of failure of system should be introduced/ tested at periodic intervals. EDP auditor should put such contingency plan under test during the audit for evaluating the effectiveness of such plans. 5.8 An appropriate control measure should be devised and documented to protect the computer system from attacks of unscrupulous elements. Before introducing an EDP application in place of certain manual procedures, parallel run of both the systems should be done for a reasonable period to ensure that all aspects of security, reliability and accessibility of data are ensured in the EDP application. 5.9 In order to ensure that the EDP applications have resulted in a consistent and reliable system for inputting of data, processing and generation of output, various tests to identify erroneous processing, to assess the quality of data, to identify inconsistent data and to compare data with physical forms should be introduced. 5.10 While engaging outside computer agencies, banks should ensure to incorporate the "clause of visitorial rights" in the contract, so as to have the right to inspect the process of application and also ensure the security of the data/inputs given to such outside agencies. 5.11 Entire domain of EDP activities (from policy to implementation) should be brought under scrutiny of Inspection and Audit Department. Financial outlay as well as activities to be performed by EDP department should be reviewed by senior management at periodical intervals. 5.12 In order to bring about uniformity of software used by various branches/offices there should be a formal method of incorporating change in standard software and it should be approved by senior management. Inspection and Audit Department should verify such changes from the view-point of control and for its implementation in other branches in order to maintain uniformity. 6. AUDIT COMMITTEE OF BOARD (APEX AUDIT COMMITTEE) 6.1 The Reserve Bank of India has, from time to time, emphasised the need on the part of the directors of the primary (urban) co-operative banks to ensure timely review and action on the findings of statutory inspection/audit reports and submission of the compliance reports thereto. Yet, in most of the banks, there is no proper system to examine and follow-up the observations and suggestions made in the inspection reports of Reserve Bank of India, statutory auditors and those submitted by the internal inspection department, vigilance cell and internal auditors. Timely follow-up action on the findings of inspection reports and guidelines, circulars etc. issued by RBI as also the internal audit/inspection, etc. is considered desirable to tone up the overall functioning and operational efficiency of the banks. 6.2 In order to ensure and enhance the effectiveness of internal audit/inspection as a management tool, it is considered necessary that an Apex Audit Committee should be set up at the Board level for overseeing and providing direction to the internal audit/inspection machinery and other executives of primary (urban) co-operative banks. The Audit Committee of the Board of Directors (ACB) may consist of the Chairman and three/four Directors, one or more of such Directors being Chartered Accountants or persons having experience in management, finance, accountancy and audit system, etc. This also implies that the banks need to constitute, wherever necessary, their Boards with an adequate number of such professionals. 6.3 The Audit Committee of the Board should review the implementation of the guidelines issued by RBI and submit a note thereon, to the Board at quarterly intervals. 6.4 The other duties/ responsibilities of the Audit Committee of Board (ACB) are as follows: 6.4.1 ACB should provide direction and oversee the operations of the total audit function in the bank. The total audit function will imply the organization, operationalisation and quality control of internal audit and inspection within the bank and follow-up on the statutory audit of the bank and inspection of the Reserve Bank. 6.4.2 As regards internal audit, ACB should review the internal inspection/audit function in the bank - the system, its quality and effectiveness in terms of follow up. It should review the follow up action on the internal inspection reports, particularly of "unsatisfactory" branches and branches classified by the bank as extra large branches. It should also specially focus on the follow up on: 6.4.2.3 Arrears in balancing of books at various branches. Master Circular 1. INTRODUCTION 2. SCOPE OF CONCURRENT AUDIT Master Circular on List of Circulars consolidated in the Master Circular
B. List of other circulars from which instructions relating to Inspection & Audit Systems in Primary (Urban) Co-operative Banks have also been consolidated in the Master Circular
|