Regulatory expectations on compliance monitoring and testing:
- What is compliance monitoring?
- Expectations on the compliance function
- Testing of internal controls & requirements on sampling
- Compliance function’s roles vs internal auditor’s roles
- Reporting of compliance risk
Creating a compliance risk library or taxonomy and mapping regulations:
- Understanding of business / operation processes
- Internal controls, policies & procedures and approvals
- Types of compliance risk taxonomy e.g. conduct risk
- Mapping of regulations to the compliance risk taxonomy
Assessing compliance risk
- Compliance Risk Assessment (“CRA”) / Institutional Risk Assessment (“IRA”)
- Organisation’s risk profile being the foundation of compliance monitoring programme
- Prioritisation of compliance resources
- Compliance monitoring tools
Planning compliance monitoring & testing
- Elements of a compliance monitoring plan
- Establishing testing programmes & testing intervals
- Detailing the responsible party – 1.5 line of defense, compliance function, internal audit
- Recording and evidencing compliance tests
Defining compliance testing methodology:
- Gathering reliable information & data
- Deciding on mandatory compliance testing
- Defining sampling methodology
- Documenting the compliance testing scope and approach
- Developing compliance subject matter experts
Determining the compliance review schedule and performing compliance tests:
- Compliance review notification & stakeholder engagement
- Execution of compliance review and documentation of compliance test results
- Conducting exit meeting and discussion on identified gaps / deficiencies
- Issuing compliance review report
Implementing issue management procedures, validating issue remediation and periodic reporting of compliance risk:
- Roles and responsibilities on issue management
- Escalation and approval procedure - overdue / extension of remediation action plan
- Monitoring & periodic progress update
- Validating for closure of remediation action plan
Programme wrap-up, sharing of experiences and Q&A
- Challenges on implementing compliance monitoring and testing programme
- Challenges on sampling size and methodology
- On-going monitoring, periodic review and compliance reporting as part of the compliance programme
- Training & awareness
- Q & A