top of page

Operational Audits

Scope includes the review and testing of internal controls within each operation of the financial institution. The audit focuses on the adequacy and compliance of policies and procedures established by management.

Internal Control Reviews | BSA | ACH | Interest Rate Risk | Liquidity Risk Management | Special Projects

INTERNAL CONTROL REVIEWS

​

Scope includes the review and testing of internal controls within each operation of the financial institution. The audit focuses on the adequacy and compliance of policies and procedures established by management. Almost every internal control audit will be supported by a detailed Risk Matrix (RM). Both Management and Kendrick Service (KS) team members work together in the design of the RM by identifying the MAJOR RISKS of the operational area and the KEY CONTROLS that mitigate those risks. The KS team then designs testing processes to assure controls are operating at an acceptable level. All controls are assessed a "PASS" or "FAIL" rating. Finally, a report is issued in graphic form detailing each risk covered and control ratings.

 

BANK SECRECY ACT (BSA)

 

Our procedures are designed to assist the financial institution in reviewing and improving its compliance with the requirements under the Bank Secrecy Act and Anti-Money Laundering rules. All BSA audits will be performed by auditors carrying a professional certification for BSA auditing – Certified Anti-Money Laundering Specialist (CAMS) and / or Certified BSA/AML Professional (CBAP). At the conclusion of our work, we will issue a report that includes a rating to help management and the Board more clearly understand the bank’s compliance with BSA and other related laws and regulations.

Our scope includes the following:


  • Evaluating corrective actions taken in response to prior reviews or regulatory examinations, if applicable;

  • Reviewing the Bank Secrecy Act, Customer identification Program (CIP), Office of Foreign Asset Control (OFAC) and anti-money laundering (AML) policies, procedures and program;

  • Evaluating knowledge and understanding of personnel;

  • Reviewing the scope, frequency, and documentation of training;

  • Reviewing large cash transactions and currency transaction reports (CTRs);

  • Evaluating compliance with record retention requirements;

  • Reviewing correspondence with the government;

  • Reviewing wire transfer activity, documentation, and departmental procedures;

  • Reviewing exemptions;

  • Reviewing 314(a) search request processes and procedures;

  • Reviewing suspicious activity reports (SARs);

  • Reviewing account reviews, including high-risk and MSB accounts;

  • Reviewing accounts held by foreign nationals, if any;

  • Reviewing processes related to the Bank’s AML/fraud detection software, as available;

  • Reviewing policies and processes related to beneficial ownership;

  • Reviewing policies and processes related to NSL (National Security Letters);

  • Evaluating guidelines for detecting, preventing, and reporting suspicious activities;

  • Evaluating CIP compliance and account opening procedures;

  • Evaluating implementation of US Patriot Act requirements;

  • Evaluating compliance with OFAC requirements;

  • Evaluating ACH processes and monitoring related for compliance with BSA and OFAC;

  • Evaluating BSA processes and monitoring as they relate to ACH services;

  • Evaluating the bank’s Anti-Money Laundering program risk assessment and procedures; and

  • Reviewing sales of monetary instruments.

  • Discussing with management to ascertain if Marijuana Related Businesses would be accepted for account relationships. If yes, determining what processes have taken place to ensure compliance with FinCEN Guidance FIN-2014-G001, "BSA Expectations Regarding Marijuana-Related Businesses.”

  

ACH

    

Includes rules and regulations governing the ACH network as required by NACHA. Appendix eight of NACHA’s ACH Rules book provides the requirement for an annual audit of compliance with these rules. This review meets these annual audit requirements and entails an examination of ACH operations and includes all aspects related to sending and receiving ACH transactions. On a sample basis, we test record retention, acceptance of entries, prenotes, returns, notification of change (NOC), credit availability, account statement content, stop pays and unauthorized transactions. All ACH audits will be performed by auditors with extensive experience in both ACH operations and/or ACH auditing. At the conclusion of our work, we will issue a report that includes a rating to help management and the Board more clearly understand the bank’s compliance with the current year’s NACHA’s ACH Rules book.

 

INTEREST RATE RISK (IRR)

 

Our primary objective will be to review the overall interest rate risk management process and to measure it against guidelines in the “Joint Agency Policy Statement on Interest Rate Risk” (JAPS) as provided by the FDIC on January 20, 2010 (FIL-2-2010). We will:

​

  • Determine appropriate policies, procedures and internal controls addressing IRR management, including limits and controls over risk taking to stay within board-approved tolerances.

  • Determine the presence of comprehensive systems and standards for measuring IRR, valuing positions, and assessing performance, including procedures for updating IRR measurement scenarios and key underlying assumptions driving the institution’s IRR analysis.

  • Review sufficiency of reporting processes to inform senior management and the board of the level of IRR exposure.

  • An important element of model validation is independent review of the logical and conceptual soundness. We will review the scope of the independent review in assessing the institution’s measurement of IRR, including the reasonableness of assumptions, the process used in determining assumptions, and the ‘backtesting’ of assumptions and results, as well as, management actions related to such. We further review for adequate follow-up procedures to monitor management’s corrective actions. While we will not test the mechanics and mathematics of the measurement model, we will review to determine that vendor provided documentation showing a credible independent third party has performed such a function.

  • On a sampling basis, we will trace reported numbers back to source documents including full source data verification for all applicable asset, liability, income and expense balances used in one of the most recent modeling reports.

  • Recalculate certain ratios and formulas addressed in the bank’s IRR policy.


LIQUIDITY RISK MANAGEMENT

 

Our primary objective will be to review the overall liquidity risk management process and measure it against guidelines in the "Joint Agency" identified critical elements of a sound liquidity risk management process, as well as, those specified in applicable regulatory handbooks (Example: OCC Handbook of 2012 (Comptroller's Handbook: Safety & Soundness-(L) Liquidity). We will:


  • Review for appropriate corporate governance and active involvement by management.

  • Review for appropriate strategies, policies, procedures, and limits used to manage and control liquidity risk, even in stressed conditions.

  • Review for appropriate liquidity risk measurement and monitoring systems.

  • Review for active management of intraday liquidity and collateral.

  • Determine an appropriately diverse mix of existing and potential future funding sources are maintained.

  • Determine adequate levels of highly liquid marketable securities that can be used to meet liquidity needs in stressful situations without legal, regulatory, or operational impediments.

  • Review the comprehensiveness of contingency funding plans (CFP) sufficient to address potential adverse liquidity events and emergency cash flow needs.

  • Review for adequate internal controls surrounding all aspects of liquidity risk management.


SPECIAL PROJECTS

       

From reviewing activities surrounding a surprise exit of a CEO, to assisting a bank in unraveling suspicious activities of certain personnel, and everywhere in between; Kendrick Services has been called on to help perform various special projects for bankers. Occasionally, needs arise where outside, and sometimes objective / independent, expertise and experience is needed to research and analyze certain situations. Because our team consist of those well versed in bank operations, regulatory compliance and IT, our potential to tackle a special project crosses almost all facets of your bank.


bottom of page