This is the person or group that owns the day-to-day risks and controls in a process.
Management
This acronym refers to knowing who the customer is and understanding the nature and purpose of the relationship.
KYC—Know Your Customer.
This control helps prevent one person from initiating, approving, and recording the same transaction.
Segregation of duties.
A loan exception should be supported by rationale and approved by the proper delegated this.
Authority level.
Giving users only the access necessary to perform their job is called this.
Least privilege
Internal Audit should use this approach when determining which engagements deserve the most attention.
A risk-based approach.
An employee sees unusual activity and should never tell the customer that this may be filed.
A SAR.
A reconciliation is strongest when prepared by one person and reviewed by this type of person.
An independent reviewer.
An adverse-action notice cannot simply say, “You did not meet Bank policy.” It must provide these.
Specific reasons for the action taken.
This is the primary problem with shared system IDs.
Activity cannot be traced to an individual; accountability is lost.
This is not Internal Audit’s job: assess controls, identify risks, report observations, or own the corrective-action plan.
Own the corrective-action plan.
True or False: One red flag by itself always proves fraud or money laundering.
False—it may warrant review or escalation, but it does not prove wrongdoing.
A report supports a key control, but no one can explain where the data comes from or whether the full population is included. This is an issue with this.
IPE completeness and accuracy.
For a completed consumer credit application, Regulation B generally requires notification of action taken within this many days.
30 days
Before a significant system change goes into production, it should be approved, tested, and this.
Documented
For Internal Audit to remain independent, the CAE should have functional accountability to this governing body.
The Board or Audit Committee.
Under CIP, which is not one of the basic identifying items generally collected: name, date of birth, address, or occupation?
Occupation
A large, unsupported, round-dollar journal entry posted at month-end may indicate this type of risk.
Potential management override or an unsupported adjustment.
This independent credit-risk function assesses loan quality and helps identify deterioration or emerging issues after a loan is made.
Loan review.
A representative discusses a securities recommendation through personal text messages. This creates potential supervision and this concern.
Recordkeeping concern
An auditor is assigned to review a process they managed just last year. Before beginning work, the auditor should disclose this potential impairment to their:
Objectivity/independence—and have the work reassigned or otherwise independently safeguarded.
An employee may discuss a potential SAR only with authorized personnel who need to know—never with this person.
The customer/account holder (or the subject of the SAR).
A control report is used to evidence daily monitoring, but the report’s population excludes transactions processed after 5:00 p.m. This is primarily a failure of report this.
Completeness.
A lender has enough information to deny an application but is still missing another document. The lender cannot use “incomplete application” as the reason for denial; it must provide this instead.
The specific reason(s) for the credit denial.
A representative recommends an investment to a retail customer. Under Regulation Best Interest, the recommendation must be in the customer’s this—not merely suitable for the representative or firm.
Best interest.