2019-01-29 | 1/POJK.03/2019Added
This regulation mandates commercial banks to establish an independent internal audit function with adequate resources, authority, and reporting lines to the Board of Directors and Board of Commissioners. It requires the creation of an internal audit charter, annual audit plans based on risk assessment, and strict adherence to professional standards and ethics. Banks must submit specific reports to the Financial Services Authority, including appointments of the head of the internal audit unit, findings threatening business continuity, independent external reviews every three years, and semi-annual audit results.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
COPY
FINANCIAL SERVICES AUTHORITY REGULATION
OF THE REPUBLIC OF INDONESIA
NUMBER 1 /POJK.03/2019
CONCERNING
THE IMPLEMENTATION OF INTERNAL AUDIT FUNCTIONS IN COMMERCIAL BANKS BY THE GRACE OF GOD THE ALMIGHTY THE COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY,
Considering:
a. that the implementation of good governance requires an independent internal audit function with authority, competent resources, and adequate information access so that the internal audit function can be carried out effectively; b. that effective internal audit implementation provides assurance to banks regarding the quality and effectiveness of the internal control system, risk management, and governance processes to protect the organization and the bank's reputation;
c. that bank internal audit practices include the application of professional internal audit standards established by the internal audit professional association;
d. that based on the considerations referred to in letters a through c, it is necessary to establish a Financial Services Authority Regulation concerning the Implementation of Internal Audit Functions in Commercial Banks;
Recalling:
DECIDING:
Establishing: FINANCIAL SERVICES AUTHORITY REGULATION CONCERNING THE IMPLEMENTATION OF INTERNAL AUDIT FUNCTIONS IN COMMERCIAL BANKS.
CHAPTER I
GENERAL PROVISIONS
Article 1
In this Financial Services Authority Regulation, the following terms are defined as:
CHAPTER II
INTERNAL AUDIT
Article 2
(1) Banks are required to have an internal audit function in accordance with the size, characteristics, and complexity of the Bank's business. (2) The internal audit function is stipulated in the internal audit function execution standards, which at a minimum include matters regulated in the Professional Internal Audit Standards. (3) The implementation of the internal audit function is supported by adequate resources, methodologies, tools, and audit techniques.
CHAPTER III
STRUCTURE, AUTHORITY, AND CORE TASKS OF THE INTERNAL AUDIT WORK UNIT
Article 3
(1) The SKAI is directly responsible to the Chief Executive Officer.
(2) In carrying out its duties, the SKAI submits reports to:
a. the Chief Executive Officer; or b. the Board of Commissioners.
(3) Copies of the reports referred to in paragraph (1) letter a are submitted to the Board of Commissioners, the Audit Committee, and the director overseeing the compliance function. (4) The Head of the SKAI is appointed and dismissed by the Chief Executive Officer after obtaining approval from the Board of Commissioners, considering the recommendation of the Audit Committee.
Article 4
The SKAI has at least the following authorities:
a. access to all information relevant to the Bank related to the duties and functions of the SKAI; b. communicate directly with the Board of Directors, Board of Commissioners, and Audit Committee, as well as the Sharia Supervisory Board for commercial Islamic banks and conventional commercial banks that have Islamic business units;
c. hold regular and incidental meetings with the Board of Directors, Board of Commissioners, and Audit Committee, as well as the Sharia Supervisory Board for commercial Islamic banks and conventional commercial banks that have Islamic business units;
d. coordinate activities with external auditors; and e. attend strategic meetings.
Article 5
The core tasks of the SKAI include at least:
a. assisting the Chief Executive Officer and the Board of Commissioners in supervision by operationalizing the planning, implementation, and monitoring of audit results; b. creating analysis and assessments in the fields of finance, accounting, operations, and other activities through audits;
c. identifying all possibilities to improve and increase the efficiency of resource and fund utilization; and
d. providing improvement suggestions and objective information about audited activities at all levels of management.
CHAPTER IV
FUNCTIONS OF THE HEAD OF THE INTERNAL AUDIT WORK UNIT
Article 6
(1) The Head of the SKAI must have adequate competence and ability to lead an independent and objective internal audit function.
(2) The Head of the SKAI is responsible for:
a. ensuring the implementation of the internal audit function in accordance with the Professional Internal Audit Standards and the Internal Audit Code of Ethics; b. selecting competent human resources according to the needs in the implementation of the SKAI's duties;
c. ensuring SKAI members follow continuing professional development and other training in accordance with the development of the complexity and business activities of the Bank;
d. drafting and reviewing the internal audit charter periodically; e. drafting the annual audit plan and budget allocation for the implementation of the internal audit function; f. ensuring the implementation of internal audit in accordance with the internal audit plan; g. reporting significant findings to the Board of Directors for corrective action to be taken quickly; h. monitoring corrective actions on significant findings;
i. reporting the results of monitoring follow-up on corrective actions for significant findings to the Board of Directors and the Board of Commissioners, with copies to the Audit Committee and the director overseeing the compliance function;
j. ensuring that in the event of the use of external party services for internal audit activities:
CHAPTER V
PROFESSIONAL ETHICS
Article 7
(1) Banks are required to ensure that the SKAI acts independently and objectively in carrying out its duties and functions.
(2) The scope of independence and objectivity as referred to in paragraph (1) refers to applicable standards.
Article 8
(1) Banks are required to:
a. establish an SKAI that has the knowledge, skills, and competencies needed in the implementation of the internal audit function for the Bank as a whole; b. ensure that the SKAI applies knowledge, skills, and competencies professionally and skeptically; and
c. ensure that the SKAI improves knowledge, skills, and other competencies through continuing professional development.
(2) Conventional commercial banks that have Islamic business units are required to appoint at least 1 (one) SKAI member who has knowledge and/or understanding of Islamic banking operations.
Article 9
Banks are required to ensure that the SKAI has integrity in carrying out its duties, reflected in actions:
a. being reliable, firm, honest, and trustworthy; b. maintaining the confidentiality of information obtained in the implementation of duties;
c. avoiding conflicts of interest; and
d. implementing the Internal Audit Code of Ethics.
CHAPTER VI
INTERNAL AUDIT CHARTER
Article 10
(1) Banks are required to have an internal audit charter containing at least:
a. the structure and position of the SKAI; b. the duties and responsibilities of the SKAI and its relationship with other work units performing control functions;
c. the authority of the SKAI;
d. the Internal Audit Code of Ethics; e. requirements for internal auditors in the SKAI; f. the accountability of the SKAI; g. prohibition of concurrent duties and positions for internal auditors and implementers in the SKAI from carrying out Bank operational activities, including in subsidiaries; h. criteria for using external expert services to support the internal audit function;
i. conditions that must be met by the SKAI to maintain independence when requested to provide consulting services or other special tasks;
j. the responsibilities and accountability of the Head of the SKAI; k. requirements to comply with the Professional Internal Audit Standards;
l. procedures for coordinating the internal audit function with legal experts or external auditors;
m. policies for periodic assignment restrictions and adequate cooling-off periods for assignments to SKAI members; and n. policies for restriction on the use of services and adequate cooling-off periods for external parties. (2) The internal audit charter as referred to in paragraph (1) is a guideline for implementing the internal audit function for:
a. audit implementation; b. initiating communication with auditees at the Bank;
c. examining Bank activities; and
d. the authority to access Bank records, documents, data, and physical assets, including information management systems and minutes of management meetings. (3) The internal audit charter is established by the Chief Executive Officer after obtaining approval from the Board of Commissioners, considering the recommendation of the Audit Committee. (4) The internal audit charter must be accessible by:
a. all internal stakeholders of the Bank; and b. external stakeholders of the Bank through the Bank's website for banks whose shares are publicly held. (5) The internal audit charter is reviewed at least once every 3 (three) years.
CHAPTER VII
SCOPE OF INTERNAL AUDIT ACTIVITIES
Article 11
(1) SKAI activities cover examinations and evaluations of Bank activities at least regarding:
a. the effectiveness, efficiency, and adequacy of the internal control system, risk management, and governance on an ongoing basis; b. the reliability, effectiveness, and integrity of information management processes and systems, including relevance, accuracy, completeness, availability, and data confidentiality;
c. compliance with statutory regulations, including compliance with Sharia principles for commercial Islamic banks and conventional commercial banks that have Islamic business units; and
d. organizational performance quality.
(2) SKAI activities as referred to in paragraph (1) apply to the Bank as a whole, including subsidiaries, Bank branches, and Bank activities outsourced to external parties.
CHAPTER VIII
AUDIT PLAN
Article 12
(1) Banks are required to have an annual audit plan and budget allocation for the implementation of the internal audit function.
(2) The annual audit plan is drafted based on a comprehensive risk assessment, covering at least:
a. policies, processes, and steps for implementing governance in accordance with relevant statutory regulations; b. risk management;
c. capital adequacy;
d. liquidity adequacy; e. internal reporting; f. compliance with statutory regulations, including compliance with Sharia principles for commercial Islamic banks and conventional commercial banks that have Islamic business units; and g. finance. (3) The annual audit plan and budget allocation as referred to in paragraph (1) must be approved by the Chief Executive Officer and the Board of Commissioners, considering the recommendation of the Audit Committee.
CHAPTER IX
RESPONSIBILITIES IN THE IMPLEMENTATION OF THE INTERNAL AUDIT FUNCTION
Article 13
(1) In the implementation of the internal audit function, the Board of Directors is responsible for:
a. developing an internal control framework to identify, measure, monitor, and control all risks faced by the Bank; b. ensuring that the SKAI obtains information regarding developments, initiatives, projects, products, operational changes, and identified and anticipated risks;
c. ensuring that appropriate corrective actions are taken quickly for all SKAI findings and recommendations; and
d. ensuring that the Head of the SKAI has the resources and budget needed to carry out duties and functions in accordance with the annual audit plan. (2) In the implementation of the internal audit function, the Board of Commissioners is responsible for:
a. ensuring that the Board of Directors drafts and maintains an adequate, effective, and efficient internal control system; b. reviewing the effectiveness and efficiency of the internal control system based on information obtained from the SKAI at least once every 1 (one) year; and
c. appointing an independent external quality controller to review the performance of the SKAI, considering the recommendation of the Audit Committee.
(3) In the implementation of the internal audit function, the Audit Committee is responsible for:
a. monitoring and reviewing the effectiveness of the Bank's internal audit implementation; b. evaluating the performance of the SKAI;
c. ensuring that the SKAI communicates with the Board of Directors, Board of Commissioners, Sharia Supervisory Board for commercial Islamic banks and conventional commercial banks that have Islamic business units, external auditors, and the Financial Services Authority;
d. ensuring that the SKAI works independently; e. providing recommendations to the Board of Commissioners regarding the drafting of the SKAI's audit plan, scope, and budget; f. reviewing audit reports and ensuring that the Board of Directors takes necessary corrective actions quickly to address control weaknesses, fraud, compliance issues with policies, laws, and regulations, or other issues identified and reported by the SKAI; g. providing recommendations to the Board of Commissioners regarding the annual remuneration of the SKAI as a whole and performance awards; and h. ensuring that the SKAI upholds integrity in carrying out its duties.
CHAPTER X
RELATIONSHIP BETWEEN THE INTERNAL AUDIT WORK UNIT AND CONTROL UNITS AND EXTERNAL AUDITORS
Article 14
(1) The SKAI cooperates with other work units performing control functions at the Bank by prioritizing the effectiveness of the control function. (2) The SKAI cooperates with external auditors to support the implementation of external audit services to the Bank.
CHAPTER XI
COMMUNICATION BETWEEN THE INTERNAL AUDIT WORK UNIT AND THE FINANCIAL SERVICES AUTHORITY
Article 15
(1) In the implementation of the internal audit function, Banks are required to communicate with the Financial Services Authority at least once every 1 (one) year. (2) The communication as referred to in paragraph (1) is conducted by the Head of the SKAI and at least discusses:
a. risk areas identified by the Financial Services Authority and the SKAI; b. the Bank's understanding of risk mitigation actions taken;
c. the Bank's monitoring of follow-up on identified weaknesses;
d. findings and recommendations from internal audit implementation in the current year; and e. the annual audit plan.
(3) The Financial Services Authority has the authority to provide recommendations to the Bank to improve the effectiveness and efficiency of the internal audit function implementation.
CHAPTER XII
INTERNAL AUDIT WORK UNIT FUNCTION IN BUSINESS GROUPS
Article 16
(1) For Banks that are subsidiaries:
a. the SKAI reports a summary of internal audits to the official overseeing the internal audit function of the parent company; and b. the Board of Commissioners communicates with the internal audit function of the parent company so that the parent company's internal audit function drafts the audit scope and carries out internal audit activities with adequate coverage for the Bank, while still observing statutory regulations. (2) For Banks that are parent companies, the Chief Executive Officer and the Board of Directors are responsible for ensuring that internal audit implementation in subsidiaries is conducted using the Bank's audit standards. (3) The implementation of internal audit in subsidiaries as referred to in paragraph (2) is conducted while still considering the size, characteristics, and complexity of the subsidiary's business.
CHAPTER XIII
USE OF EXTERNAL PARTY SERVICES IN INTERNAL AUDIT IMPLEMENTATION
Article 17
(1) Banks may use external party services in the implementation of internal audit that require special expertise and are temporary in nature. (2) The use of external party services as referred to in paragraph (1) that are temporary in nature may be exempted for:
a. the use of external party services related to information technology; and/or b. the use of external party services for other matters based on approval from the Financial Services Authority. (3) Banks are required to explain the reasons for the implementation of internal audit by external parties as referred to in paragraph (1) to the Financial Services Authority. (4) The role of external parties in the implementation of the internal audit function is the responsibility of the Head of the SKAI. (5) Banks are required to ensure the independence of the use of external parties in the implementation of internal audit.
CHAPTER XIV
REPORTING OBLIGATIONS TO THE FINANCIAL SERVICES AUTHORITY
Article 18
Banks are required to submit reports to the Financial Services Authority regarding the implementation of the internal audit function, namely:
a. reports on the appointment or dismissal of the Head of the SKAI; b. special reports regarding every internal audit finding estimated to endanger the continuity of the Bank's business;
c. reports on the results of reviews by independent external parties as referred to in Article 13 paragraph (2) letter c; and
d. reports on the implementation and main points of internal audit results.
Article 19
Banks are required to submit to the Financial Services Authority reports on the appointment or dismissal of the Head of the SKAI as referred to in Article 18 letter a:
a. accompanied by the Chief Executive Officer's decision letter, Board of Commissioners' approval letter, and Audit Committee recommendation; b. signed by the Chief Executive Officer and the Lead Commissioner;
c. at the latest 10 (ten) working days after the date of appointment or dismissal of the Head of the SKAI; and
d. offline.
Article 20
Banks are required to submit to the Financial Services Authority special reports regarding every internal audit finding estimated to endanger the continuity of the Bank's business as referred to in Article 18 letter b:
a. signed by the Chief Executive Officer and the Independent Commissioner who is the Chairman of the Audit Committee; b. at the latest 3 (three) working days after discovery; and
c. offline.
Article 21
(1) Banks are required to submit to the Financial Services Authority reports on the results of reviews by independent external parties as referred to in Article 18 letter c:
a. conducted once every 3 (three) years, namely for the period from July to June of the third following year; b. covering at least:
Article 22
Banks are required to submit to the Financial Services Authority reports on the implementation and main points of internal audit results as referred to in Article 18 letter d:
a. covering at least:
Article 23
In the event that online submission of reports as referred to in Article 22 letter d cannot be performed, Banks are required to submit reports offline to the Financial Services Authority.
Article 24
In the event that the deadline for submitting reports to the Financial Services Authority offline as referred to in Article 19 letter d, Article 20 letter c, Article 21 paragraph (1) letter e, and/or Article 23 falls on a national holiday, the report is submitted at the latest on the next working day.
Article 25
Submission of offline reports is directed to:
CHAPTER XV
ADMINISTRATIVE SANCTIONS
Article 26
(1) Banks that do not fulfill the provisions as referred to in Article 2 paragraph (1), Article 7 paragraph (1), Article 8, Article 9, Article 10 paragraph (1), Article 12 paragraph (1), Article 15 paragraph (1), Article 17 paragraph (3) and/or paragraph (5), Article 18, Article 19, Article 20, Article 21 paragraph (1), Article 22, and/or Article 23, are subject to administrative sanctions consisting of:
a. written reprimand; b. listing of members of the Board of Directors, Board of Commissioners, and/or executive officials in the list of failed candidates through a re-evaluation mechanism for principal parties of the Bank as referred to in Financial Services Authority Regulations concerning re-evaluation for principal parties of financial service institutions;
c. suspension of certain business activities; and/or
d. dismissal of members of the Board of Directors, Board of Commissioners, and/or executive officials and subsequently appointing and hiring temporary replacements.
(2) Administrative sanctions may be imposed individually or jointly.
Article 27
In addition to sanctions as referred to in Article 26, Banks that submit offline reports beyond the submission deadline as referred to in Article 19 letter c, Article 20 letter b, Article 21 paragraph (1) letter d, and/or Article 22 letter c are subject to administrative sanctions consisting of a fine of Rp 500,000.00 (five hundred thousand rupiah) per working day and a maximum of Rp 15,000,000.00 (fifteen million rupiah).
CHAPTER XVI
TRANSITIONAL PROVISIONS
Article 28
Violations of the implementation of the internal audit function conducted before the effective date of this Financial Services Authority Regulation and discovered after this Financial Services Authority Regulation comes into force, are subject to administrative sanctions referring to this Financial Services Authority Regulation.
Article 29
(1) The first review period as referred to in Article 21 paragraph (1) letter a starts from the position of the last reported review period of the Bank until June of the third following year. (2) Banks may continue to use the existing internal audit charter before this Financial Services Authority Regulation comes into force until June 1, 2019.
CHAPTER XVII
CLOSING PROVISIONS
Article 30
Upon the coming into force of this Financial Services Authority Regulation, Bank Indonesia Regulation No. 1/6/PBI/1999 concerning the Assignment of Compliance Directors (Compliance Director) and Legal Directors 1 (Law Department) regarding the Implementation of Internal Audit Standards for General Banks (State Gazette of the Republic of Indonesia Year 1999 Number 158, Supplement to the State Gazette of the Republic of Indonesia Number 3883) is repealed and declared invalid.
This copy is consistent with the original
Legal Director 1
Legal Department signed
Yuliana
Article 31
This Financial Services Authority Regulation comes into force on the date of enactment.
To ensure that everyone knows it, ordering the enactment of this Financial Services Authority Regulation by placing it in the State Gazette of the Republic of Indonesia.
Established in Jakarta on January 28, 2019
CHAIRMAN OF THE COMMISSIONERS
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
WIMBOH SANTOSO
Enacted in Jakarta on January 29, 2019
MINISTER OF LAW AND HUMAN RIGHTS
REPUBLIC OF INDONESIA, signed
YASONNA H. LAOLY
STATE GAZETTE OF THE REPUBLIC OF INDONESIA YEAR 2019 NUMBER 20
EXPLANATION
OF
FINANCIAL SERVICES AUTHORITY REGULATION
OF THE REPUBLIC OF INDONESIA
NUMBER 1 /POJK.03/2019
CONCERNING
IMPLEMENTATION OF INTERNAL AUDIT FUNCTION ON GENERAL BANKS
I. GENERAL
Governance implementation in the banking industry is needed to face increasingly increased risks and dynamics. One part of governance implementation in the banking industry is the effective implementation of the internal audit function. This function is carried out by the Internal Audit Unit (SKAI) acting independently and objectively. An effective internal audit function can be realized through the provision of authority, competent resources, and adequate information access.
Control functions are reflected in the three lines of defense concept. The first line of defense (first line) is embedded supervision in business units responsible for identifying, assessing, and controlling business risks. The second line of defense (second line) includes supporting functions such as risk management and compliance responsible for ensuring that risks in business units have been identified and managed properly. The Internal Audit Unit (SKAI) acts as the third line of defense (third line) by assessing the effectiveness of processes carried out in the first and second lines of defense to provide independent assurance to the Bank that internal control systems, risk management, and governance processes and systems have been implemented effectively.
The Internal Audit Unit (SKAI) must be able to evaluate and play an active role in continuously improving the effectiveness of internal controls in relation to the Bank's business activities that have the potential to cause losses in achieving objectives set by Bank management. In this regard, the SKAI protects the organization and helps reduce the risk of losses and reputational risks that may occur to the Bank. SKAI activities include the application of Internal Audit Professional Standards established by the internal audit professional association.
In light of the above, it is necessary to regulate the implementation of the internal audit function on general banks.
II. ARTICLE BY ARTICLE
Article 1
Sufficiently clear.
Article 2
Paragraph (1)
The obligation to have an internal audit function includes Banks that are part of a business group.
The organizational structure of the Internal Audit Unit (SKAI) is adjusted to the complexity and business activities of the Bank.
For example, the SKAI can be in the form of a division or department.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
Sufficiently clear.
Article 3
Paragraph (1)
Sufficiently clear.
Paragraph (2)
The Internal Audit Unit (SKAI) may submit reports directly to the Board of Commissioners if communication with the President Director is considered inappropriate. For example, SKAI findings related to the integrity of the President Director. Paragraph (3) Sufficiently clear. Paragraph (4) Sufficiently clear.
Article 4
Letter a
Sufficiently clear.
Letter b
Sufficiently clear.
Letter c
Sufficiently clear.
Letter d
Sufficiently clear.
Letter e
The Internal Audit Unit (SKAI) attends strategic meetings without voting rights.
Examples of strategic meetings include:
Article 5
Letter a
Sufficiently clear.
Letter b
Analysis and assessments are developed independently and informatively to describe the risks faced by the Bank.
Letter c
Sufficiently clear.
Letter d
Sufficiently clear.
Article 6
Paragraph (1)
The competence of the Head of the Internal Audit Unit (SKAI) is evidenced among others by relevant audit certifications.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
Sufficiently clear.
Article 7
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Applicable standards include Internal Audit Professional Standards regarding independence and objectivity.
Examples of conditions causing the Internal Audit Unit (SKAI) to be independent in carrying out tasks and functions include:
Article 8
Paragraph (1)
Letter a
Knowledge, skills, and competencies in the implementation of comprehensive internal audit can be possessed by the Head and members of the Internal Audit Unit (SKAI) both individually and collectively, in accordance with the development of business activities and Bank complexity. Letter b Professional competence includes the SKAI's ability to collect and understand information, examine and evaluate audit evidence, and communicate with stakeholders. Letter c Sustainable professional development can be fulfilled through efforts:
Article 9
Letter a
Sufficiently clear.
Letter b
Sufficiently clear.
Letter c
Examples of conflicts of interest include:
Article 10
Paragraph (1)
Letter a
Sufficiently clear.
Letter b
Sufficiently clear.
Letter c
Sufficiently clear.
Letter d
Sufficiently clear.
Letter e
Sufficiently clear.
Letter f
Sufficiently clear.
Letter g
Sufficiently clear.
Letter h
Sufficiently clear.
Letter i
The provision of consulting services by the Internal Audit Unit (SKAI) to internal Bank parties considers independence aspects including:
Paragraph (2)
Sufficiently clear.
Paragraph (3)
Sufficiently clear.
Paragraph (4)
Sufficiently clear.
Paragraph (5)
Sufficiently clear.
Article 11
Sufficiently clear.
Article 12
Paragraph (1)
The annual audit plan can be part of a long-term (multi-year) audit plan.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
The Bank allocates adequate budget for the implementation of the annual audit plan.
The aforementioned budget can be adjusted based on changes in the audit plan due to changes in the Bank's risk profile.
Article 13
Sufficiently clear.
Article 14
Paragraph (1)
Cooperation between the Internal Audit Unit (SKAI) and work units performing other control functions in the Bank, such as risk management work units and compliance work units, does not cause the transfer of responsibility of each work unit in the control function. Paragraph (2) Cooperation between the Internal Audit Unit (SKAI) and external auditors can be carried out through periodic meetings to discuss matters considered important by both parties. Examples of cooperation between the Internal Audit Unit (SKAI) and external auditors include:
Article 15
Sufficiently clear.
Article 16
Paragraph (1)
Regulatory provisions include regulations concerning bank secrecy.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
Sufficiently clear.
Article 17
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
Sufficiently clear.
Paragraph (4)
The role of external parties in the implementation of the internal audit function includes that external parties are not allowed to become team leaders in the implementation of internal audits. Paragraph (5) Independence of external parties in internal audits includes:
Article 18
Letter a
Sufficiently clear.
Letter b
Examples of internal audit findings estimated to endanger the Bank's business continuity include:
Article 19
Sufficiently clear.
Article 20
Sufficiently clear.
Article 21
Paragraph (1)
Letter a
Example:
Review of the internal audit function by an independent external party is conducted for the period from July 2016 to June 2019.
Letter b
Sufficiently clear.
Letter c
Sufficiently clear.
Letter d
Sufficiently clear.
Letter e
Sufficiently clear.
Paragraph (2)
Example:
The Bank has conducted the last review for the period from July 2015 to June 2018. According to the provisions, the next review period is from July 2018 to June 2021, but the Bank plans to conduct the review earlier than 3 (three) years, the review periods that the Bank can choose are:
Article 22
Sufficiently clear.
Article 23
Sufficiently clear.
Article 24
Sufficiently clear.
Article 25
Sufficiently clear.
Article 26
Sufficiently clear.
Article 27
Sanctions are calculated starting from the working day following the reporting deadline.
Article 28
Sufficiently clear.
Article 29
Paragraph (1)
Examples:
Article 30
Sufficiently clear.
Article 31
Sufficiently clear.
SUPPLEMENT TO THE STATE GAZETTE OF THE REPUBLIC OF INDONESIA NUMBER 6308
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.