#815139 - 09/14/07 01:17 PM Who performs compliance risk assessment?
butercup
I need some clarification. Should the compliance department be performing the compliance risk assessment or should internal audit do it? Right now there is a very blurry line between what compliance should be doing and what internal audit should do. Currently, Internal audit completes an annual risk assessment that includes the compliance side. I feel like compliance should conduct their own risk assessment and develop a review schedule from that. Right now, the only reviews that get done are my audits. I think Internal audit should include compliance as a whole on the audit risk assessment and conduct an audit of the entire compliance department on an annual basis.

What do other banks do?

09/18/07 03:49 PM ahou
ahou Offline
We have an IA for safety & soundness audits and an IA for compliance audits. The Compliance auditor does a compliance risk assessment and designs an audit schedule from that assessment. The previous bank I worked for did the same.
09/18/07 04:31 PM DeeQ
DeeQ Offline
The Compliance Officer performs the compliance RA ands the IA does the IA risk assessment forhis area. The Audit & Compliance Committee approves both annually.
